PCI DSS Non-Compliance Fines in 2026

Colourful domino tiles illustrating the cascading financial and operational consequences of PCI DSS non-compliance in 2026.

Card-scheme assessments, real enforcement cases and the true cost of a payment-card data breach

Public schedules from Visa, Mastercard, American Express, Discover and JCB — combined with 2026 market data, documented cases in Spain and other jurisdictions, and a practical guide to telephone-payment risk.

EDITORIAL POSITIONThere is no single statutory ‘PCI fine’. PCI DSS is an industry security standard. The financial exposure can combine payment-brand assessments, acquirer pass-through charges, forensic and remediation costs, card replacement and fraud recovery, regulatory penalties, litigation, business interruption and even loss of card acceptance. This report keeps those categories separate.
FieldPublication detail
PublisherPay by Call
Editorial cut-off14 August 2026
Geographic scopeGlobal, with detailed EU, UK, Spain and US evidence
Evidence policyPrimary official sources wherever publicly available
Intended audienceMerchants, acquirers, payment service providers, contact centres, compliance, risk, security and legal teams

This publication is an independent industry reference and does not constitute legal advice, card-scheme advice, certification or a guarantee of compliance. Scheme rules and commercial contracts can change; always confirm the rules and agreements that apply to your organisation.

PAY BY CALL | INDUSTRY REFERENCE 2026

Executive summary

The phrase ‘PCI DSS fine’ is widely used but technically imprecise. PCI DSS is maintained by the PCI Security Standards Council (PCI SSC), while compliance programmes and enforcement are operated by payment brands and acquirers. Public authorities may impose separate penalties under data-protection, cybersecurity, consumer-protection or sector-specific law. A merchant can therefore face several liabilities arising from the same event, none of which should automatically be attributed to PCI SSC.

No universal price list exists. Visa’s public Core Rules refer the specific Account Information Security programme amount to a separate programme guide; Mastercard and American Express publish several numerical schedules; Discover and JCB describe obligations and consequences but do not publish a complete general monetary tariff on their public PCI pages.

The public numbers are not all directly comparable. Visa’s general violation tiers are not an automatic PCI tariff; Mastercard’s figures are maximum assessments for specified categories; American Express’s non-validation fees are cumulative by missed deadline; regulatory fines are imposed under law, not by PCI SSC.

The payment market continues to expand. The euro area recorded 47.8 billion card payments worth €1.8 trillion in the second half of 2025. Remote transactions represented 19% of card payments by count and 30% by value, concentrating a disproportionate share of value in channels where the physical card is absent.

Fraud remains economically material even where the overall rate is low. The ECB and EBA reported €4.2 billion of payment fraud in the EEA in 2024. Fraud involving cards issued in the EU/EEA reached €1.329 billion, and card fraud was 17 times higher where the payee was outside the EEA — a context in which strong customer authentication is often not applied.

The UK provides one of the clearest current views of card-not-present risk. UK Finance reported £423.5 million of remote-purchase fraud in 2025 across 3,196,962 cases. Its remote-purchase category includes internet, telephone and mail order; it must not be represented as telephone fraud alone.

Public cases show that the headline regulatory penalty is only one component. Heartland disclosed a net 2009 breach-related expense of $128.9 million; Target disclosed $202 million net of insurance; Home Depot disclosed $198 million net of insurance. These totals combine settlements, claims, remediation and other items — they are not single PCI fines.

Telephone environments need special attention. If an agent hears or sees a primary account number, keys it into a workstation, or a recorder captures DTMF tones or security codes, people, endpoints, networks, applications and recordings can enter PCI DSS scope. Secure IVR and DTMF-masking architectures can materially reduce exposure when properly implemented.

THE SINGLE MOST USEFUL MANAGEMENT CONCLUSIONTreat PCI DSS non-compliance as a chain-reaction risk, not a tariff. The practical goal is to minimise the amount of cardholder data entering the organisation, reduce the number of systems and people that can access it, validate the resulting scope correctly, and maintain evidence that controls operate throughout the year.

1. The 2026 payment and fraud market in numbers

The figures below are the latest high-quality public observations available by the editorial cut-off. They do not all cover the same geography, period or definition, so they should be read as complementary indicators rather than combined into a single global total.

Market indicatorLatest public observationWhat it means for PCI risk
Euro-area card payments47.8bn payments, €1.8tn in H2 2025; average €39A very large and growing card-data attack surface
Remote share, euro area19% of card payments by count; 30% by value in H2 2025Remote channels represent higher average value and require CNP controls
Euro-area cards and terminals872.7m cards; 25.7m POS terminals; 93% of terminals contactlessA broad acceptance ecosystem with many dependencies
EEA payment fraud€4.2bn in 2024, up from €3.5bn in 2023Low-rate fraud can still generate multi-billion-euro losses
EU/EEA-issued card fraud€1.329bn in 2024, 29% higher year on yearCard fraud remains a major fraud category
Cross-border authentication effectCard fraud rate 17× higher where payee was outside EEAAuthentication coverage and geography materially affect fraud
UK card fraud£594.9m and 3.775m cases in 2025Large case volumes create operational and customer-service costs
UK remote-purchase fraud£423.5m; 3,196,962 cases; average £132 in 2025Remote purchase was the dominant UK card-fraud loss category
Spain supervisory signalCard-fraud transactions fell in H1 2025, but stolen card data remained a prominent causeA falling aggregate does not eliminate credential-exposure risk
Global breach economicsIBM 2026 global average: $4.99m per breachA general benchmark, not a PCI-specific cost estimate
Global threat contextVerizon 2026: 31% of breaches began with vulnerabilities; 48% involved ransomwareScope reduction must be paired with basic cyber hygiene

