PCI-DSS Merchant Levels 1–4 Explained
Your PCI-DSS validation obligation is not determined by industry or company size — it’s determined almost entirely by annual card transaction volume. Here is how the four merchant levels are set, and what each one requires you to prove.
Levels Are Set by Card Brand, Not by PCI SSC
The PCI Security Standards Council maintains the PCI-DSS requirements. Merchant levels and validation thresholds are set independently by each card brand — Visa, Mastercard, American Express, Discover, and JCB — and their published thresholds differ slightly from one another. Visa’s and Mastercard’s frameworks are the most commonly referenced; if your business accepts multiple brands, your acquirer will tell you which brand’s threshold governs your validation requirement, and a brand can also reclassify a merchant to Level 1 following a data breach regardless of transaction volume.
The Four Levels, by Transaction Volume
Transaction counts include all channels — in-store, e-commerce, mail order, and telephone — combined, not just one channel in isolation.
Thresholds per Visa and Mastercard public merchant-level documentation. American Express, Discover, and JCB apply their own similar but not identical thresholds — confirm with your acquirer if you accept those brands directly.
What Actually Changes Between a Self-Assessment and a Formal Audit
A self-administered questionnaire — the appropriate one from A through P2PE — completed and attested to internally, typically signed by an executive officer. No independent assessor review is required, though quarterly Approved Scanning Vendor (ASV) scans are generally still required for internet-facing systems. Faster and less expensive, but the organization bears full responsibility for the accuracy of its own self-assessment.
A formal, on-site (or remote, where permitted) audit conducted by a PCI SSC Qualified Security Assessor (QSA), producing a detailed Report on Compliance covering every applicable requirement with tested evidence, not attestation. Significantly more rigorous, more time-consuming, and more expensive — but it is also what most acquiring banks and some cyber insurers treat as the credible standard for a high-transaction-volume merchant’s risk posture.
See our SAQ types guide to identify which specific questionnaire applies once you know your level.
A Breach Can Reclassify You to Level 1 Overnight
Mastercard’s program explicitly provides that any merchant suffering an incident leading to compromise of account data can be reclassified as Level 1, regardless of transaction volume — meaning a Level 4 merchant with a breach can suddenly be facing a QSA-led ROC. This is one of the strongest arguments for treating PCI-DSS as continuous operational discipline rather than an annual paperwork exercise, since the validation bar itself can move against you at the worst possible moment.
Armorstack’s VERITY portfolio confirms your current merchant level with your acquirer, maps it to the correct validation path, and builds the monitoring and segmentation posture that keeps a routine incident from escalating into a forced Level 1 reclassification.
Continue Reading
Now that you know your level, find the exact questionnaire that fits how you process cards.
Cost drivers differ sharply between a self-assessed Level 4 merchant and a QSA-audited Level 1.
Back to the full guide on the 12 requirements and who has to comply.