PCI DSS Merchant Levels

Table of Contents

Compliance Questions?

Key Takeaways

  1. Volume Determines Validation: The four PCI DSS merchant levels are determined by the annual volume of payment card transactions processed. Higher transaction volumes correspond to stricter compliance requirements and more rigorous validation procedures.

  2. Level 1 Requires On-Site Validation: Merchants processing over 6 million annual transactions (Level 1) face the highest compliance burden, requiring an annual on-site security validation performed by a qualified third-party firm, resulting in a Report on Compliance (ROC).

  3. SAQs and Quarterly Scans: Merchants in Levels 2, 3, and 4 generally validate their compliance annually by completing a Self-Assessment Questionnaire (SAQ). Crucially, all merchants must perform mandatory quarterly network scans by an Approved Scanning Vendor (ASV).

Understanding PCI DSS Requirements

The PCI DSS (Payment Card Industry Data Security Standard) outlines requirements to help companies avoid payment data breaches or credit card fraud, and is the result of collaboration between major security card brands. These requirements ensure that card payments receive proper protections. 

In many cases, service providers may not know that they need to be PCI compliant until clients start asking for assurance. One unique aspect of PCI compliance for service providers is registering for the Visa Global Registry of Service Providers or MasterCard SDP Compliant Registered Service Provider List. These lists are maintained by Visa and MasterCard for use by prospective customers to find service providers that Visa and MasterCard deem as PCI compliant.

Speak to a Compliance Specialist.

Book a free consultation with a specialist to check off your compliance needs. Secure your spot today.

Understanding PCI DSS Merchant Levels:

The process for being listed is straight forward but can be particularly daunting for organizations that are not directly dealing with cardholder data and therefore do not have a relationship with an acquiring bank. 

Click below to read about PCI DSS Merchant Levels for each major card brand:

Subscribe to our newsletter.

Stay up to date with the latest from Auditwerx.

Your PCI Partner

Auditwerx can provide the guidance and assistance necessary to get a service provider easily through the Visa and MasterCard service provider registration process as well as keeping them listed.

Merchant levels may change, but Auditwerx QSAs understand what it takes to get through merchant assessments quickly and easily. Contact a PCI specialist today!

FAQs

The four levels, based on annual transaction volume, are: Level 1 (over 6 million transactions), Level 2 (1 million to 6 million transactions), Level 3 (20,000 to 1 million e-commerce transactions), and Level 4 (under 20,000 e-commerce transactions or up to 1 million total transactions).

Level 1 merchants must obtain an annual Report on Compliance (ROC) from a qualified third-party firm that performs an on-site security validation. They also must complete quarterly network scans by an Approved Scanning Vendor (ASV).

Merchants in these lower levels generally validate their compliance annually by completing the appropriate Self-Assessment Questionnaire (SAQ) and ensuring they perform mandatory quarterly network scans by an ASV.

The volume of transactions dictates the level of risk and exposure to cardholder data. Higher volumes require more rigorous compliance requirements, ensuring that businesses with greater risk exposure implement the strictest security controls and external validation procedures.

About the Author

Picture of Auditwerx Team
Auditwerx Team
Tampa-based Auditwerx has provided over 3,500 security compliance reports to clients nationally and internationally since 2009, leveraging the specialized resources and experts of a top accounting firm for high-quality, personalized service. As a division of Carr, Riggs & Ingram Capital, LLC, Auditwerx offers clients the skills of a large firm—including CISSPs and CISAs—combined with the accessibility of a niche, boutique firm, dedicated to building long-term, transparent partnerships.

Related Content

Gain Deeper Insights