Source: ECB payment statistics, second half of 2025

Source: ECB/EBA payment fraud report

Source: UK Finance Annual Fraud Report 2026

Source: Banco de España Supervision Report 2025

Reading the market data correctly

Three distinctions matter. First, a fraud figure is not a PCI DSS non-compliance figure: fraud can occur despite compliance, and non-compliance can exist without detected fraud. Second, a card-not-present category normally groups e-commerce, telephone and mail-order transactions; public datasets rarely isolate telephone payments. Third, average breach-cost studies cover many industries and data types. They illuminate the wider economic context but cannot be used as a card-scheme penalty calculator.

EVIDENCE GAPThere is no authoritative public global PCI DSS compliance rate, no complete worldwide register of card-scheme assessments, and no consistent public dataset that isolates telephone-payment breaches. Any publication claiming one precise global average PCI fine should disclose its methodology and sources.

2. What a ‘PCI fine’ actually is

The organisations play different roles

ActorPrimary roleWhat it may do after non-compliance or compromise
PCI SSCDevelops and maintains PCI security standards and supporting programmesDoes not act as a global fining authority for merchants
Payment brand / schemeOperates network rules and a compliance or data-security programmeMay assess a member, require investigation, impose validation, restrict or terminate participation
IssuerIssues cards to cardholdersMay replace cards, manage customer claims and participate in scheme recovery processes
AcquirerContracts with merchants and connects acceptance to a schemeValidates merchant compliance, manages incidents and may contractually pass through costs
MerchantAccepts the paymentMust protect account data, validate as required, notify incidents and manage suppliers
Service providerStores, processes, transmits or can affect the security of account dataMust meet applicable PCI obligations and support customer evidence
Regulator / courtEnforces public law and adjudicates claimsMay impose fines, orders, damages or settlements independently of PCI programmes

The six-layer cost stack

1. Card-scheme assessment. A payment brand may assess an issuer, acquirer or other member under its rules or programme.

2. Contractual pass-through. The member may recover all or part of the amount from a merchant or service provider under the acquiring or service agreement.

3. Investigation and remediation. Payment Card Industry Forensic Investigator (PFI), legal, notification, call-centre, monitoring, containment, replacement technology and revalidation costs can begin before liability is decided.

4. Card replacement and fraud recovery. Issuers and schemes may pursue recovery for operational costs and fraudulent transactions, subject to the relevant rules and facts.

5. Public-law and civil exposure. Data-protection authorities, consumer regulators, attorneys general, class actions and contractual claims operate separately from PCI SSC.

6. Business impact. Downtime, delayed sales, customer churn, higher acquiring cost, reserve requirements, restrictions and loss of card acceptance can exceed the published assessment.

TERMINOLOGY RULE FOR ACCURATE PUBLISHINGVisa, Mastercard, American Express, Discover and JCB are payment brands, schemes or networks in this context — not simply ‘card issuers’. An assessment imposed on an acquirer should not automatically be described as a fine imposed directly on the merchant.

Compliance validation is not immunity

An Attestation of Compliance, Report on Compliance or Self-Assessment Questionnaire is evidence of validation for a defined environment and period. It is not a warranty that no control can fail later. After an incident, forensic evidence may show that the entity was not compliant at the relevant time, that scope was incomplete, or that a service-provider dependency was misunderstood. Conversely, Visa states that assessments may be waived where forensic investigation does not identify non-compliance, subject to its programme terms.

3. PCI DSS v4.0.1 in 2026

PCI DSS v4.0.1, published in June 2024, is the active reference point for this report. PCI SSC described v4.0.1 as a limited revision that added clarification and corrected formatting and typographical issues; it did not add or delete requirements and did not alter the 31 March 2025 effective date for future-dated requirements.

By 2026, organisations should no longer be treating those future-dated controls as a distant roadmap. PCI SSC stated that 51 of 64 new requirements in the v4.x generation became effective on 31 March 2025. The practical emphasis is continuous evidence: assigned responsibilities, risk analyses, secure configurations, vulnerability management, access control, monitoring, incident readiness, supplier governance and the security of payment-page scripts and e-commerce channels.

Source: PCI DSS v4.0.1 publication notice

Source: PCI SSC guidance on future-dated v4.x requirements

A minimum evidence file for 2026

A current, documented cardholder data environment (CDE) scope, including connected systems and systems that can affect security.

