Why med spas specifically draw scrutiny

Recurring membership billing, stored card-on-file for package treatments, and high-ticket single transactions all increase a business's PCI compliance level and the frequency of required validation. This isn't unique to med spas, but the combination of all three in one business is more common here than in most other hospitality verticals.

The four PCI levels, in plain terms

PCI compliance level is set by annual transaction volume, not business type — but a med spa's membership and package billing model tends to accumulate more stored-card transactions than a comparable single-visit business, which can push it into a stricter validation tier faster than the owner expects.

What compliance actually requires

A completed Self-Assessment Questionnaire (SAQ) matched to how the business actually takes payment (card-present terminal vs. card-on-file vs. online booking payment). Quarterly network vulnerability scans if storing, processing, or transmitting card data through owned systems. Documented policies for how stored card data is protected, and confirmation that any booking or POS software is itself PCI-compliant.

The compliance fee, and how to tell if it's fair

Processors frequently charge a monthly or annual PCI compliance fee whether or not the business has actually completed its SAQ. A fair fee funds real compliance support; an inflated one is a padded line item. The way to tell the difference: ask the processor to walk through exactly what the fee funds and whether SAQ completion status is actively tracked for the account.