PCI Standards must be met by all businesses that take credit/debit or paycards from the top four major card industry providers: American Express, Discover, MasterCard and Visa. PCI Compliance Standards are not laws - they are contractual obligations with the credit card companies. Credit card companies may enforce the terms of their contracts by imposing fines and/or sanctions against companies who do no comply with the standards for each credit card company.
What Happens If My Business Does Not Become PCI Compliant?
PCI Compliance is a requirement of your contract with the credit card companies. If you do not make your business PCI compliant, you are in violation of your contract. The credit card companies can take the following actions if your business does not abide by the security standards.
Visa may charge your business up to $500,000 per incident if your network and the information of consumers is compromised.
You may be banned from allowing your customers to use credit cards issued by the company that finds your business non-compliant.
If you do not notify the companies of probable or actual violations or thefts of our customers' information, you will also be fined. Again, Visa can charge you as much as $100,000 per incident.
Other fines may be charged if the credit card company feels that the your company's violations pose a risk to the credit card company and/or its members.