Data-flow diagrams covering e-commerce, payment terminals, telephone/IVR, recordings, VoIP, remote support and service providers.

A current inventory of stored account data, with a defensible business need, retention period and secure deletion process.

Evidence that sensitive authentication data — including card verification codes — is not retained after authorisation.

Defined responsibility matrices for the entity, acquirer, payment gateway, contact-centre platform, telephony provider and other service providers.

Quarterly and annual control evidence appropriate to the validation method, plus incident-response testing and training.

A process for significant change, new integrations, mergers, contact-centre outsourcing and supplier changes so that scope is reassessed before go-live.

4. Public card-scheme assessment and fee schedules

This section reports only amounts supported by public scheme material available by 14 August 2026. Currency is US dollars unless stated. ‘Up to’ means a maximum, not an automatic invoice. Contract terms, programme guides, regional rules, facts of the case and the member relationship can change the result.

4.1 Visa

Visa’s public Account Information Security (AIS) material states that Visa manages the enforcement and validation of PCI DSS compliance and that issuers and acquirers are responsible for ensuring that their agents, merchants and service providers comply. Importantly, Visa explains that it assesses the issuer or acquirer, which pays the assessment, and that the member must not represent to a merchant or agent that Visa imposed the assessment directly on that merchant or agent.

The Visa Core Rules dated 18 April 2026 refer the specific AIS non-compliance assessment amount to the AIS Programme Guide rather than publishing it in the Core Rules. The general violation schedule below is public, but it must not be presented as an automatic PCI DSS tariff.

Visa general violation categoryMonth / eventPublic assessment
Tier 11st / 2nd / 3rd / 4th / 5th / 6th$25k / $50k / $75k / $100k / $125k / $150k
Tier 1Each month thereafterPrevious month + $25k
Tier 21st / 2nd / 3rd / 4th / 5th / 6th$5k / $10k / $20k / $30k / $40k / $50k
Tier 2Each month thereafterPrevious month + $10k
Case administrationApplicable case$1,000 case fee
Significant violationOn confirmation$50k
Significant violationEach month after correction deadline$50k–$1m
Failure to notify/respond to loss or theftPer incidentUp to $100k
VISA CAVEATUse the table only as a general Core Rules reference. A PCI/AIS-specific amount may depend on the AIS Programme Guide and the facts of the member’s case. Do not label the Tier 1 and Tier 2 table ‘Visa’s PCI fines’ without this qualification.

Source: Visa Account Information Security and compliance information

Source: Visa Core Rules and Visa Product and Service Rules, 18 April 2026

4.2 Mastercard

Mastercard’s Security Rules and Procedures — Merchant Edition dated 4 August 2026 publishes maximum assessments by merchant and service-provider level. The table is expressed by calendar-year violation, not by the number of months a merchant remains non-compliant.

Entity / category1st violation2nd3rd4th
Level 1 or 2 merchantUp to $25kUp to $50kUp to $100kUp to $200k
Level 3 merchantUp to $10kUp to $20kUp to $40kUp to $80k
Level 1 or 2 service providerUp to $25kUp to $50kUp to $100kUp to $200k
Additional Mastercard provisionPublic maximum / consequence
Account data compromise confirms a PCI SSC violationUp to $100,000 per violation
Failure to comply with specified account-data compromise proceduresUp to $25,000 per day
Persistent or serious non-complianceTermination, deregistration or removal from listings may be possible under applicable rules
Compromised merchantMay be reclassified as Level 1, increasing validation obligations

Mastercard merchant levels

LevelPublished transaction threshold / status
Level 1More than 6 million Mastercard and Maestro transactions annually, or otherwise classified by Mastercard
Level 2More than 1 million and up to 6 million transactions annually
Level 3More than 20,000 and up to 1 million combined e-commerce transactions annually
Level 4All other merchants

A 2026 reporting change also matters. Effective 1 January 2026, Mastercard’s rules require an issuer or acquirer to notify the Mastercard Site Data Protection programme promptly where it determines or reasonably believes that a service provider or merchant is not compliant, subject to stated Validation Exemption Programme conditions. Broader merchant notice provisions are scheduled for 1 January 2027. Organisations should verify the current text and effective dates when publishing or acting on this point.

Source: Mastercard rules and standards portal

Source: Mastercard Security Rules and Procedures — Merchant Edition, 4 August 2026

4.3 American Express

American Express’s International Merchant Regulations, October 2025 edition, publish cumulative non-validation fees. The first missed deadline may therefore be followed by additional charges until the required validation documentation is submitted. Local-currency equivalents and regional qualifications may apply; the published table notes that these fees do not apply in Argentina.

