How to determine your PCI Level?

Regardless of whether your business processes 10 transactions a year or 10 million, PCI DSS compliance is mandatory.

Higher transaction volumes increase the risk of data breaches, prompting the Payment Card Industry Data Security Standard (PCI DSS) to classify businesses into compliance levels.

Determining your compliance level is essential as it dictates your reporting requirements and guides your path to compliance.

Understand the actual requirements

PCI merchant vs. service provider

To determine your PCI DSS level, first identify whether your business is a merchant or a service provider.

Merchants are businesses that accept card payments from any of the five PCI Security Standards Council members: American Express, Discover, JCB, MasterCard, or Visa.

Service providers, on the other hand, do not issue cards but are involved in processing, storing, or transmitting cardholder data for merchants, thereby affecting the security of that data. This category includes companies like managed service providers that offer managed firewalls and hosting services.

The payment card brands categorize both merchants and service providers into different reporting levels based on their annual transaction volume. Let’s explore these levels for each group.

Differences between levels

PCI merchant levels

For merchants, there are generally four PCI DSS compliance levels starting with Level 4 and working up to Level 1.

  • PCI Level 1: Businesses processing over 6 million card transactions per year
  • PCI Level 2: Businesses processing 1 million to 6 million card transactions per year
  • PCI Level 3: Businesses processing 20,000 to 1 million card transactions per year
  • PCI Level 4: Businesses processing fewer than 20,000 card transactions per year

Each PCI compliance level could have a different set of reporting requirements, with Level 4 requiring a self attestation and Level 1 requiring a third-party audit.

1. Merchant Requirements

Merchant Levels

Requirements

1

PCI Level

Process over 6mio transactions / year

Level 1 merchants are those that process over 6 million card transactions annually, facing the most rigorous reporting requirements among the four PCI compliance levels.

Instead of completing a self-assessment questionnaire (SAQ), these merchants must submit an annual Report on Compliance (RoC), which is prepared with the help of a third-party Qualified Security Assessor (QSA). The QSA conducts a comprehensive audit to determine if the business meets PCI DSS requirements and compiles their findings in the RoC. These audits are required every year.

In addition to the RoC, Level 1 merchants must complete two types of testing: quarterly network scans and annual penetration testing. They also need to provide an Attestation of Compliance (AoC) form, signed by the QSA, confirming adherence to PCI DSS standards.

Importantly, any merchant that experiences a data breach compromising cardholder data may be elevated to Level 1 by their acquiring bank or other relevant parties.

Certification Requirements Summary:

  • Annual RoC
  • Quarterly network scan by ASV
  • Annual penetration test
  • Completed AoC form

2

PCI Level

Process between 1 - 6 mio transactions / year

Level 2 merchants process between 1 million and 6 million card transactions annually. Unlike Level 1 merchants, they are not required to undergo an annual QSA-led Report on Compliance audit. Instead, they complete a Self-Assessment Questionnaire (SAQ), although a third-party QSA may be required to attest to the SAQ in some cases.

The SAQ consists of a series of self-guided questions that evaluate your PCI compliance. There are eight types of SAQs, and the specific one you need to complete depends on your business type as a merchant or service provider.

For instance, an e-commerce merchant that processes card-not-present transactions and uses a third party to handle cardholder data would fill out SAQ A. Conversely, an e-commerce merchant that collects cardholder data through their own application and transmits it to a third party would complete SAQ A-EP.

The number of questions varies by SAQ type, with SAQ A being the shortest at 24 questions, while SAQ D contains 328 questions.

Certification Requirements Summary:

 

  • Annual SAQ
  • Quarterly network scan by ASV
  • Annual penetration test
  • Completed AoC form

3

PCI Level

Process between 20k - 1 mio transactions/year

Level 3 merchants process between 20,000 and 1 million transactions annually. Merchants at this level must complete a Self-Assessment Questionnaire (SAQ) for their business, along with the relevant ASV scanning and penetration testing requirements.

Additionally, they are required to conduct quarterly scans by an Approved Scanning Vendor (ASV) and complete an Attestation of Compliance (AoC).

Certification Requirements Summary:

 

  • Annual SAQ
  • Quarterly network scan by ASV
  • Completed AoC formv

4

PCI Level

Process less than 20k transactions/year

Level 4 merchants process fewer than 20,000 transactions per year and have the least stringent reporting requirements of all four compliance levels. Small businesses often fall into this compliance category and only require an SAQ including applicable ASV scanning and penetration testing requirements.

Certification Requirements Summary:

 

  • Annual SAQ
  • Quarterly network scan by ASV
  • Completed AoC form

Terminology:

RoC – Report on Compliance

AoC – Attestation of Compliance

ASV – Approved Scanning Vendor

SAQ – Self Assessment Questionnaire

2. Service Provider Requirements

Merchant Levels

Requirements

1

PCI Level

More than 300,000 card transactions per year

Level 1 service providers store, process, transmit, or have an impact on more than 300,000 card transactions per year.

Similar to a Level 1 merchant, Level 1 service providers must undergo an annual audit led by a QSA. Once the audit is completed, the QSA will issue an RoC.

Level 1 service providers must also complete annual penetration testing, quarterly network scans by an ASV, and an AoC form.

Certification Requirements Summary:

  • Annual RoC
  • Quarterly network scan by ASV
  • Annual penetration test
  • Completed AoC form

2

PCI Level

Fewer than 300,000 card transactions per year

Level 2 service providers store, process, transmit, or have an impact on fewer than 300,000 card transactions per year.

This level must complete an SAQ D for Service Providers and an AoC form to prove PCI compliance. It is possible at this level that customers would require the SAQ to be attested by a QSA. Level 2 service providers also need to perform annual penetration testing and conduct quarterly network scans by an ASV.

Certification Requirements Summary:

  • Annual SAQ D for Service providers
  • Quarterly network scan by ASV
  • Annual Penetration test
  • Completed AoC form
Get free advice from experts, in 72h or less

Ask us anything

Send us any question you have, we’ll annonymize it and post an answer in 72h or less on our “Ask us anything” page.