Card-scheme assessments, real enforcement cases and the true cost of a payment-card data breach
Public schedules from Visa, Mastercard, American Express, Discover and JCB — combined with 2026 market data, documented cases in Spain and other jurisdictions, and a practical guide to telephone-payment risk.
| EDITORIAL POSITIONThere is no single statutory ‘PCI fine’. PCI DSS is an industry security standard. The financial exposure can combine payment-brand assessments, acquirer pass-through charges, forensic and remediation costs, card replacement and fraud recovery, regulatory penalties, litigation, business interruption and even loss of card acceptance. This report keeps those categories separate. |
| Field | Publication detail |
| Publisher | Pay by Call |
| Editorial cut-off | 14 August 2026 |
| Geographic scope | Global, with detailed EU, UK, Spain and US evidence |
| Evidence policy | Primary official sources wherever publicly available |
| Intended audience | Merchants, acquirers, payment service providers, contact centres, compliance, risk, security and legal teams |
This publication is an independent industry reference and does not constitute legal advice, card-scheme advice, certification or a guarantee of compliance. Scheme rules and commercial contracts can change; always confirm the rules and agreements that apply to your organisation.
PAY BY CALL | INDUSTRY REFERENCE 2026
Executive summary
The phrase ‘PCI DSS fine’ is widely used but technically imprecise. PCI DSS is maintained by the PCI Security Standards Council (PCI SSC), while compliance programmes and enforcement are operated by payment brands and acquirers. Public authorities may impose separate penalties under data-protection, cybersecurity, consumer-protection or sector-specific law. A merchant can therefore face several liabilities arising from the same event, none of which should automatically be attributed to PCI SSC.
No universal price list exists. Visa’s public Core Rules refer the specific Account Information Security programme amount to a separate programme guide; Mastercard and American Express publish several numerical schedules; Discover and JCB describe obligations and consequences but do not publish a complete general monetary tariff on their public PCI pages.
The public numbers are not all directly comparable. Visa’s general violation tiers are not an automatic PCI tariff; Mastercard’s figures are maximum assessments for specified categories; American Express’s non-validation fees are cumulative by missed deadline; regulatory fines are imposed under law, not by PCI SSC.
The payment market continues to expand. The euro area recorded 47.8 billion card payments worth €1.8 trillion in the second half of 2025. Remote transactions represented 19% of card payments by count and 30% by value, concentrating a disproportionate share of value in channels where the physical card is absent.
Fraud remains economically material even where the overall rate is low. The ECB and EBA reported €4.2 billion of payment fraud in the EEA in 2024. Fraud involving cards issued in the EU/EEA reached €1.329 billion, and card fraud was 17 times higher where the payee was outside the EEA — a context in which strong customer authentication is often not applied.
The UK provides one of the clearest current views of card-not-present risk. UK Finance reported £423.5 million of remote-purchase fraud in 2025 across 3,196,962 cases. Its remote-purchase category includes internet, telephone and mail order; it must not be represented as telephone fraud alone.
Public cases show that the headline regulatory penalty is only one component. Heartland disclosed a net 2009 breach-related expense of $128.9 million; Target disclosed $202 million net of insurance; Home Depot disclosed $198 million net of insurance. These totals combine settlements, claims, remediation and other items — they are not single PCI fines.
Telephone environments need special attention. If an agent hears or sees a primary account number, keys it into a workstation, or a recorder captures DTMF tones or security codes, people, endpoints, networks, applications and recordings can enter PCI DSS scope. Secure IVR and DTMF-masking architectures can materially reduce exposure when properly implemented.
| THE SINGLE MOST USEFUL MANAGEMENT CONCLUSIONTreat PCI DSS non-compliance as a chain-reaction risk, not a tariff. The practical goal is to minimise the amount of cardholder data entering the organisation, reduce the number of systems and people that can access it, validate the resulting scope correctly, and maintain evidence that controls operate throughout the year. |
1. The 2026 payment and fraud market in numbers
The figures below are the latest high-quality public observations available by the editorial cut-off. They do not all cover the same geography, period or definition, so they should be read as complementary indicators rather than combined into a single global total.