American Express category1st deadline2nd deadline3rd deadline
Level 1 merchant / service provider$25,000+$35,000+$45,000
Level 2 merchant$5,000+$10,000+$15,000
Level 3 or 4 merchant$50+$100+$250
Data-incident provisionPublished amount / deadline
Data-incident non-compliance feeUp to $100,000 per incident
Indemnity for qualifying incident involving at least 10,000 American Express card numbers plus expiration date or sensitive authentication data$5 per affected account, subject to conditions and exclusions
Initial incident noticeWithin 72 hours
PFI engagement for incident involving at least 10,000 unique card numbersWithin five days, subject to the applicable rules

Source: American Express Data Security Operating Policy and merchant security page

Source: American Express International Merchant Regulations, October 2025

4.4 Discover

Discover Global Network publicly requires ongoing PCI DSS compliance and validation appropriate to the participant. Its public compliance material warns that a breach may generate fraud losses, non-compliance fees and other damages. However, the public page reviewed for this report does not provide a complete general numerical schedule comparable to the Mastercard and American Express tables above. The absence of a public tariff must not be interpreted as the absence of financial exposure.

Source: Discover Global Network PCI compliance and validation requirements

4.5 JCB

JCB’s public Data Security Programme expressly covers merchants and service providers and includes e-commerce, mail-order/telephone-order and phone-call service transactions in its validation framework. JCB publishes its PCI DSS obligations and programme structure, but the public programme pages reviewed for this report do not contain a complete general numerical non-compliance tariff. Acquirer agreements and current regional programme documentation remain decisive.

Source: JCB Data Security Programme

Source: JCB PCI DSS compliance information

5. Cross-scheme comparison and enforcement path

SchemeWhat is publicly quantifiable?Critical qualification
VisaGeneral violation tiers; significant-violation range; incident notice/response maximumAIS-specific amount is referred to a separate programme guide; member is assessed
MastercardMerchant/service-provider maxima by violation; $100k per confirmed PCI violation; $25k/day procedure maximumAmounts are maxima; annual violation sequence and entity level matter
American ExpressCumulative non-validation deadlines; up to $100k incident fee; conditional $5/account indemnityDeadlines, incident thresholds, regional rules and exclusions apply
DiscoverConsequences identified publicly, but no complete numerical general schedule locatedConfirm current network and acquirer documentation
JCBProgramme and validation obligations, but no complete numerical general schedule locatedMOTO and phone-call services are expressly in programme scope

A typical enforcement and cost path

1. A validation deadline is missed, a control gap is identified, or a suspected account-data compromise is reported.

2. The merchant or service provider notifies its acquirer or customer according to contracts and scheme rules; the member notifies the scheme where required.

3. The scheme or acquirer may require investigation, evidence, a remediation plan, enhanced validation or a PFI investigation.

4. If non-compliance is found, the scheme may assess the member. The acquirer may pass through scheme assessments and its own contractual costs, subject to the agreement and applicable law.

5. Regulatory investigations, card replacement, fraud recovery, claims, notification and litigation can proceed on separate tracks.

6. Continued non-compliance can escalate amounts, validation burden or participation restrictions even after the original breach is contained.

WHY THE DOMINO METAPHOR IS ACCURATEThe trigger may be a single failed control, but the cost propagates through several contracts and legal regimes. Each party — merchant, service provider, acquirer, scheme, issuer and regulator — has a different mandate, evidence threshold and recovery mechanism.

6. Public cases in Spain and worldwide

The cases below are included because official decisions or public company filings provide verifiable amounts. They illustrate the scale and composition of exposure, not a direct price comparison. Regulatory decisions are not PCI SSC fines, while company totals often include settlements, claims, remediation and insurance effects.

CasePublicly documented factsFinancial outcome and correct classification
Air Europa — SpainAEPD: 489,000 people; 1.5m records; forensic evidence indicated more than 2.7m unique card numbers exfiltrated. Data included card number, expiry and CVV.€500k for Article 32(1) GDPR security infringement plus €100k for late Article 33 notification: €600k regulatory fine, not a scheme assessment.
British Airways — UKICO: 429,612 people affected; payment-card number and CVV were involved for subsets of data subjects.£20m data-protection penalty. Regulatory enforcement, not a PCI SSC fine.
Heartland — USCompany filing recorded scheme-related settlements and recovery programmes following the 2008 intrusion.$59.3m Visa; $34.4m Mastercard paid; $3.5m American Express; $5m Discover. 2009 expense $132.9m gross, $128.9m net after $4m insurance. Mostly settlements/recoveries, not one PCI fine.
Target — USMore than 40m payment-card customer accounts affected, according to the California Attorney General settlement announcement.$18.5m multistate AG settlement. Target’s 2017 10-K reported $292m cumulative gross breach expense, $90m insurance, $202m net.
Home Depot — USApproximately 40m payment cards affected, according to the New York Attorney General.$17.5m multistate AG settlement. Home Depot’s 2017 10-K reported $298m gross breach costs, $100m insurance, $198m net.

6.1 Air Europa: the Spanish reference case

The Spanish Data Protection Agency’s Air Europa proceeding is particularly relevant because the compromised dataset included card number, expiry date and card verification value. The AEPD recorded 489,000 affected people and 1.5 million records, while the forensic material described exfiltration of more than 2.7 million unique card numbers. The authority imposed €500,000 for infringement of Article 32(1) GDPR and €100,000 for infringement of Article 33, producing a €600,000 total.

