Introduction
Canadian restaurants process high volumes of card payments across point‑of‑sale (POS) terminals, online ordering, and delivery platforms. That makes Payment Card Industry (PCI) compliance and cyber insurance mission‑critical. This page explains how “PCI fines & assessments” work, what POS vendors cover versus what the merchant still owns, typical cyber policy sublimits and waiting periods, realistic price anchors for restaurants, and how Summit can help place fit‑for‑purpose coverage.
Why this matters now
-
PCI DSS v4.0 became the only active standard on March 31, 2024; most “future‑dated” v4.0 requirements became mandatory on March 31, 2025 (v4.0.1 issued June 2024 for clarifications). Source: PCI Security Standards Council and independent QSA timelines.
-
Brand/contract enforcement continues through Visa and Mastercard programs; acquirers are responsible for merchant PCI, and non‑compliance can trigger assessments after breaches.
What “PCI fines & assessments” actually are
-
Assessments: card‑brand/liability amounts billed via your acquirer after an account data compromise (e.g., issuer operating expense reimbursements, card reissuance, fraud recovery). Visa’s rules allow non‑compliance assessments to the acquirer if a merchant/service provider fails PCI; acquirer then seeks reimbursement per your processing agreement.
-
Fines/penalties for PCI violations: Mastercard documents “SDP noncompliance assessments” and PCI‑violation assessments in its Security Rules and ADC (Account Data Compromise) sections.
POS platforms: what they cover vs. what you still own
-
Square: states it “complies with PCI DSS on your behalf” when you use Square hardware/software end‑to‑end; however, adding third‑party integrations can put PCI obligations back on you.
-
Lightspeed: emphasizes all merchants that accept cards must be PCI compliant; Lightspeed Payments hardware/software is kept PCI compliant, but merchants must manage broader controls (e.g., networks, training, passwords).
-
Toast: merchant agreement references brand rules and PCI DSS; merchants still bear obligations set by networks/acquirers and other laws.
-
Clover: for ecommerce, Clover tokenization can reduce scope; for PCI DSS v4.0, merchants using their own payment pages must meet new script‑management requirements (6.4.3, 11.6.1).
How cyber insurance addresses PCI exposures for restaurants
-
PCI fines & assessments coverage: many Canadian cyber policies include a specific insuring agreement for “PCI fines and assessments.”
-
Sublimits are common and separate from the overall cyber limit. Public filings show PCI DSS Assessment sublimits frequently in the CAD/USD 50,000–250,000 range for small accounts, with options to buy higher.
-
Business interruption (BI) and dependent BI (cloud/POS vendor outages) respond to lost income and extra expense once the waiting period is met; market waiting periods are commonly 8–12 hours, though some carriers offer 6 hours or lower by endorsement/controls.
Common sublimits and waiting periods (illustrative)
| Item | Typical SME restaurant pattern | Notes/sources |
|---|---|---|
| PCI fines & assessments | CAD 50k–250k sublimit; higher available | SEC schedule example showing $50k base with options to $250k+; many markets mirror this structure. |
| Regulatory fines/penalties | Often full limit or separate sublimit | Wording varies; “most‑favourable‑jurisdiction” language is common. |
| Business interruption waiting period | 8–12 hours common; some 6h; best‑case 1h for DDoS with controls | |
| Dependent BI (vendor outage) | Same or slightly longer waiting period | Check wording for “system failure” vs. “security failure.” |
Price anchors for Canadian restaurants (indicative)
-
Entry‑level standalone cyber for small restaurants commonly starts around CAD $500–$1,000/year; some bundled or low‑limit options appear at ~CAD $750–$1,000/year, with $50k add‑ons in PL/E&O sometimes $100–$200/year.
-
Broader small‑business cyber ranges of CAD ~$300–$4,000+ are common depending on revenue, controls, and limits; mid‑market can scale to five figures. Sources include Summit’s guides and market commentary.
Notes: Actual premiums depend on limit, revenue, number of locations, payment volume, POS architecture, MFA/backup posture, claims history, and vendor dependencies.
2025 PCI DSS v4.0 controls that trip up restaurants
-
Payment‑page script inventory/change detection for ecommerce (6.4.3, 11.6.1) now required; even if you outsource checkout, confirm scope with your provider.
-
“Never store” sensitive authentication data; keep POS software/firmware and network devices patched; remove vendor defaults; train staff; and segment cardholder data environments.
Claims scenarios (restaurant‑specific)
-
POS malware or misconfiguration results in card data theft; acquirer bills PCI assessments and card reissuance costs. Cyber “PCI fines & assessments” may respond up to the sublimit; regulatory defence/penalties may also trigger. Historic POS breach patterns are instructive.
-
Third‑party tech outage (e.g., software update gone wrong) shuts down payments/ordering; dependent BI may apply if the outage exceeds your waiting period.
-
Web‑skimming on an online ordering page violates PCI DSS, driving breach costs and assessments; v4.0 script governance requirements now apply.
How Summit helps restaurants
-
Coverage built for hospitality: see our Hospitality and Restaurant Insurance resources.
-
Cyber expertise: we compare multiple markets and forms, confirm PCI fines & assessments sublimits, evaluate dependent BI, ransomware, social engineering, and regulatory cover. Explore our Cyber Insurance hub.
-
Transparent compensation and client‑first placement process: see our compensation disclosure.
Practical checklist for owners/operators
-
Confirm your payment flow: end‑to‑end with a validated provider (e.g., Square, Toast, Lightspeed, Clover) or mixed/integrated? Document PCI scope and SAQ type annually.
-
Enforce MFA, unique credentials, and removal of vendor defaults across POS and back‑office systems; harden Wi‑Fi and segment guest networks.
-
Patch POS endpoints and gateways promptly; perform anti‑tamper checks on card readers; train staff on phishing and handling card data.
-
For ecommerce/online ordering, inventory and authorize payment‑page scripts; monitor for tampering (PCI DSS 6.4.3, 11.6.1).
-
Align insurance with payment volume and tech dependencies: set a PCI sublimit that reflects worst‑case assessments; review BI waiting period against realistic outage durations for your vendors.
FAQ — PCI fines & assessments, POS, and cyber insurance
-
Are “PCI fines & assessments” insurable? Many Canadian cyber policies include a specific insuring agreement for PCI fines & assessments, usually with a separate sublimit and subject to insurability of fines by law.
-
What sublimit do restaurants typically carry for PCI fines & assessments? For small/independent restaurants, CAD 50k–250k sublimits are common, with options to buy higher; confirm in your specimen and binder.
-
Does using Square/Lightspeed/Clover/Toast make me “fully PCI compliant”? These platforms reduce scope and handle parts of PCI, but you still own network/security hygiene, staff training, and any third‑party systems touching card data.
-
What waiting period should I expect on cyber BI? 8–12 hours is common market practice; some carriers offer lower (e.g., 1 hour for DDoS with approved mitigation).
-
How much does cyber cost for restaurants? Indicative entry points are ~CAD $500–$1,000/year for small operations, scaling with limits/controls. Various industry sources and guides offer further details.
Need help sizing the right PCI sublimit, BI waiting period, and vendor‑dependency coverage for your restaurant? Connect with Summit’s hospitality and cyber specialists via our Hospitality and Cyber Insurance pages.