| Market indicator | Latest public observation | What it means for PCI risk |
| Euro-area card payments | 47.8bn payments, €1.8tn in H2 2025; average €39 | A very large and growing card-data attack surface |
| Remote share, euro area | 19% of card payments by count; 30% by value in H2 2025 | Remote channels represent higher average value and require CNP controls |
| Euro-area cards and terminals | 872.7m cards; 25.7m POS terminals; 93% of terminals contactless | A broad acceptance ecosystem with many dependencies |
| EEA payment fraud | €4.2bn in 2024, up from €3.5bn in 2023 | Low-rate fraud can still generate multi-billion-euro losses |
| EU/EEA-issued card fraud | €1.329bn in 2024, 29% higher year on year | Card fraud remains a major fraud category |
| Cross-border authentication effect | Card fraud rate 17× higher where payee was outside EEA | Authentication coverage and geography materially affect fraud |
| UK card fraud | £594.9m and 3.775m cases in 2025 | Large case volumes create operational and customer-service costs |
| UK remote-purchase fraud | £423.5m; 3,196,962 cases; average £132 in 2025 | Remote purchase was the dominant UK card-fraud loss category |
| Spain supervisory signal | Card-fraud transactions fell in H1 2025, but stolen card data remained a prominent cause | A falling aggregate does not eliminate credential-exposure risk |
| Global breach economics | IBM 2026 global average: $4.99m per breach | A general benchmark, not a PCI-specific cost estimate |
| Global threat context | Verizon 2026: 31% of breaches began with vulnerabilities; 48% involved ransomware | Scope reduction must be paired with basic cyber hygiene |
Source: ECB payment statistics, second half of 2025
Source: ECB/EBA payment fraud report
Source: UK Finance Annual Fraud Report 2026
Source: Banco de España Supervision Report 2025
Reading the market data correctly
Three distinctions matter. First, a fraud figure is not a PCI DSS non-compliance figure: fraud can occur despite compliance, and non-compliance can exist without detected fraud. Second, a card-not-present category normally groups e-commerce, telephone and mail-order transactions; public datasets rarely isolate telephone payments. Third, average breach-cost studies cover many industries and data types. They illuminate the wider economic context but cannot be used as a card-scheme penalty calculator.
| EVIDENCE GAPThere is no authoritative public global PCI DSS compliance rate, no complete worldwide register of card-scheme assessments, and no consistent public dataset that isolates telephone-payment breaches. Any publication claiming one precise global average PCI fine should disclose its methodology and sources. |
2. What a ‘PCI fine’ actually is
The organisations play different roles
| Actor | Primary role | What it may do after non-compliance or compromise |
| PCI SSC | Develops and maintains PCI security standards and supporting programmes | Does not act as a global fining authority for merchants |
| Payment brand / scheme | Operates network rules and a compliance or data-security programme | May assess a member, require investigation, impose validation, restrict or terminate participation |
| Issuer | Issues cards to cardholders | May replace cards, manage customer claims and participate in scheme recovery processes |
| Acquirer | Contracts with merchants and connects acceptance to a scheme | Validates merchant compliance, manages incidents and may contractually pass through costs |
| Merchant | Accepts the payment | Must protect account data, validate as required, notify incidents and manage suppliers |
| Service provider | Stores, processes, transmits or can affect the security of account data | Must meet applicable PCI obligations and support customer evidence |
| Regulator / court | Enforces public law and adjudicates claims | May impose fines, orders, damages or settlements independently of PCI programmes |
The six-layer cost stack
1. Card-scheme assessment. A payment brand may assess an issuer, acquirer or other member under its rules or programme.
2. Contractual pass-through. The member may recover all or part of the amount from a merchant or service provider under the acquiring or service agreement.
3. Investigation and remediation. Payment Card Industry Forensic Investigator (PFI), legal, notification, call-centre, monitoring, containment, replacement technology and revalidation costs can begin before liability is decided.
4. Card replacement and fraud recovery. Issuers and schemes may pursue recovery for operational costs and fraudulent transactions, subject to the relevant rules and facts.
5. Public-law and civil exposure. Data-protection authorities, consumer regulators, attorneys general, class actions and contractual claims operate separately from PCI SSC.
6. Business impact. Downtime, delayed sales, customer churn, higher acquiring cost, reserve requirements, restrictions and loss of card acceptance can exceed the published assessment.
| TERMINOLOGY RULE FOR ACCURATE PUBLISHINGVisa, Mastercard, American Express, Discover and JCB are payment brands, schemes or networks in this context — not simply ‘card issuers’. An assessment imposed on an acquirer should not automatically be described as a fine imposed directly on the merchant. |
Compliance validation is not immunity
An Attestation of Compliance, Report on Compliance or Self-Assessment Questionnaire is evidence of validation for a defined environment and period. It is not a warranty that no control can fail later. After an incident, forensic evidence may show that the entity was not compliant at the relevant time, that scope was incomplete, or that a service-provider dependency was misunderstood. Conversely, Visa states that assessments may be waived where forensic investigation does not identify non-compliance, subject to its programme terms.
3. PCI DSS v4.0.1 in 2026
PCI DSS v4.0.1, published in June 2024, is the active reference point for this report. PCI SSC described v4.0.1 as a limited revision that added clarification and corrected formatting and typographical issues; it did not add or delete requirements and did not alter the 31 March 2025 effective date for future-dated requirements.
By 2026, organisations should no longer be treating those future-dated controls as a distant roadmap. PCI SSC stated that 51 of 64 new requirements in the v4.x generation became effective on 31 March 2025. The practical emphasis is continuous evidence: assigned responsibilities, risk analyses, secure configurations, vulnerability management, access control, monitoring, incident readiness, supplier governance and the security of payment-page scripts and e-commerce channels.
Source: PCI DSS v4.0.1 publication notice
Source: PCI SSC guidance on future-dated v4.x requirements
A minimum evidence file for 2026
A current, documented cardholder data environment (CDE) scope, including connected systems and systems that can affect security.
Data-flow diagrams covering e-commerce, payment terminals, telephone/IVR, recordings, VoIP, remote support and service providers.
A current inventory of stored account data, with a defensible business need, retention period and secure deletion process.
