9 min read · Last updated August 19, 2026
- Payment Card Industry Data Security Standard (PCI DSS) fines and assessments are enforced through a business’s own contract with its card-processing bank, not by a government regulator, and a general cyber policy often does not cover them.
- Visa’s own published assessment schedule sets non-compliance fines at $5,000 to $25,000 for smaller-volume merchants, but Visa can raise even that to $100,000 per incident at its own discretion, and all of it is billed through the acquiring bank.
- P.F. Chang’s was reimbursed $1.7 million for standard breach-response costs after its 2014 card breach, then denied a separate $1.9 million in card-brand assessments because its cyber policy had no distinct PCI coverage grant.
- A cyber policy that treats “PCI-DSS Assessment” coverage as its own line item, not a subset of breach-response coverage, is the detail that decides whether a card-data breach produces one bill or two.
In this article
- What PCI DSS actually is, and who bills you for it
- The bill that a standard breach payout does not touch
- A national chain already fought this fight and lost
- Why compliance status decides whether the coverage even applies
- What to check on your own cyber policy
Priya Nair, who owns a small home goods shop, filed a cyber insurance claim after a hacker breached her point-of-sale system and stole customer card data, and three weeks later, a letter from her card-processing bank billed her $9,500 separately for card-brand non-compliance assessments tied to that same breach. The insurer had already paid for forensics, customer notification, and credit monitoring, the standard breach-response package. The $9,500 bill was a different bill entirely, because breach-response coverage and card-brand assessment coverage are two different things written into two different parts of the policy.
What PCI DSS actually is, and who bills you for it
The Payment Card Industry Data Security Standard (PCI DSS), the security standard every business that stores, processes, or transmits card data is required to follow, is not a government law. It’s a contractual requirement, and the PCI Security Standards Council’s own site is explicit that “whether an entity is required to comply with or validate compliance to a PCI SSC standard is at the discretion of organizations that manage compliance programs, such as a payment brand, acquirer, or other entity.” In plain terms: Visa, Mastercard, and the bank that processes your card transactions, called the acquiring bank, enforce PCI DSS through your merchant agreement, not a regulator who answers to Congress.
That enforcement structure is exactly why the bill lands the way it does. Visa’s own published assessment schedule breaks what Visa calls Non-Compliance Assessments, or NCAs, the fines and fees it charges for failing to follow its security rules, into tiers by transaction volume. A Level 3 merchant, the category covering any business processing under a million card transactions a year, which is most small merchants, faces $5,000 to $25,000 depending on volume, while issuers, acquirers, and the largest merchants face a flat $100,000. Visa’s own schedule adds a catch even smaller merchants aren’t protected from: “for Level 3 merchants, the NCAs start at amounts outlined in the schedule below, but at Visa’s discretion can be increased to the $100k threshold if the facts of the case warrant it.” Visa doesn’t have a direct contract with Priya’s shop, though. It has a contract with the acquiring bank, which is why the assessment shows up as a bill from her payment processor rather than a letter from Visa itself.
The bill that a standard breach payout does not touch
Cyber insurers have responded to this exact structure by writing “PCI-DSS Assessment” as its own distinct coverage grant, separate from the breach-response coverage every cyber policy leads with. Corvus Insurance’s own coverage explainer for brokers says it directly: “third-party coverages guarantee an organization is all set in the event of PCI fines and assessments, right? Not quite, unless coverage is explicit.” A cyber liability managing general agent (MGA), an underwriting firm that designs and administers policies on an insurance carrier’s behalf, 360 Coverage Pros, describes its own policy the same way, confirming that a policy “responds to PCI assessments as well as claims expenses in the wake of a breach” only when the assessment coverage is written in, not assumed.
| Cost after a card-data breach | Typically paid by |
|---|---|
| Forensic investigation, customer notification, credit monitoring | Standard cyber breach-response coverage |
| Third-party lawsuits from affected customers | Cyber liability coverage |
| Card-brand non-compliance assessments (Visa, Mastercard) | PCI-DSS Assessment coverage, if written into the policy as its own grant |
| Card reissuance costs billed by the acquiring bank | Often bundled with PCI-DSS Assessment coverage; verify with your carrier |
For a business owner reading a cyber policy for the first time, PCI-DSS Assessment coverage often looks like a minor line item buried well below the headline breach-response and liability limits. It is not minor. It is the only part of the policy that responds to the specific bill a card network can generate, and it needs to be confirmed as present, not assumed. It’s the same buried-sublimit pattern that shows up when a cyber policy rides as an endorsement on a business owner’s policy rather than standing alone: the coverage exists on paper, capped far below what a real claim needs.
