Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

PCI DSS merchant levels explained

PCI DSS Merchant Levels: A Clear Guide to All 4 in 2026

PCI DSS merchant levels decide how you prove compliance, not what you have to comply with. Every merchant that stores, processes or transmits cardholder data is subject to all of PCI DSS v4.0.1; the level — 1 through 4 — sets whether you validate with an on-site assessment and a Report on Compliance, or with a Self-Assessment Questionnaire, and how often you scan. The levels are set by the card brands, not by the PCI Security Standards Council, and the thresholds are counted in transactions per year. This guide explains the four levels as Visa and Mastercard define them, what each one requires, the three ways a merchant gets moved up a level without its volume changing, and how to work out which level you are actually on.

PCI DSS merchant levels: four tiers by annual transaction volume
The four levels: the top tier validates with a QSA-signed Report on Compliance; the three below use a Self-Assessment Questionnaire.

Where PCI DSS merchant levels come from

The PCI Security Standards Council writes the standard. It does not define merchant levels, set validation requirements or enforce anything. Those decisions belong to each card brand’s compliance program — Visa, Mastercard, American Express, Discover and JCB each publish their own — and are applied through the merchant’s acquiring bank, which is the party contractually responsible for making sure its merchants validate at the right level. Visa states that “a merchant’s total Visa transaction volume over a 12-month period determines your merchant level and the necessary requirements for validation”, counting credit, debit and prepaid together, and measured per country or per acquirer.

Two things follow. The level is per brand, so a merchant can in principle be Level 2 with Visa and Level 3 with Mastercard, though the brands have aligned their thresholds closely enough that this rarely matters. And the acquirer has the final say: it can require a higher validation than the brand minimum, and it is the acquirer, not the brand, that a merchant reports to.

The four PCI DSS merchant levels

Level Visa and Mastercard threshold (transactions per year) Validation Scanning
Level 1 Over 6 million, any channel; or any merchant the brand designates Level 1 Annual on-site assessment by a QSA (or qualified internal auditor with an ISA) and a Report on Compliance; Attestation of Compliance Quarterly external scans by an Approved Scanning Vendor
Level 2 1 million to 6 million, any channel Annual Self-Assessment Questionnaire and Attestation of Compliance; Mastercard requires a QSA or ISA where the SAQ is A, A-EP or D Quarterly ASV scans
Level 3 20,000 to 1 million e-commerce transactions Annual SAQ and AoC Quarterly ASV scans
Level 4 Fewer than 20,000 e-commerce transactions, and up to 1 million in all channels Annual SAQ and AoC, as required by the acquirer Quarterly ASV scans where the SAQ type requires them

Read the PCI DSS merchant levels thresholds carefully. Levels 1 and 2 count all channels — card-present, mail order, e-commerce. Level 3 is an e-commerce count only; a retailer with 500,000 in-store transactions and 30,000 online is Level 3 by the online figure but is also inside Level 4’s “up to 1 million in all channels”. Where a merchant meets more than one definition, the higher level applies.

Level 1: the Report on Compliance

Level 1 is the only tier that requires an independent assessment. A Qualified Security Assessor tests every applicable requirement against the environment and writes a Report on Compliance in the Council’s template; the merchant signs an Attestation of Compliance; both go to the acquirer, and the brands may ask for the AoC directly. Large merchants with an internal audit function can use an Internal Security Assessor instead of a QSA where the brand permits it, but the ROC format and the quarterly ASV scans are the same. Budget for the assessment as a project, not a form — our guide to PCI DSS compliance cost gives the ranges.

Levels 2 to 4: the Self-Assessment Questionnaire

Everyone below Level 1 self-assesses. The SAQ type depends on how the merchant handles card data — SAQ A for fully outsourced e-commerce, SAQ A-EP where the merchant’s site affects the payment page, SAQ B and B-IP for standalone terminals, SAQ C and C-VT for payment applications and virtual terminals, SAQ P2PE for validated point-to-point encryption, and SAQ D for everyone else. The level does not choose the SAQ; the channel does. Our guide to PCI DSS SAQ types covers the selection. Mastercard’s Level 2 rule is the one exception worth remembering: a Level 2 merchant completing SAQ A, SAQ A-EP or SAQ D must engage a QSA or a PCI SSC-certified Internal Security Assessor for its validation, while Level 2 merchants on SAQ B, B-IP, C, C-VT or P2PE may self-assess without one.