Evidence that sensitive authentication data — including card verification codes — is not retained after authorisation.
Defined responsibility matrices for the entity, acquirer, payment gateway, contact-centre platform, telephony provider and other service providers.
Quarterly and annual control evidence appropriate to the validation method, plus incident-response testing and training.
A process for significant change, new integrations, mergers, contact-centre outsourcing and supplier changes so that scope is reassessed before go-live.
4. Public card-scheme assessment and fee schedules
This section reports only amounts supported by public scheme material available by 14 August 2026. Currency is US dollars unless stated. ‘Up to’ means a maximum, not an automatic invoice. Contract terms, programme guides, regional rules, facts of the case and the member relationship can change the result.
4.1 Visa
Visa’s public Account Information Security (AIS) material states that Visa manages the enforcement and validation of PCI DSS compliance and that issuers and acquirers are responsible for ensuring that their agents, merchants and service providers comply. Importantly, Visa explains that it assesses the issuer or acquirer, which pays the assessment, and that the member must not represent to a merchant or agent that Visa imposed the assessment directly on that merchant or agent.
The Visa Core Rules dated 18 April 2026 refer the specific AIS non-compliance assessment amount to the AIS Programme Guide rather than publishing it in the Core Rules. The general violation schedule below is public, but it must not be presented as an automatic PCI DSS tariff.
| Visa general violation category | Month / event | Public assessment |
| Tier 1 | 1st / 2nd / 3rd / 4th / 5th / 6th | $25k / $50k / $75k / $100k / $125k / $150k |
| Tier 1 | Each month thereafter | Previous month + $25k |
| Tier 2 | 1st / 2nd / 3rd / 4th / 5th / 6th | $5k / $10k / $20k / $30k / $40k / $50k |
| Tier 2 | Each month thereafter | Previous month + $10k |
| Case administration | Applicable case | $1,000 case fee |
| Significant violation | On confirmation | $50k |
| Significant violation | Each month after correction deadline | $50k–$1m |
| Failure to notify/respond to loss or theft | Per incident | Up to $100k |
| VISA CAVEATUse the table only as a general Core Rules reference. A PCI/AIS-specific amount may depend on the AIS Programme Guide and the facts of the member’s case. Do not label the Tier 1 and Tier 2 table ‘Visa’s PCI fines’ without this qualification. |
Source: Visa Account Information Security and compliance information
Source: Visa Core Rules and Visa Product and Service Rules, 18 April 2026
4.2 Mastercard
Mastercard’s Security Rules and Procedures — Merchant Edition dated 4 August 2026 publishes maximum assessments by merchant and service-provider level. The table is expressed by calendar-year violation, not by the number of months a merchant remains non-compliant.
| Entity / category | 1st violation | 2nd | 3rd | 4th |
| Level 1 or 2 merchant | Up to $25k | Up to $50k | Up to $100k | Up to $200k |
| Level 3 merchant | Up to $10k | Up to $20k | Up to $40k | Up to $80k |
| Level 1 or 2 service provider | Up to $25k | Up to $50k | Up to $100k | Up to $200k |
| Additional Mastercard provision | Public maximum / consequence |
| Account data compromise confirms a PCI SSC violation | Up to $100,000 per violation |
| Failure to comply with specified account-data compromise procedures | Up to $25,000 per day |
| Persistent or serious non-compliance | Termination, deregistration or removal from listings may be possible under applicable rules |
| Compromised merchant | May be reclassified as Level 1, increasing validation obligations |
Mastercard merchant levels
| Level | Published transaction threshold / status |
| Level 1 | More than 6 million Mastercard and Maestro transactions annually, or otherwise classified by Mastercard |
| Level 2 | More than 1 million and up to 6 million transactions annually |
| Level 3 | More than 20,000 and up to 1 million combined e-commerce transactions annually |
| Level 4 | All other merchants |
A 2026 reporting change also matters. Effective 1 January 2026, Mastercard’s rules require an issuer or acquirer to notify the Mastercard Site Data Protection programme promptly where it determines or reasonably believes that a service provider or merchant is not compliant, subject to stated Validation Exemption Programme conditions. Broader merchant notice provisions are scheduled for 1 January 2027. Organisations should verify the current text and effective dates when publishing or acting on this point.
Source: Mastercard rules and standards portal
Source: Mastercard Security Rules and Procedures — Merchant Edition, 4 August 2026
4.3 American Express
American Express’s International Merchant Regulations, October 2025 edition, publish cumulative non-validation fees. The first missed deadline may therefore be followed by additional charges until the required validation documentation is submitted. Local-currency equivalents and regional qualifications may apply; the published table notes that these fees do not apply in Argentina.
| American Express category | 1st deadline | 2nd deadline | 3rd deadline |
| Level 1 merchant / service provider | $25,000 | +$35,000 | +$45,000 |
| Level 2 merchant | $5,000 | +$10,000 | +$15,000 |
| Level 3 or 4 merchant | $50 | +$100 | +$250 |
| Data-incident provision | Published amount / deadline |
| Data-incident non-compliance fee | Up to $100,000 per incident |
| Indemnity for qualifying incident involving at least 10,000 American Express card numbers plus expiration date or sensitive authentication data | $5 per affected account, subject to conditions and exclusions |
| Initial incident notice | Within 72 hours |
| PFI engagement for incident involving at least 10,000 unique card numbers | Within five days, subject to the applicable rules |
Source: American Express Data Security Operating Policy and merchant security page
Source: American Express International Merchant Regulations, October 2025
4.4 Discover
Discover Global Network publicly requires ongoing PCI DSS compliance and validation appropriate to the participant. Its public compliance material warns that a breach may generate fraud losses, non-compliance fees and other damages. However, the public page reviewed for this report does not provide a complete general numerical schedule comparable to the Mastercard and American Express tables above. The absence of a public tariff must not be interpreted as the absence of financial exposure.
