PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

What happens if you are not PCI DSS compliant

PCI DSS is enforced contractually, not by statute. Non-compliance is handled by your acquirer under its agreement with the payment brands, and consequences escalate from remediation deadlines and monthly non-compliance charges through to higher transaction costs and, in severe or repeated cases, loss of the ability to accept cards. A breach adds forensic investigation and liability for fraud and reissuance costs.

Before any breach

Your acquirer can require a remediation plan and evidence within a set deadline.
Brand programmes may apply monthly non-compliance charges passed through by the acquirer; the amounts are set contractually and are not published by PCI SSC.
Transaction pricing may be adjusted, and some acquirers withhold settlement or restrict services.
Persistent non-compliance can end in termination of the merchant agreement.

After a suspected compromise

The brands may require a PCI Forensic Investigator (PFI) engagement, paid for by the entity.
Expect account data compromise reporting to the acquirer and brands, per Requirement 12.10.1.
Liability for fraud losses, card reissuance and case management costs is typically passed through the acquirer.
Entities are commonly moved to a higher validation level after a compromise, meaning a QSA-led Report on Compliance from then on.

Beyond the payment brands

Data protection regulators assess payment card breaches under their own regimes; PCI DSS status is often treated as evidence of the security standard expected.
Contractual customers, especially enterprises, may treat lapsed compliance as a breach of contract.
Reputational and operational costs of an incident routinely exceed the direct charges.

How to recover position

Re-establish scope and confirm the correct validation route with your acquirer in writing.
Prioritise the requirements that stop data loss: no stored sensitive authentication data, MFA into the CDE, patching, log review.
Where a requirement genuinely cannot be met, document a compensating control or use the customised approach — do not leave it silent.
Complete a QSA-validated assessment once the gaps are actually closed.

Turn the reading into an answer

The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Written by Haumaru Whānau QSAs. PCI DSS content paraphrased from PCI DSS v4.0.1 and PCI SSC published guidance; payment brand programmes are set by the brands and your acquirer. Independent summary; not endorsed by PCI SSC.