A national chain already fought this fight and lost
This is not a hypothetical gap. It played out in federal court after a real breach. In 2014, hackers gained access to the payment systems at P.F. Chang’s China Bistro restaurants and posted roughly 60,000 stolen credit card numbers online. According to Insurance Journal’s account of the resulting coverage dispute, the restaurant chain’s cyber insurer, Chubb, paid $1.7 million to cover standard breach-response costs. Separately, “P.F. Chang’s got hit for another $1.9 million in fines levied against them by their credit card processing vendor for Payment Card Industry (PCI) assessments following the breach,” and when the chain sought reimbursement for that $1.9 million from Chubb, the insurer denied it.

P.F. Chang’s is a national chain, not a small shop, but the mechanism that produced its uncovered $1.9 million bill is identical to what a small merchant faces: the card brand’s assessment moves through the acquiring bank to the merchant, and a cyber policy without an explicit PCI-DSS Assessment grant treats that bill as outside its scope, no matter how completely it paid the underlying breach claim.
Why compliance status decides whether the coverage even applies
Even a policy that does carry PCI-DSS Assessment coverage can tie it to whether the business was actually compliant before the breach happened. One cyber insurer, Corvus, is direct about that condition in its own broker-facing coverage guide: “most cyber insurers are likely to exclude or sub-limit PCI-DSS Fines and Penalties coverage if the client is unable to prove compliance.” Coverage terms vary by carrier, so that specific condition needs to be confirmed on your own policy rather than assumed either way. What it turns the coverage into, when a carrier does write it this way, is something closer to a conditional promise than a guaranteed payout. A business that never validated its own PCI compliance status, which is common among small merchants who assume their point-of-sale vendor handles it, can find the assessment coverage reduced or denied for the same reason the underlying fine exists in the first place.
Small businesses remain a real target for this exposure. An Insurance Information Institute paper on small-business cyber risk cites Ponemon Institute research finding that half of small and midsize businesses had experienced a data breach, and cites Hiscox data putting the average cost of a cybersecurity incident for the smallest organizations at $35,967, figures from an III paper published in 2017 using data from 2016, still the most-cited baseline in trade coverage of this exposure. A card-data breach at a small retailer or restaurant is exactly the scenario where PCI assessments, forensic costs, and liability claims can all land on the same incident at once, and compliance status matters at the application stage too, the same way misstating multi-factor authentication on a cyber application can void coverage entirely.
What to check on your own cyber policy
Cyber is one of the few commercial lines still getting cheaper for buyers right now, which makes this the moment to negotiate coverage detail rather than just premium. US cyber insurance rates fell 2% in the second quarter of 2026, matching the prior quarter’s decline, according to Marsh’s Global Insurance Market Index. A softening market gives a small business more leverage to ask for a named PCI-DSS Assessment grant instead of accepting a policy that only implies it.
Ask your broker or carrier directly whether “PCI-DSS Assessment” or “PCI Fines and Penalties” appears as its own named coverage grant, not just a general reference to “regulatory fines,” and get the sublimit in writing rather than assuming it matches your main breach-response limit. Confirm whether that coverage is conditioned on documented PCI compliance, and if you haven’t validated your own compliance status with your payment processor recently, do that before a breach forces the question. A card-data breach at a business that takes card payments routinely produces the breach-response bill people expect and the card-brand assessment bill almost nobody budgets for, and only one of those two bills is guaranteed to be covered by a standard policy.
Frequently asked questions
What is a PCI DSS assessment, and who charges it? It’s a fine or cost the card networks (Visa, Mastercard, and others) charge for non-compliance with data security standards after a card-data breach. The charge is billed through your acquiring bank, the bank that processes your card transactions, rather than sent to you directly by the card networks.
Does my cyber insurance policy automatically cover PCI fines? Not necessarily. Standard breach-response coverage pays for forensics, notification, and credit monitoring, but PCI-DSS Assessment coverage is often written as its own separate line item with its own sublimit, and some policies exclude it entirely unless it’s explicitly added.
How much can a PCI non-compliance assessment cost a small business? Under Visa’s published assessment schedule, smaller-volume merchants can face assessments in the $5,000 to $25,000 range per incident, while the largest merchants and processors can face assessments up to $100,000. Card reissuance costs from the breach can add to that total separately.
Why did P.F. Chang’s cyber insurer deny its PCI assessment claim? The insurer, Chubb, paid $1.7 million for standard breach-response costs but denied a separate $1.9 million in card-brand assessments because the policy’s coverage for that specific type of cost wasn’t written the way the claim required, according to Insurance Journal’s account of the dispute.
Does PCI assessment coverage require me to already be PCI compliant? Often, yes. Many cyber insurers sublimit or exclude PCI-DSS Assessment coverage if the business can’t demonstrate it was compliant before the breach, which means an unvalidated compliance status can reduce or eliminate this specific coverage even if the rest of the policy pays normally.
Does your cyber policy actually name PCI-DSS assessment coverage?
Compare business insurance quotes and confirm what a card-data breach would actually cost you beyond the standard breach-response payout.
Compare Business Insurance Quotes