Three ways a merchant is moved up a level

Volume is the default rule for PCI DSS merchant levels, but the brands reserve the right to reassign a merchant, and three triggers are common.

  1. A data compromise. Mastercard’s Level 1 definition includes any merchant that has suffered a breach resulting in an account data compromise, regardless of volume. Visa’s program gives it similar discretion. A compromised Level 4 merchant should expect to validate as Level 1 for its next cycle.
  2. Brand discretion. Both brands state that any merchant they determine should meet Level 1 requirements is Level 1. That decision is typically made for merchants with elevated risk — high fraud rates, a history of non-compliance, or a business model the brand wants assessed.
  3. The acquirer’s own rules. The acquirer carries the brands’ fines and can require a ROC from a merchant the brands would let self-assess. Large or unusual Level 2 merchants are sometimes asked for a QSA assessment for that reason.

One move goes the other way. Visa’s Technology Innovation Program offers validation relief to merchants whose transactions overwhelmingly originate through EMV chip terminals, validated point-to-point encryption or industry-standard tokenization — Visa cites at least 75% of yearly transactions — because the exposure of cardholder data in those environments is limited. Ask the acquirer whether it applies; it does not remove the obligation to comply.

What PCI DSS merchant levels do not change

The standard applies in full at every level. A Level 4 merchant with a single terminal is subject to all twelve PCI DSS requirements that apply to its environment, including the ones that became mandatory on 31 March 2025 when v4.0’s future-dated requirements took effect. What changes is scope — a merchant that outsources payment processing entirely has a small environment and a short SAQ — not obligation. The scoping rules are covered in our guide to PCI DSS scope; get scope right before worrying about level, because it decides the size of the job at any tier.

Nor do PCI DSS merchant levels change the consequences of a breach. Fines, forensic investigation costs and card reissuance charges are passed to the merchant by the acquirer regardless of tier, and a Level 4 merchant with no validated compliance is in the weakest position to contest them.

Working out your PCI DSS merchant level

  1. Get the count from the acquirer. The acquirer sees the transaction volume per brand and is the party that assigns the level. Do not estimate from revenue.
  2. Count per brand and per channel. Visa and Mastercard are separate counts. Split e-commerce from other channels, because Level 3 is an e-commerce threshold.
  3. Apply the highest definition you meet. More than 6 million in any channel is Level 1 regardless of the e-commerce figure.
  4. Check the exceptions. A compromise in the last 12 months, a brand designation, or an acquirer requirement can override the volume rule.
  5. Confirm in writing. The acquirer’s merchant agreement or compliance portal should state the level and the validation documents due. Keep the confirmation with the AoC.

Frequently asked questions

Who sets PCI DSS merchant levels?
The card brands — Visa, Mastercard, American Express, Discover and JCB — each through its own compliance program, applied by the acquiring bank. The PCI Security Standards Council writes the standard but does not set levels or enforce them.

Does a Level 4 merchant have to comply with all of PCI DSS?
Yes. All applicable requirements apply at every level. The level changes only how compliance is validated — SAQ versus on-site assessment — and reporting frequency.

What is the difference between Level 3 and Level 4?
Level 3 is 20,000 to 1 million e-commerce transactions a year. Level 4 is fewer than 20,000 e-commerce transactions, or up to 1 million transactions across all channels. Both validate by SAQ.

Can a small merchant be made Level 1?
Yes. A merchant that has suffered an account data compromise, or that a brand designates because of its risk profile, validates as Level 1 regardless of volume.

Do we need a QSA at Level 2?
For Visa, an SAQ is sufficient. Mastercard requires a QSA or ISA-certified staff for Level 2 merchants completing SAQ A, A-EP or D; merchants on the other SAQ types may self-assess. The acquirer may require more.

Where this leaves you

Get your transaction counts from the acquirer, per brand and per channel, apply the highest definition you meet, and check the three overrides. Then stop treating the level as the compliance problem: at every tier the standard applies in full, and the real variable is scope. A small environment with a short SAQ and clean quarterly scans is a better position than a large one with a ROC.

References

More on PCI DSS

Scoping worksheets, the policy set behind every SAQ type and the evidence index a QSA works from are in the PCI DSS Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.