The publication lesson is precise: this was a data-protection authority’s penalty based on GDPR obligations. It should not be described as ‘a PCI DSS fine’, even though the facts concern payment-card data and the incident is highly relevant to PCI risk management.

Source: AEPD decision PS/00179/2020 — Air Europa

6.2 Heartland: scheme-related costs can dwarf a simple tariff

Heartland Payment Systems’ 2010 annual filing provides rare public granularity. It recorded $59.3 million paid in connection with Visa, including a $780,000 credit for earlier fines, and $34.4 million paid in connection with Mastercard, while describing recovery offers of $41.4 million including a $6.6 million credit for earlier fines. It also recorded $3.5 million for American Express and $5 million for Discover. Total 2009 breach-related expense was $132.9 million, or $128.9 million after $4 million of insurance proceeds.

These figures should be quoted with their accounting context. The majority were settlement and recovery arrangements and wider breach costs, not a single schedule-based PCI DSS assessment.

Source: Heartland Payment Systems 2010 Form 10-K

6.3 Target and Home Depot: gross cost, insurance and regulatory settlement

Target’s 2017 Form 10-K reported $292 million of cumulative gross data-breach expense, offset by $90 million of insurance, for $202 million net. A separate multistate attorneys-general settlement announced by California was $18.5 million. The settlement announcement described more than 40 million payment-card customer accounts as affected.

Home Depot’s 2017 Form 10-K reported $298 million of gross breach costs and $100 million of insurance reimbursement, leaving $198 million net. In 2020, a coalition of attorneys general announced a $17.5 million settlement; New York’s announcement described approximately 40 million payment cards as affected.

Source: Target Corporation 2017 Form 10-K

Source: California Attorney General Target settlement announcement

Source: The Home Depot 2017 Form 10-K

Source: New York Attorney General Home Depot settlement announcement

6.4 British Airways: card data inside a broader security failure

The UK Information Commissioner’s Office fined British Airways £20 million following a cyberattack affecting personal data relating to 429,612 people. The penalty notice records payment-card numbers and CVVs for subsets of affected data. As with Air Europa, the amount is a public-law data-protection penalty. It is relevant evidence of the regulatory layer, not a substitute for any card-scheme analysis.

Source: ICO British Airways monetary penalty notice

What the cases collectively show

A regulatory fine may be only a small percentage of the total disclosed cost.

Insurance can reduce net accounting expense but may not cover every category, future premium impact or operational harm.

Amounts announced by schemes, regulators and companies use different legal and accounting definitions.

The largest costs often arise after the incident through settlements, recovery programmes, remediation and customer response.

Accurate reporting must state who imposed or received the amount and what the amount represents.

7. Telephone payments, contact centres and CNP exposure

Telephone payments remain operationally important for travel, healthcare, utilities, public services, collections, insurance, hospitality and customer support. They are also easy to underestimate because the cardholder is speaking to a person rather than entering data on a web checkout. From a security perspective, however, the card data still travels through people, telephony systems, endpoints, networks and payment applications unless the architecture deliberately prevents it.

7.1 How a conventional agent-assisted payment expands scope

Exposure pointHow account data may enter scopeTypical control question
AgentHears the PAN, expiry date or security codeCan the agent avoid hearing or seeing card data?
DesktopAgent keys data into a browser, virtual terminal or CRMIs entry isolated from the corporate endpoint?
Telephony / VoIPVoice or signalling traffic carries account data within the entity’s controlIs the network component in the assessed scope?
Call recordingAudio or DTMF tones capture card dataAre payment segments suppressed, masked or securely deleted?
CRM and notesAgents paste or type account data into free-text fieldsAre fields blocked, monitored and purged?
Remote workHome networks, softphones, screen tools or local notes increase exposureDoes the design remain secure outside the office?
Supplier integrationsContact-centre, payment and telephony providers can affect securityAre responsibilities and evidence contractually defined?

7.2 Call recordings and security codes

PCI SSC FAQ 1210 states that sensitive authentication data, including card verification codes, must not be retained after authorisation even if encrypted. If audio recordings contain that data, storage after authorisation violates the applicable requirement. PCI SSC’s guidance is to prevent recording through suppression or redaction, or to securely delete the data immediately after authorisation where prevention is not possible.

Muting an agent’s headset is not necessarily sufficient if DTMF tones, screen recordings, diagnostic logs or downstream platforms still receive the data. The control objective must be assessed end to end.

Source: PCI SSC FAQ 1210 — audio recordings containing card verification codes

7.3 VoIP is not automatically out of scope

PCI SSC FAQ 1153 explains that VoIP components carrying account data can be in scope while the data is within the entity’s control. The analysis depends on architecture, responsibility and whether the systems store, process, transmit or can affect the security of account data. Labelling a system ‘telephony’ does not itself remove PCI obligations.

Source: PCI SSC FAQ 1153 — VoIP and PCI DSS scope

7.4 Secure design patterns

DTMF masking or suppression: the cardholder enters digits on the telephone keypad while the agent remains connected; tones are intercepted or transformed before reaching the agent and enterprise environment.

