PCI DSS

PCI DSS Fine Calculator

Non-compliance costs money before anything goes wrong. Card brands assess a monthly penalty for as long as a merchant stays out of compliance, and the amount escalates the longer it runs. Requirements 6.4.3 and 11.6.1 became mandatory on 31 March 2025.

Your situation
What that costs

Assessment this month

$16,500

$5,000 to $10,000 published range

Total assessed so far

$34,500

$15,000 to $30,000 published range

How this is calculated

Card brands publish an escalating scale rather than a single figure. Widely reported bands are $5,000 to $10,000 a month for the first three months, $25,000 to $50,000 for months four to six, and $50,000 to $100,000 from month seven onward. Within a band, the higher your card volume the closer to the top you are assessed, so this calculator uses merchant level to pick a point between the published low and high. It does not invent a figure of its own.

These assessments are only the visible part. A breach discovered while non-compliant adds a mandatory forensic investigation, card reissuance at $5 to $15 per card, credit monitoring, and higher processing rates. None of that is included above, which makes this a floor rather than an estimate.

Frequently asked questions

Card brands assess monthly and escalate with duration. Widely reported bands are $5,000 to $10,000 a month for the first three months, $25,000 to $50,000 for months four to six, and $50,000 to $100,000 from month seven onward. Within a band, the higher your card volume the closer to the top you are assessed, so a Level 1 merchant pays nearer $100,000 and a Level 4 merchant nearer $50,000.

No. The monthly assessments apply for being out of compliance, whether or not any card data was stolen. A breach discovered while non-compliant adds separate costs on top: a mandatory forensic investigation, card reissuance, credit monitoring and higher processing rates.

The future-dated requirements of PCI DSS 4.0, including 6.4.3 and 11.6.1, became mandatory on 31 March 2025.

Card brands assess the acquiring bank, which passes the charge on to the merchant under the terms of the merchant agreement. Sustained non-compliance can also end that agreement.

6.4.3 and 11.6.1 need evidence, not intentions.

Report URI produces a timestamped script inventory, continuous change detection and an exportable record of what browsers blocked and allowed — the evidence an assessor asks for.