Watch Out for EMV Non-Compliance Fees
The October 1st EMV liability shift has come and gone, and you probably know that if you don’t have an EMV-capable terminal to take chip cards, you’re now liable for fraudulent transactions. But did you know that you may be subject to an EMV non-compliance fee or EMV non-enabled fee?
- What are EMV non-compliance/non-enabled fees?
- Will my business be charged EMV non-compliance fees?
- How much is the fee?
- Why are processors charging EMV non-compliance fees?
- Is EMV compliance the same as PCI compliance?
- How do I get EMV compliant and avoid fees?
What are EMV non-compliance fees?
EMV non-compliance fees are fees that your processor can add to your bill if you don’t use EMV-capable equipment. Unlike the liability shift, where you would only be charged if you process a fraudulent transaction, EMV non-compliance fees will be charged automatically for as long as you continue to take cards without an EMV chip terminal. Basically, they’re a penalty for not using an EMV-capable machine. Note that EMV non-compliance fee is a general term and that the fee charged may have a different name, like EMV non-enabled fee.
Processors are free to label the fee however they'd like. If you see any new or confusing fees on your statement, be sure to check into what it is and how to avoid it in the future.
Will my business be charged EMV non-compliance fees?
As of March 2017, CardFellow has reviewed statements that showed an EMV non-enabled fee from the following processors:
According to payments resource Digital Transactions, as of October 2015, only Vantiv-owned National Processing Company (NPC) was confirmed to have announced an EMV non-compliance fee (called the EMV non-enabled fee.) In the summer of 2016, some consumers began reporting that Elavon was also charging EMV non-compliance fees, and in 2017, CardFellow confirmed this with a firsthand statement review of an Elavon statement from December 2016.
It's worth noting that NPC and Elavon have multiple ISOs (or resellers) of processing services, so even if you don't think you process through NPC or Elavon, you might. Be sure to check your statements carefully for an EMV non-enabled fee.
Many processors already have other non-compliance fees (such as PCI non-compliance) so there’s an established pattern of charging for non-compliance. Keep an eye out for any communication from your processor, as they will likely inform you of EMV non-compliance fees in the coming months.
If your processor does impose an EMV non-compliance fee, there are two situations where it would not apply to you:
- You don’t take any credit or debit cards in person.
- You already have and are using EMV-capable credit card terminals.
Exceptions for card-not-present businessesIt’s important to note that EMV non-compliance fees only apply to businesses that take credit cards in person, known as “card present” transactions. This means that businesses that only take payments in “card-not-present” situations are not affected. Examples of card-not-present transactions include those taken by online-only businesses or mail and phone order businesses.
What if I have a mix of card-present and card-not-present transactions?If your business takes payments both in person and online, you will pay the EMV non-compliance fee on the card-present transactions.
Using EMV capable terminalsIf you already have an EMV-capable terminal and are actively accepting chip credit cards, the EMV non-compliance fee won’t affect you. If you don’t have an EMV-capable terminal and are charged a non-compliance fee, you can get an EMV-capable terminal and begin using it to end the EMV non-enabled charge.
How much is the fee?
EMV non-compliance fees will likely vary by processor. Processors may choose to impose a flat monthly or annual non-compliance fee, or they may opt for a percentage fee based on your processing volume.
NPC has announced a percentage charge for EMV non-compliance. The fee will be charged as a percentage of card-present transaction volume. So the more you process without an EMV terminal, the higher your fee will be. NPC began imposing the fee in 2016. In our review of one statement (snippet pictured above), NPC imposed a fee of 10 basis points on volume. If you're being charged an EMV non-enabled fee, let us know in the comments.
The Elavon statement that CardFellow reviewed showed a non-enabled fee of $5. It's not clear if this fee is monthly or annually, or if it's processor-mandated. Additionally, the fee amount may not be the same for every business. As we continue to uncover more information about EMV non-compliance fees, including Elavon's, we'll update this article.
Note that resellers (or ISOs) have the option of passing along the fee or absorbing the cost themselves, though the latter is unlikely. It's also worth mentioning that there are currently no restrictions on adding a markup to an EMV non-compliance fee. If your processing company wants to play games and make more money from you, it could easily pass along the non-compliance fee charged by the processor plus a markup for itself, while telling you that the whole fee is the non-compliance fee and that it can't do anything. That may or may not be the case. Keep an eye on your statements, and don't be afraid to ask questions about new fees, especially the EMV non-enabled fee.
Why are processors charging EMV non-compliance fees?
There are two reasons, depending on how cynically you want to view it. The more optimistic reason is that processors want to hasten the upgrade to EMV-capable terminals because EMV chip card transactions are more secure and will help reduce fraud. Everyone likes less fraud. The cynical reason is that it’s a money grab. Extra fees mean extra money for the processor, though NPC states the fee is to help mitigate their own risk for your business not accepting EMV transactions.
Is EMV compliance the same as PCI compliance?
PCI compliance refers to the requirements you need to meet for accepting any type of card, such as not storing card data. EMV compliance refers to the ability to accept EMV chip cards with an EMV terminal. Just because you may be PCI compliant doesn’t mean you’re automatically EMV compliant and vice-versa. However, some EMV terminals use advanced security such as end-to-end encryption and may help you achieve PCI compliance more easily.
Because EMV compliance and PCI compliance are different things, you could now be subject to two fees at your processor’s discretion: one for EMV non-compliance and one for PCI non-compliance. (Note that not all processors charge a PCI non-compliance fee.)
How do I become EMV compliant and avoid fees?
One complication is that many businesses haven’t been able to get or activate EMV capable terminals due to delays from processors and equipment manufacturers. Essentially, you could be told that you can't use an EMV terminal right now, but in the meantime, they're going to charge you for not having one. Hopefully this scenario will be avoided as more EMV-capable equipment becomes available. Since EMV non-compliance fees aren’t expected to start until the beginning of 2016 for NPC and have not been announced by other processors, there is still time to get set up with an EMV capable terminal.
If you already have an EMV-capable terminal that isn’t active or usable, call your processor to find out when it will be active. If they can’t activate it, push back on any EMV non-compliance fees, if they charge them. You shouldn’t be penalized for their delay.
If you don’t have an EMV-capable terminal, call your processor to find out what you need to get set up with one. You can also sign up for a free CardFellow account or browse our product directory to find EMV-capable equipment.
Even if you’re charged the EMV non-enabled fee, you can stop those charges by getting and using an EMV-capable terminal. The fee will only be charged while you’re processing with a non-EMV terminal.
The bottom line is that processors and banks want you to move to EMV equipment because it’s more secure for everyone. If you’ve been holding off on EMV-capable equipment you may want to think about upgrading before more processors begin imposing expensive fees.
If you've seen a non-enabled or non-compliance fee on your statement, let us know how much it is and which processor charged it in the comments below!