Secure IVR: the caller is transferred or bridged to an automated payment flow so that the merchant’s people and systems do not receive raw account data.

Tokenisation: the merchant retains a token for later business processes instead of the primary account number, subject to correct implementation and scope analysis.

Hosted payment orchestration: a PCI-validated provider captures and transmits the card data directly to the payment processor while the merchant receives status rather than raw credentials.

Recording controls: payment segments are suppressed and screen/voice recording behaviour is tested, including failure states and remote-agent scenarios.

OUTSOURCING DOES NOT OUTSOURCE ACCOUNTABILITYUsing a PCI DSS validated service provider can reduce scope and technical exposure, but the merchant still needs due diligence, a responsibility matrix, current validation evidence, secure integration, incident procedures and monitoring of the service relationship.

Source: PCI SSC guidance on accepting telephone payments securely

8. PCI DSS and EMV 3-D Secure: different controls

PCI DSS and EMV 3-D Secure (EMV 3DS) address different parts of payment risk. PCI DSS protects account data and the systems, people and processes that store, process, transmit or can affect its security. EMV 3DS enables cardholder authentication and data exchange for card-not-present transactions, helping issuers and merchants manage fraud and authorisation decisions. One does not replace the other.

Control frameworkPrimary purposeWhat it does not do
PCI DSSProtect account data and reduce compromise risk across the payment environmentDoes not authenticate every cardholder or guarantee that a transaction is legitimate
EMV 3-D SecureAuthenticate the consumer and exchange risk data for CNP transactionsDoes not by itself secure all systems that handle card data or remove PCI DSS obligations

The strongest design combines data minimisation with transaction authentication: prevent raw card data entering the merchant environment where possible, validate the reduced scope, and apply appropriate authentication and fraud controls to the transaction channel.

Source: EMVCo — EMV 3-D Secure

Source: PCI SSC — PCI 3DS Core Security Standard

9. A practical exposure model and board-level checklist

A model, not a tariff calculator

TOTAL EXPOSURE ≈scheme and contractual assessments + forensic investigation + containment and remediation + notification and customer support + card replacement and fraud recovery + regulatory enforcement and litigation + downtime, churn and higher cost of acceptance

The terms are not independent or linear. A slow notification can increase regulatory exposure; incomplete scope can prolong forensics; poor supplier records can delay containment; and loss of card acceptance can convert a compliance issue into a revenue crisis. The model is therefore best used to identify missing cost categories, not to forecast an exact amount.

Scenario guide

ScenarioLikely first-order exposureEscalation risk
Validation overdue, no known breachNon-validation fee/assessment, acquirer charges, urgent assessment and remediationCumulative or repeated assessments; trading restrictions
Control gap or suspected compromiseIncident response, legal and forensic triage, evidence preservation, notification decisionsPFI requirement, wider scope, regulatory notice
Confirmed compromise and non-complianceAll investigation/remediation costs plus potential scheme and contractual assessmentsCard recovery, regulator, litigation, termination and reputation
Compromise but no non-compliance foundIncident and business costs remainSome programme assessments may be waived or reduced under applicable rules; never assume immunity

Board and executive checklist

Can management state exactly where account data enters, travels and is stored — including telephone, recording and remote-work systems?

Has the organisation reduced scope by design, or merely documented a large and complex CDE?

Is the validation method current and appropriate to merchant/service-provider level and acquirer requirements?

Is there evidence that controls operate continuously, not only during the annual assessment?

Are payment-page scripts, e-commerce dependencies and change-detection controls covered under PCI DSS v4.x?

Can security codes enter recordings, logs, CRM notes, quality-monitoring tools, screen captures or AI transcription systems?

Are all relevant service providers identified, validated and mapped to a written responsibility matrix?

Do contracts clearly allocate incident notice, PFI, assessment, card-recovery, legal and insurance responsibilities?

Has the incident plan been tested with the acquirer, gateway, telephony provider, insurer, legal counsel and communications team?

Can the organisation preserve evidence without delaying containment or mandatory notice?

Does cyber insurance cover PCI/scheme assessments where legally insurable, forensic costs, card replacement, business interruption and regulatory response?

Are senior leaders shown gross exposure as well as expected insurance recovery?

Is there a defined process to reassess scope after acquisitions, new contact-centre technology, cloud migrations and supplier changes?

Are customers and agents given a payment route that does not require disclosing card details aloud?

Has management tested failure modes — transfer failure, recording restart, fallback to manual entry and remote-agent exceptions?

10. How Pay by Call reduces telephone-payment exposure

Pay by Call is designed to separate card capture from agents and ordinary corporate systems. Through its PCI-as-a-Service (PCIaaS) approach, card details can be collected through a controlled payment flow while the organisation and agent receive transaction status rather than the raw credentials. The architectural goal is data minimisation: fewer people, endpoints, applications and recordings exposed to account data.

Security and payment capabilities

PCI DSS Level 1 service-provider posture, supporting a controlled payment-data environment and customer due diligence.

Telephone-payment flows designed so agents do not need to hear, see or type card details into corporate systems.

