PCI-DSS · Merchant Levels

PCI-DSS Merchant Levels 1–4 Explained

Your PCI-DSS validation obligation is not determined by industry or company size — it’s determined almost entirely by annual card transaction volume. Here is how the four merchant levels are set, and what each one requires you to prove.

Important Caveat

Levels Are Set by Card Brand, Not by PCI SSC

The PCI Security Standards Council maintains the PCI-DSS requirements. Merchant levels and validation thresholds are set independently by each card brand — Visa, Mastercard, American Express, Discover, and JCB — and their published thresholds differ slightly from one another. Visa’s and Mastercard’s frameworks are the most commonly referenced; if your business accepts multiple brands, your acquirer will tell you which brand’s threshold governs your validation requirement, and a brand can also reclassify a merchant to Level 1 following a data breach regardless of transaction volume.

Visa & Mastercard

The Four Levels, by Transaction Volume

Transaction counts include all channels — in-store, e-commerce, mail order, and telephone — combined, not just one channel in isolation.

Level Visa Threshold Mastercard Threshold Validation Required
Level 1Over 6 million transactions/year (any channel), or Visa-designatedOver 6 million transactions/year, or any brand that suffered a data breachAnnual QSA-led Report on Compliance (ROC) + quarterly ASV scans
Level 21 to 6 million transactions/year1 to 6 million transactions/yearAnnual SAQ (self-assessed) + quarterly ASV scans + Attestation of Compliance
Level 320,000 to 1 million e-commerce transactions/year20,000 to 1 million transactions/yearAnnual SAQ + quarterly ASV scans
Level 4Fewer than 20,000 e-commerce transactions/year, or up to 1 million transactions/year of any other channelFewer than 20,000 transactions/yearAnnual SAQ; acquirer sets whether ASV scans and AOC submission are required

Thresholds per Visa and Mastercard public merchant-level documentation. American Express, Discover, and JCB apply their own similar but not identical thresholds — confirm with your acquirer if you accept those brands directly.

SAQ vs. ROC

What Actually Changes Between a Self-Assessment and a Formal Audit

SAQ (Levels 2–4)

A self-administered questionnaire — the appropriate one from A through P2PE — completed and attested to internally, typically signed by an executive officer. No independent assessor review is required, though quarterly Approved Scanning Vendor (ASV) scans are generally still required for internet-facing systems. Faster and less expensive, but the organization bears full responsibility for the accuracy of its own self-assessment.

Report on Compliance (Level 1)

A formal, on-site (or remote, where permitted) audit conducted by a PCI SSC Qualified Security Assessor (QSA), producing a detailed Report on Compliance covering every applicable requirement with tested evidence, not attestation. Significantly more rigorous, more time-consuming, and more expensive — but it is also what most acquiring banks and some cyber insurers treat as the credible standard for a high-transaction-volume merchant’s risk posture.

See our SAQ types guide to identify which specific questionnaire applies once you know your level.

Watch For

A Breach Can Reclassify You to Level 1 Overnight

Mastercard’s program explicitly provides that any merchant suffering an incident leading to compromise of account data can be reclassified as Level 1, regardless of transaction volume — meaning a Level 4 merchant with a breach can suddenly be facing a QSA-led ROC. This is one of the strongest arguments for treating PCI-DSS as continuous operational discipline rather than an annual paperwork exercise, since the validation bar itself can move against you at the worst possible moment.

Armorstack’s VERITY portfolio confirms your current merchant level with your acquirer, maps it to the correct validation path, and builds the monitoring and segmentation posture that keeps a routine incident from escalating into a forced Level 1 reclassification.

Not Sure Which Merchant Level You’re At?

Armorstack confirms your merchant level with your acquirer and maps the correct validation path before your next assessment cycle.

877-890-5508 · [email protected]