Source: Discover Global Network PCI compliance and validation requirements
4.5 JCB
JCB’s public Data Security Programme expressly covers merchants and service providers and includes e-commerce, mail-order/telephone-order and phone-call service transactions in its validation framework. JCB publishes its PCI DSS obligations and programme structure, but the public programme pages reviewed for this report do not contain a complete general numerical non-compliance tariff. Acquirer agreements and current regional programme documentation remain decisive.
Source: JCB Data Security Programme
Source: JCB PCI DSS compliance information
5. Cross-scheme comparison and enforcement path
| Scheme | What is publicly quantifiable? | Critical qualification |
| Visa | General violation tiers; significant-violation range; incident notice/response maximum | AIS-specific amount is referred to a separate programme guide; member is assessed |
| Mastercard | Merchant/service-provider maxima by violation; $100k per confirmed PCI violation; $25k/day procedure maximum | Amounts are maxima; annual violation sequence and entity level matter |
| American Express | Cumulative non-validation deadlines; up to $100k incident fee; conditional $5/account indemnity | Deadlines, incident thresholds, regional rules and exclusions apply |
| Discover | Consequences identified publicly, but no complete numerical general schedule located | Confirm current network and acquirer documentation |
| JCB | Programme and validation obligations, but no complete numerical general schedule located | MOTO and phone-call services are expressly in programme scope |
A typical enforcement and cost path
1. A validation deadline is missed, a control gap is identified, or a suspected account-data compromise is reported.
2. The merchant or service provider notifies its acquirer or customer according to contracts and scheme rules; the member notifies the scheme where required.
3. The scheme or acquirer may require investigation, evidence, a remediation plan, enhanced validation or a PFI investigation.
4. If non-compliance is found, the scheme may assess the member. The acquirer may pass through scheme assessments and its own contractual costs, subject to the agreement and applicable law.
5. Regulatory investigations, card replacement, fraud recovery, claims, notification and litigation can proceed on separate tracks.
6. Continued non-compliance can escalate amounts, validation burden or participation restrictions even after the original breach is contained.
| WHY THE DOMINO METAPHOR IS ACCURATEThe trigger may be a single failed control, but the cost propagates through several contracts and legal regimes. Each party — merchant, service provider, acquirer, scheme, issuer and regulator — has a different mandate, evidence threshold and recovery mechanism. |
6. Public cases in Spain and worldwide
The cases below are included because official decisions or public company filings provide verifiable amounts. They illustrate the scale and composition of exposure, not a direct price comparison. Regulatory decisions are not PCI SSC fines, while company totals often include settlements, claims, remediation and insurance effects.
| Case | Publicly documented facts | Financial outcome and correct classification |
| Air Europa — Spain | AEPD: 489,000 people; 1.5m records; forensic evidence indicated more than 2.7m unique card numbers exfiltrated. Data included card number, expiry and CVV. | €500k for Article 32(1) GDPR security infringement plus €100k for late Article 33 notification: €600k regulatory fine, not a scheme assessment. |
| British Airways — UK | ICO: 429,612 people affected; payment-card number and CVV were involved for subsets of data subjects. | £20m data-protection penalty. Regulatory enforcement, not a PCI SSC fine. |
| Heartland — US | Company filing recorded scheme-related settlements and recovery programmes following the 2008 intrusion. | $59.3m Visa; $34.4m Mastercard paid; $3.5m American Express; $5m Discover. 2009 expense $132.9m gross, $128.9m net after $4m insurance. Mostly settlements/recoveries, not one PCI fine. |
| Target — US | More than 40m payment-card customer accounts affected, according to the California Attorney General settlement announcement. | $18.5m multistate AG settlement. Target’s 2017 10-K reported $292m cumulative gross breach expense, $90m insurance, $202m net. |
| Home Depot — US | Approximately 40m payment cards affected, according to the New York Attorney General. | $17.5m multistate AG settlement. Home Depot’s 2017 10-K reported $298m gross breach costs, $100m insurance, $198m net. |
6.1 Air Europa: the Spanish reference case
The Spanish Data Protection Agency’s Air Europa proceeding is particularly relevant because the compromised dataset included card number, expiry date and card verification value. The AEPD recorded 489,000 affected people and 1.5 million records, while the forensic material described exfiltration of more than 2.7 million unique card numbers. The authority imposed €500,000 for infringement of Article 32(1) GDPR and €100,000 for infringement of Article 33, producing a €600,000 total.