PCIaaS orchestration that helps organisations reduce the technical and operational surface of their PCI DSS scope.

PBC 3DS, a native voice approach to 3-D Secure designed to add cardholder authentication to telephone payment journeys. Patent pending; international patent applications have been filed.

Integration patterns intended to return payment result and business references without returning raw card data to the merchant environment.

AVOID THE DOMINO EFFECT WITH PAY BY CALL A single exposed payment credential can trigger investigation, remediation, contractual recovery, regulator attention and customer harm. Pay by Call helps prevent that chain reaction by keeping card data away from agents, recordings and day-to-day corporate systems while supporting secure payment and authentication journeys.

A reduced-scope architecture must still be validated against the organisation’s actual integration, contracts, people and processes. Pay by Call can support scope reduction and control design; the customer remains responsible for confirming its own PCI DSS obligations with its acquirer and qualified advisers.

Frequently asked questions

Is PCI DSS a law?

PCI DSS is an industry security standard, not a single global statute. Contracts and payment-brand rules make it commercially enforceable, while regulators may impose separate duties and penalties under public law.

Does PCI SSC fine merchants?

PCI SSC maintains standards and programmes; it is not a global merchant-fining authority. Payment brands and members operate compliance programmes, and regulators enforce applicable law.

How much is the fine for PCI DSS non-compliance?

There is no universal amount. The public schedules in this report differ by scheme, entity level, missed deadline, violation, incident and region. Acquirer contracts and non-public programme documentation can also matter.

Can a merchant be charged even if the payment brand assesses the acquirer?

Potentially, yes. An acquiring agreement may permit pass-through or recovery of assessments and other costs. The exact contractual and legal basis must be reviewed. Visa’s public material also warns members not to misrepresent an assessment as having been imposed directly by Visa on the merchant.

Does annual validation prove that an organisation was compliant at the time of a breach?

Not automatically. Validation covers a defined scope and evidence set. A later investigation can identify scope errors, control failures or changes. It can also find that non-compliance was not present, which may affect programme treatment.

Does outsourcing card capture eliminate PCI DSS?

Usually not completely. A validated provider can materially reduce scope, but the merchant retains supplier governance, integration, policy, validation and incident responsibilities.

May a call recording contain a CVV?

Sensitive authentication data such as a CVV must not be retained after authorisation, even if encrypted. Recording suppression, redaction or immediate secure deletion must be designed and tested.

Are telephone payments included in card-not-present fraud data?

Often yes, but normally within a broader remote-purchase or CNP category that also includes e-commerce and mail order. Public data rarely isolates telephone payments, so the total category must not be described as MOTO-only.

Does 3-D Secure make a business PCI compliant?

No. EMV 3DS supports cardholder authentication and fraud management. PCI DSS protects account data and the environment that handles it. They are complementary.

What should a company do first?

Map every payment channel and data flow, remove unnecessary storage and exposure, verify service-provider responsibilities, validate the reduced scope and test incident response. In telephone environments, start by determining whether agents or recordings can receive card data.

Conclusion

The risk of PCI DSS non-compliance in 2026 cannot be understood through one headline fine. Public scheme schedules show that some assessments can escalate quickly, but the documented cases show a wider truth: forensics, recovery, regulators, litigation, customer response and business interruption can dominate the final cost.

The most defensible strategy is to reduce the amount of account data the organisation handles, keep the validated scope accurate, maintain year-round control evidence and prepare for coordinated incident response. For telephone payments, that means designing the journey so card details do not pass through agents, recordings or general corporate technology in the first place.

Methodology, limitations and primary sources

Research method

This report reviewed public payment-brand rules and compliance pages, PCI SSC standards and FAQs, central-bank and industry fraud statistics, regulator decisions and listed-company filings available by 14 August 2026. Numerical schedules were included only where a primary public document supported them. Where a scheme publishes the existence of obligations or consequences but not a complete tariff, the report says so rather than substituting unattributed secondary estimates.

Limitations

Payment-brand programme guides, bulletins, bilateral contracts and regional terms may not be public and may change after the editorial cut-off.

Public cases disclose different categories of cost and are not directly comparable.

Market statistics use different definitions, currencies, periods and geographic scopes.

The report does not determine whether any named organisation was PCI DSS compliant except where the source expressly addresses that issue.

The absence of a published numerical schedule does not imply zero liability.

This document is not legal, contractual, forensic, certification or insurance advice.

