PCI Compliance
PCI compliance
PCI is not hard. Your processor makes it hard.
Most merchants already meet the standard and still pay a non-compliance fee every month, because nobody walked them through the questionnaire and nobody told them what it costs to leave it unfinished.
Over 90% of our clients are certified in under an hour. Then we go back and look at what the fee took while they were not.
The problem
Nobody in the chain is paid to get you compliant
PCI DSS is a card network standard, not a law. Your processor is required to make you validate against it, and is allowed to charge you when you have not. That is the whole arrangement. The party that collects the penalty is the same party responsible for helping you avoid it.
So the questionnaire arrives once, by email, from a portal nobody recognizes, and then it stops arriving. The monthly fee starts quietly and does not stop. We have seen it billed for years to businesses that never store a card number and were never at any real risk.
Meanwhile the thing PCI is actually for, keeping card data from walking out of your business, gets no attention at all.
What the fee really is
Six reasons a careful business still pays a non-compliance fee
1
The questionnaire was never finished
The self assessment goes out by email, once, from a sender the merchant does not know. It gets filed as spam and the account is marked non-compliant from that day forward.
2
The wrong questionnaire was assigned
A business that never touches a card number gets handed the version written for one that stores them. It is long, it is irrelevant, and it is abandoned halfway through.
3
Validation lapsed and nobody said so
It has to be renewed every year. The reminder goes to whoever opened the account, who may have left the company two owners ago.
4
The scan was never set up
Some merchant types need a quarterly network scan. If nobody scheduled it, the account reads as non-compliant no matter how well run the business is.
5
The fee was never really disclosed
It lands as a small monthly line with a name that does not say penalty. We break down how it appears on a statement on our PCI DSS compliance fee page.
6
Compliance was reached and the fee stayed on
The most common one, and the most recoverable. If you are paying it now, start with PCI non-compliance fee? You may not owe it.
What we do
Easy PCI, and it is finished in one sitting
We do not hand you a portal login and wish you luck. We sit on the phone with you and finish it. Over 90% of our clients are certified in under an hour.
The right questionnaire for how you actually take cards, not the longest one on the list
The questions answered with you, in plain language, in one call
Scanning arranged where your merchant type genuinely requires it
The attestation filed with your processor, so the fee stops at the source rather than being argued about later
A reminder to you, not to a mailbox nobody reads, before validation lapses next year
Training for the people who handle cards, if you want it. You can request PCI training here
The money already spent
Then we look at what the fee took while you were not compliant
Getting you certified stops the bleeding. It does nothing about the months or years already billed. That is a separate question, and it is the one most merchants never ask.
How long the fee has been charged, and whether the rate moved without notice
Whether you were in fact compliant during any part of that period
Whether the fee was disclosed in your agreement, and at what amount
Whether the processor ever gave you a workable path to compliance
What is recoverable, who it comes back from, and what it takes to get it
If the fee was justified and properly disclosed, we tell you that and we leave it alone. We are not looking for an argument to have with your processor.
What it costs
A flat fee, and we keep 0% of your savings
Every other firm in this business takes a share of what it finds. We charge a flat fee, and whatever the work saves you or gets back for you is yours. What an audit costs is here.
PCI is normally handled alongside a full processing audit, because the fee sits on the same statement as everything else we read, and because the answers to the compliance questions tell us how your account was set up in the first place.
Send us one statement
One recent statement is enough for us to tell you whether you are being charged a PCI fee, whether it is justified, and what it has cost you so far. The first review is free and there is nothing to sign.
Want to talk?
- Call us today 800-672-1292
- Book a free consultation