The publication lesson is precise: this was a data-protection authority’s penalty based on GDPR obligations. It should not be described as ‘a PCI DSS fine’, even though the facts concern payment-card data and the incident is highly relevant to PCI risk management.
Source: AEPD decision PS/00179/2020 — Air Europa
6.2 Heartland: scheme-related costs can dwarf a simple tariff
Heartland Payment Systems’ 2010 annual filing provides rare public granularity. It recorded $59.3 million paid in connection with Visa, including a $780,000 credit for earlier fines, and $34.4 million paid in connection with Mastercard, while describing recovery offers of $41.4 million including a $6.6 million credit for earlier fines. It also recorded $3.5 million for American Express and $5 million for Discover. Total 2009 breach-related expense was $132.9 million, or $128.9 million after $4 million of insurance proceeds.
These figures should be quoted with their accounting context. The majority were settlement and recovery arrangements and wider breach costs, not a single schedule-based PCI DSS assessment.
Source: Heartland Payment Systems 2010 Form 10-K
6.3 Target and Home Depot: gross cost, insurance and regulatory settlement
Target’s 2017 Form 10-K reported $292 million of cumulative gross data-breach expense, offset by $90 million of insurance, for $202 million net. A separate multistate attorneys-general settlement announced by California was $18.5 million. The settlement announcement described more than 40 million payment-card customer accounts as affected.
Home Depot’s 2017 Form 10-K reported $298 million of gross breach costs and $100 million of insurance reimbursement, leaving $198 million net. In 2020, a coalition of attorneys general announced a $17.5 million settlement; New York’s announcement described approximately 40 million payment cards as affected.
Source: Target Corporation 2017 Form 10-K
Source: California Attorney General Target settlement announcement
Source: The Home Depot 2017 Form 10-K
Source: New York Attorney General Home Depot settlement announcement
6.4 British Airways: card data inside a broader security failure
The UK Information Commissioner’s Office fined British Airways £20 million following a cyberattack affecting personal data relating to 429,612 people. The penalty notice records payment-card numbers and CVVs for subsets of affected data. As with Air Europa, the amount is a public-law data-protection penalty. It is relevant evidence of the regulatory layer, not a substitute for any card-scheme analysis.
Source: ICO British Airways monetary penalty notice
What the cases collectively show
A regulatory fine may be only a small percentage of the total disclosed cost.
Insurance can reduce net accounting expense but may not cover every category, future premium impact or operational harm.
Amounts announced by schemes, regulators and companies use different legal and accounting definitions.
The largest costs often arise after the incident through settlements, recovery programmes, remediation and customer response.
Accurate reporting must state who imposed or received the amount and what the amount represents.
7. Telephone payments, contact centres and CNP exposure
Telephone payments remain operationally important for travel, healthcare, utilities, public services, collections, insurance, hospitality and customer support. They are also easy to underestimate because the cardholder is speaking to a person rather than entering data on a web checkout. From a security perspective, however, the card data still travels through people, telephony systems, endpoints, networks and payment applications unless the architecture deliberately prevents it.
7.1 How a conventional agent-assisted payment expands scope
| Exposure point | How account data may enter scope | Typical control question |
| Agent | Hears the PAN, expiry date or security code | Can the agent avoid hearing or seeing card data? |
| Desktop | Agent keys data into a browser, virtual terminal or CRM | Is entry isolated from the corporate endpoint? |
| Telephony / VoIP | Voice or signalling traffic carries account data within the entity’s control | Is the network component in the assessed scope? |
| Call recording | Audio or DTMF tones capture card data | Are payment segments suppressed, masked or securely deleted? |
| CRM and notes | Agents paste or type account data into free-text fields | Are fields blocked, monitored and purged? |
| Remote work | Home networks, softphones, screen tools or local notes increase exposure | Does the design remain secure outside the office? |
| Supplier integrations | Contact-centre, payment and telephony providers can affect security | Are responsibilities and evidence contractually defined? |
7.2 Call recordings and security codes
PCI SSC FAQ 1210 states that sensitive authentication data, including card verification codes, must not be retained after authorisation even if encrypted. If audio recordings contain that data, storage after authorisation violates the applicable requirement. PCI SSC’s guidance is to prevent recording through suppression or redaction, or to securely delete the data immediately after authorisation where prevention is not possible.
Muting an agent’s headset is not necessarily sufficient if DTMF tones, screen recordings, diagnostic logs or downstream platforms still receive the data. The control objective must be assessed end to end.
Source: PCI SSC FAQ 1210 — audio recordings containing card verification codes
7.3 VoIP is not automatically out of scope
PCI SSC FAQ 1153 explains that VoIP components carrying account data can be in scope while the data is within the entity’s control. The analysis depends on architecture, responsibility and whether the systems store, process, transmit or can affect the security of account data. Labelling a system ‘telephony’ does not itself remove PCI obligations.
Source: PCI SSC FAQ 1153 — VoIP and PCI DSS scope
7.4 Secure design patterns
DTMF masking or suppression: the cardholder enters digits on the telephone keypad while the agent remains connected; tones are intercepted or transformed before reaching the agent and enterprise environment.
Secure IVR: the caller is transferred or bridged to an automated payment flow so that the merchant’s people and systems do not receive raw account data.