Primary source register

1. PCI Security Standards Council — PCI DSS — standard overview and enforcement-routing information

2. PCI SSC — Document Library — official standards and supporting material

3. PCI SSC — PCI DSS v4.0.1 publication notice — revision scope and June 2024 publication

4. PCI SSC — Future-dated v4.x requirements — 31 March 2025 effective-date context

5. PCI SSC — Telephone payment guidance — contact-centre and telephone-payment security

6. PCI SSC FAQ 1210 — audio recordings and card verification codes

7. PCI SSC FAQ 1153 — VoIP and PCI DSS scope

8. Visa — Account Information Security — enforcement, member assessment and waiver explanation

9. Visa Core Rules, 18 April 2026 — public violation schedules and AIS cross-reference

10. Mastercard — Rules and standards portal — current public rules index

11. Mastercard Security Rules and Procedures — Merchant Edition, 4 August 2026 — merchant/service-provider assessments and compromise provisions

12. American Express — Data Security Operating Policy — current merchant security programme

13. American Express International Merchant Regulations, October 2025 — non-validation fees and incident provisions

14. Discover Global Network — PCI compliance — validation obligations and consequences

15. JCB — Data Security Programme — programme scope including MOTO and phone-call services

16. JCB — PCI DSS — public compliance information

17. EMVCo — EMV 3-D Secure — authentication purpose and CNP context

18. PCI SSC — PCI 3DS Core Security Standard — 3DS component security

19. ECB — Payment statistics, second half of 2025 — published 22 July 2026

20. ECB/EBA — Payment fraud report — EEA fraud statistics for 2024

21. UK Finance — Annual Fraud Report 2026 — UK fraud statistics for 2025

22. Banco de España — Supervision Report 2025, Chapter 4 — Spanish payment-security supervisory indicators

23. Banco de España — Complaints report press note — accepted complaints involving card and transfer fraud

24. IBM — Cost of a Data Breach Report 2026 — general global breach-cost benchmark

25. Verizon — Data Breach Investigations Report 2026 — general threat and breach patterns

26. AEPD — Air Europa decision PS/00179/2020 — Spanish enforcement case

27. Heartland Payment Systems — 2010 Form 10-K — scheme-related settlements and breach expense

28. ICO — British Airways penalty notice — UK enforcement case

29. Target Corporation — 2017 Form 10-K — gross, insurance and net breach costs

30. California Attorney General — Target settlement — multistate regulatory settlement

31. The Home Depot — 2017 Form 10-K — gross, insurance and net breach costs

32. New York Attorney General — Home Depot settlement — multistate regulatory settlement

Pay by Call | PCI DSS Non-Compliance Reference 2026 | Page

PAY BY CALL | INDUSTRY REFERENCE 2026

Appendix: copy-ready reference tables

The following compact tables are designed for editorial reuse. Preserve the qualification text whenever copying a monetary figure. Do not remove ‘up to’, convert a general rule into a PCI-specific tariff, or describe regulatory penalties as PCI SSC fines.

A.1 Visa public general rules — editorial copy table

categoryperiod_or_eventpublic_amount_usdqualification
Tier 1months 1–625k; 50k; 75k; 100k; 125k; 150kGeneral Core Rules schedule; not automatic AIS/PCI tariff
Tier 1month 7 onwardprevious month + 25kGeneral Core Rules schedule
Tier 2months 1–65k; 10k; 20k; 30k; 40k; 50kGeneral Core Rules schedule; not automatic AIS/PCI tariff
Tier 2month 7 onwardprevious month + 10kGeneral Core Rules schedule
Case feeapplicable case1kAdministrative case fee
Significant violationconfirmation50kGeneral significant-violation rule
Significant violationmonthly after deadline50k–1mRange; facts and rule application matter
Loss/theft notice or response failureper incidentup to 100kMaximum

A.2 Mastercard public assessment table

entityfirstsecondthirdfourthqualification
Level 1/2 merchant≤25k≤50k≤100k≤200kper calendar-year violation; maxima
Level 3 merchant≤10k≤20k≤40k≤80kper calendar-year violation; maxima
Level 1/2 service provider≤25k≤50k≤100k≤200kper calendar-year violation; maxima

A.3 American Express public non-validation table

entityfirst_deadlinesecond_deadlinethird_deadlinequalification
Level 1 merchant / SP25k+35k+45kcumulative; local equivalent; regional qualifications
Level 2 merchant5k+10k+15kcumulative; local equivalent; regional qualifications
Level 3/4 merchant50+100+250cumulative; local equivalent; regional qualifications

A.4 Public case table

casecountryamountclassificationkey caveat
Air EuropaSpain€600kGDPR regulator penaltynot a PCI SSC/scheme fine
British AirwaysUK£20mdata-protection penaltynot a PCI SSC/scheme fine
HeartlandUS$128.9m net 2009 expensesettlements/recovery/wider breach costnot one PCI fine
TargetUS$202m net cumulative expense; $18.5m AG settlementcompany cost + regulator settlementdifferent cost categories
Home DepotUS$198m net cost; $17.5m AG settlementcompany cost + regulator settlementdifferent cost categories

A.5 Data citation table

metricperiodvaluesourcedo_not_infer
Euro-area card paymentsH2 202547.8bn; €1.8tnECBnot PCI incident volume
Euro-area remote shareH2 202519% count; 30% valueECBnot telephone-only
EEA payment fraud2024€4.2bnECB/EBAnot all card fraud
EU/EEA-issued card fraud2024€1.329bnECB/EBAnot PCI non-compliance
UK remote-purchase fraud2025£423.5m; 3,196,962 casesUK Financeincludes internet, phone and mail order
Global average breach cost2026 report$4.99mIBMnot PCI-specific