Tokenisation: the merchant retains a token for later business processes instead of the primary account number, subject to correct implementation and scope analysis.
Hosted payment orchestration: a PCI-validated provider captures and transmits the card data directly to the payment processor while the merchant receives status rather than raw credentials.
Recording controls: payment segments are suppressed and screen/voice recording behaviour is tested, including failure states and remote-agent scenarios.
| OUTSOURCING DOES NOT OUTSOURCE ACCOUNTABILITYUsing a PCI DSS validated service provider can reduce scope and technical exposure, but the merchant still needs due diligence, a responsibility matrix, current validation evidence, secure integration, incident procedures and monitoring of the service relationship. |
Source: PCI SSC guidance on accepting telephone payments securely
8. PCI DSS and EMV 3-D Secure: different controls
PCI DSS and EMV 3-D Secure (EMV 3DS) address different parts of payment risk. PCI DSS protects account data and the systems, people and processes that store, process, transmit or can affect its security. EMV 3DS enables cardholder authentication and data exchange for card-not-present transactions, helping issuers and merchants manage fraud and authorisation decisions. One does not replace the other.
| Control framework | Primary purpose | What it does not do |
| PCI DSS | Protect account data and reduce compromise risk across the payment environment | Does not authenticate every cardholder or guarantee that a transaction is legitimate |
| EMV 3-D Secure | Authenticate the consumer and exchange risk data for CNP transactions | Does not by itself secure all systems that handle card data or remove PCI DSS obligations |
The strongest design combines data minimisation with transaction authentication: prevent raw card data entering the merchant environment where possible, validate the reduced scope, and apply appropriate authentication and fraud controls to the transaction channel.
Source: EMVCo — EMV 3-D Secure
Source: PCI SSC — PCI 3DS Core Security Standard
9. A practical exposure model and board-level checklist
A model, not a tariff calculator
| TOTAL EXPOSURE ≈scheme and contractual assessments + forensic investigation + containment and remediation + notification and customer support + card replacement and fraud recovery + regulatory enforcement and litigation + downtime, churn and higher cost of acceptance |
The terms are not independent or linear. A slow notification can increase regulatory exposure; incomplete scope can prolong forensics; poor supplier records can delay containment; and loss of card acceptance can convert a compliance issue into a revenue crisis. The model is therefore best used to identify missing cost categories, not to forecast an exact amount.
Scenario guide
| Scenario | Likely first-order exposure | Escalation risk |
| Validation overdue, no known breach | Non-validation fee/assessment, acquirer charges, urgent assessment and remediation | Cumulative or repeated assessments; trading restrictions |
| Control gap or suspected compromise | Incident response, legal and forensic triage, evidence preservation, notification decisions | PFI requirement, wider scope, regulatory notice |
| Confirmed compromise and non-compliance | All investigation/remediation costs plus potential scheme and contractual assessments | Card recovery, regulator, litigation, termination and reputation |
| Compromise but no non-compliance found | Incident and business costs remain | Some programme assessments may be waived or reduced under applicable rules; never assume immunity |
Board and executive checklist
Can management state exactly where account data enters, travels and is stored — including telephone, recording and remote-work systems?
Has the organisation reduced scope by design, or merely documented a large and complex CDE?
Is the validation method current and appropriate to merchant/service-provider level and acquirer requirements?
Is there evidence that controls operate continuously, not only during the annual assessment?
Are payment-page scripts, e-commerce dependencies and change-detection controls covered under PCI DSS v4.x?
Can security codes enter recordings, logs, CRM notes, quality-monitoring tools, screen captures or AI transcription systems?
Are all relevant service providers identified, validated and mapped to a written responsibility matrix?
Do contracts clearly allocate incident notice, PFI, assessment, card-recovery, legal and insurance responsibilities?
Has the incident plan been tested with the acquirer, gateway, telephony provider, insurer, legal counsel and communications team?
Can the organisation preserve evidence without delaying containment or mandatory notice?
Does cyber insurance cover PCI/scheme assessments where legally insurable, forensic costs, card replacement, business interruption and regulatory response?
Are senior leaders shown gross exposure as well as expected insurance recovery?
Is there a defined process to reassess scope after acquisitions, new contact-centre technology, cloud migrations and supplier changes?
Are customers and agents given a payment route that does not require disclosing card details aloud?
Has management tested failure modes — transfer failure, recording restart, fallback to manual entry and remote-agent exceptions?
10. How Pay by Call reduces telephone-payment exposure
Pay by Call is designed to separate card capture from agents and ordinary corporate systems. Through its PCI-as-a-Service (PCIaaS) approach, card details can be collected through a controlled payment flow while the organisation and agent receive transaction status rather than the raw credentials. The architectural goal is data minimisation: fewer people, endpoints, applications and recordings exposed to account data.
Security and payment capabilities
PCI DSS Level 1 service-provider posture, supporting a controlled payment-data environment and customer due diligence.
Telephone-payment flows designed so agents do not need to hear, see or type card details into corporate systems.
PCIaaS orchestration that helps organisations reduce the technical and operational surface of their PCI DSS scope.
PBC 3DS, a native voice approach to 3-D Secure designed to add cardholder authentication to telephone payment journeys. Patent pending; international patent applications have been filed.
Integration patterns intended to return payment result and business references without returning raw card data to the merchant environment.
| AVOID THE DOMINO EFFECT WITH PAY BY CALL A single exposed payment credential can trigger investigation, remediation, contractual recovery, regulator attention and customer harm. Pay by Call helps prevent that chain reaction by keeping card data away from agents, recordings and day-to-day corporate systems while supporting secure payment and authentication journeys. |
A reduced-scope architecture must still be validated against the organisation’s actual integration, contracts, people and processes. Pay by Call can support scope reduction and control design; the customer remains responsible for confirming its own PCI DSS obligations with its acquirer and qualified advisers.
Frequently asked questions
Is PCI DSS a law?
PCI DSS is an industry security standard, not a single global statute. Contracts and payment-brand rules make it commercially enforceable, while regulators may impose separate duties and penalties under public law.
Does PCI SSC fine merchants?
PCI SSC maintains standards and programmes; it is not a global merchant-fining authority. Payment brands and members operate compliance programmes, and regulators enforce applicable law.
How much is the fine for PCI DSS non-compliance?
There is no universal amount. The public schedules in this report differ by scheme, entity level, missed deadline, violation, incident and region. Acquirer contracts and non-public programme documentation can also matter.
Can a merchant be charged even if the payment brand assesses the acquirer?
Potentially, yes. An acquiring agreement may permit pass-through or recovery of assessments and other costs. The exact contractual and legal basis must be reviewed. Visa’s public material also warns members not to misrepresent an assessment as having been imposed directly by Visa on the merchant.
Does annual validation prove that an organisation was compliant at the time of a breach?
Not automatically. Validation covers a defined scope and evidence set. A later investigation can identify scope errors, control failures or changes. It can also find that non-compliance was not present, which may affect programme treatment.
Does outsourcing card capture eliminate PCI DSS?
Usually not completely. A validated provider can materially reduce scope, but the merchant retains supplier governance, integration, policy, validation and incident responsibilities.
May a call recording contain a CVV?
Sensitive authentication data such as a CVV must not be retained after authorisation, even if encrypted. Recording suppression, redaction or immediate secure deletion must be designed and tested.
Are telephone payments included in card-not-present fraud data?
Often yes, but normally within a broader remote-purchase or CNP category that also includes e-commerce and mail order. Public data rarely isolates telephone payments, so the total category must not be described as MOTO-only.
Does 3-D Secure make a business PCI compliant?
No. EMV 3DS supports cardholder authentication and fraud management. PCI DSS protects account data and the environment that handles it. They are complementary.
What should a company do first?
Map every payment channel and data flow, remove unnecessary storage and exposure, verify service-provider responsibilities, validate the reduced scope and test incident response. In telephone environments, start by determining whether agents or recordings can receive card data.
Conclusion
The risk of PCI DSS non-compliance in 2026 cannot be understood through one headline fine. Public scheme schedules show that some assessments can escalate quickly, but the documented cases show a wider truth: forensics, recovery, regulators, litigation, customer response and business interruption can dominate the final cost.
The most defensible strategy is to reduce the amount of account data the organisation handles, keep the validated scope accurate, maintain year-round control evidence and prepare for coordinated incident response. For telephone payments, that means designing the journey so card details do not pass through agents, recordings or general corporate technology in the first place.
Methodology, limitations and primary sources
Research method
This report reviewed public payment-brand rules and compliance pages, PCI SSC standards and FAQs, central-bank and industry fraud statistics, regulator decisions and listed-company filings available by 14 August 2026. Numerical schedules were included only where a primary public document supported them. Where a scheme publishes the existence of obligations or consequences but not a complete tariff, the report says so rather than substituting unattributed secondary estimates.
Limitations
Payment-brand programme guides, bulletins, bilateral contracts and regional terms may not be public and may change after the editorial cut-off.
Public cases disclose different categories of cost and are not directly comparable.
Market statistics use different definitions, currencies, periods and geographic scopes.
The report does not determine whether any named organisation was PCI DSS compliant except where the source expressly addresses that issue.
The absence of a published numerical schedule does not imply zero liability.
This document is not legal, contractual, forensic, certification or insurance advice.
Primary source register
1. PCI Security Standards Council — PCI DSS — standard overview and enforcement-routing information
2. PCI SSC — Document Library — official standards and supporting material
3. PCI SSC — PCI DSS v4.0.1 publication notice — revision scope and June 2024 publication
4. PCI SSC — Future-dated v4.x requirements — 31 March 2025 effective-date context
5. PCI SSC — Telephone payment guidance — contact-centre and telephone-payment security
6. PCI SSC FAQ 1210 — audio recordings and card verification codes
7. PCI SSC FAQ 1153 — VoIP and PCI DSS scope
8. Visa — Account Information Security — enforcement, member assessment and waiver explanation
9. Visa Core Rules, 18 April 2026 — public violation schedules and AIS cross-reference
10. Mastercard — Rules and standards portal — current public rules index
11. Mastercard Security Rules and Procedures — Merchant Edition, 4 August 2026 — merchant/service-provider assessments and compromise provisions
12. American Express — Data Security Operating Policy — current merchant security programme
13. American Express International Merchant Regulations, October 2025 — non-validation fees and incident provisions
14. Discover Global Network — PCI compliance — validation obligations and consequences
15. JCB — Data Security Programme — programme scope including MOTO and phone-call services
16. JCB — PCI DSS — public compliance information
17. EMVCo — EMV 3-D Secure — authentication purpose and CNP context
18. PCI SSC — PCI 3DS Core Security Standard — 3DS component security
19. ECB — Payment statistics, second half of 2025 — published 22 July 2026
20. ECB/EBA — Payment fraud report — EEA fraud statistics for 2024
21. UK Finance — Annual Fraud Report 2026 — UK fraud statistics for 2025
22. Banco de España — Supervision Report 2025, Chapter 4 — Spanish payment-security supervisory indicators
23. Banco de España — Complaints report press note — accepted complaints involving card and transfer fraud
24. IBM — Cost of a Data Breach Report 2026 — general global breach-cost benchmark
25. Verizon — Data Breach Investigations Report 2026 — general threat and breach patterns
26. AEPD — Air Europa decision PS/00179/2020 — Spanish enforcement case
27. Heartland Payment Systems — 2010 Form 10-K — scheme-related settlements and breach expense
28. ICO — British Airways penalty notice — UK enforcement case
29. Target Corporation — 2017 Form 10-K — gross, insurance and net breach costs
30. California Attorney General — Target settlement — multistate regulatory settlement
31. The Home Depot — 2017 Form 10-K — gross, insurance and net breach costs
32. New York Attorney General — Home Depot settlement — multistate regulatory settlement
Pay by Call | PCI DSS Non-Compliance Reference 2026 | Page
PAY BY CALL | INDUSTRY REFERENCE 2026
Appendix: copy-ready reference tables
The following compact tables are designed for editorial reuse. Preserve the qualification text whenever copying a monetary figure. Do not remove ‘up to’, convert a general rule into a PCI-specific tariff, or describe regulatory penalties as PCI SSC fines.
A.1 Visa public general rules — editorial copy table
| category | period_or_event | public_amount_usd | qualification |
| Tier 1 | months 1–6 | 25k; 50k; 75k; 100k; 125k; 150k | General Core Rules schedule; not automatic AIS/PCI tariff |
| Tier 1 | month 7 onward | previous month + 25k | General Core Rules schedule |
| Tier 2 | months 1–6 | 5k; 10k; 20k; 30k; 40k; 50k | General Core Rules schedule; not automatic AIS/PCI tariff |
| Tier 2 | month 7 onward | previous month + 10k | General Core Rules schedule |
| Case fee | applicable case | 1k | Administrative case fee |
| Significant violation | confirmation | 50k | General significant-violation rule |
| Significant violation | monthly after deadline | 50k–1m | Range; facts and rule application matter |
| Loss/theft notice or response failure | per incident | up to 100k | Maximum |
A.2 Mastercard public assessment table
| entity | first | second | third | fourth | qualification |
| Level 1/2 merchant | ≤25k | ≤50k | ≤100k | ≤200k | per calendar-year violation; maxima |
| Level 3 merchant | ≤10k | ≤20k | ≤40k | ≤80k | per calendar-year violation; maxima |
| Level 1/2 service provider | ≤25k | ≤50k | ≤100k | ≤200k | per calendar-year violation; maxima |
A.3 American Express public non-validation table
| entity | first_deadline | second_deadline | third_deadline | qualification |
| Level 1 merchant / SP | 25k | +35k | +45k | cumulative; local equivalent; regional qualifications |
| Level 2 merchant | 5k | +10k | +15k | cumulative; local equivalent; regional qualifications |
| Level 3/4 merchant | 50 | +100 | +250 | cumulative; local equivalent; regional qualifications |
A.4 Public case table
| case | country | amount | classification | key caveat |
| Air Europa | Spain | €600k | GDPR regulator penalty | not a PCI SSC/scheme fine |
| British Airways | UK | £20m | data-protection penalty | not a PCI SSC/scheme fine |
| Heartland | US | $128.9m net 2009 expense | settlements/recovery/wider breach cost | not one PCI fine |
| Target | US | $202m net cumulative expense; $18.5m AG settlement | company cost + regulator settlement | different cost categories |
| Home Depot | US | $198m net cost; $17.5m AG settlement | company cost + regulator settlement | different cost categories |
A.5 Data citation table
| metric | period | value | source | do_not_infer |
| Euro-area card payments | H2 2025 | 47.8bn; €1.8tn | ECB | not PCI incident volume |
| Euro-area remote share | H2 2025 | 19% count; 30% value | ECB | not telephone-only |
| EEA payment fraud | 2024 | €4.2bn | ECB/EBA | not all card fraud |
| EU/EEA-issued card fraud | 2024 | €1.329bn | ECB/EBA | not PCI non-compliance |
| UK remote-purchase fraud | 2025 | £423.5m; 3,196,962 cases | UK Finance | includes internet, phone and mail order |
| Global average breach cost | 2026 report | $4.99m | IBM | not PCI-specific |