Regardless of whether your business processes 10 transactions a year or 10 million, PCI DSS compliance is mandatory.
Higher transaction volumes increase the risk of data breaches, prompting the Payment Card Industry Data Security Standard (PCI DSS) to classify businesses into compliance levels.
Determining your compliance level is essential as it dictates your reporting requirements and guides your path to compliance.
To determine your PCI DSS level, first identify whether your business is a merchant or a service provider.
Merchants are businesses that accept card payments from any of the five PCI Security Standards Council members: American Express, Discover, JCB, MasterCard, or Visa.
Service providers, on the other hand, do not issue cards but are involved in processing, storing, or transmitting cardholder data for merchants, thereby affecting the security of that data. This category includes companies like managed service providers that offer managed firewalls and hosting services.
The payment card brands categorize both merchants and service providers into different reporting levels based on their annual transaction volume. Let’s explore these levels for each group.
For merchants, there are generally four PCI DSS compliance levels starting with Level 4 and working up to Level 1.
Each PCI compliance level could have a different set of reporting requirements, with Level 4 requiring a self attestation and Level 1 requiring a third-party audit.
Level 1 merchants are those that process over 6 million card transactions annually, facing the most rigorous reporting requirements among the four PCI compliance levels.
Instead of completing a self-assessment questionnaire (SAQ), these merchants must submit an annual Report on Compliance (RoC), which is prepared with the help of a third-party Qualified Security Assessor (QSA). The QSA conducts a comprehensive audit to determine if the business meets PCI DSS requirements and compiles their findings in the RoC. These audits are required every year.
In addition to the RoC, Level 1 merchants must complete two types of testing: quarterly network scans and annual penetration testing. They also need to provide an Attestation of Compliance (AoC) form, signed by the QSA, confirming adherence to PCI DSS standards.
Importantly, any merchant that experiences a data breach compromising cardholder data may be elevated to Level 1 by their acquiring bank or other relevant parties.
Certification Requirements Summary:
Level 2 merchants process between 1 million and 6 million card transactions annually. Unlike Level 1 merchants, they are not required to undergo an annual QSA-led Report on Compliance audit. Instead, they complete a Self-Assessment Questionnaire (SAQ), although a third-party QSA may be required to attest to the SAQ in some cases.
The SAQ consists of a series of self-guided questions that evaluate your PCI compliance. There are eight types of SAQs, and the specific one you need to complete depends on your business type as a merchant or service provider.
For instance, an e-commerce merchant that processes card-not-present transactions and uses a third party to handle cardholder data would fill out SAQ A. Conversely, an e-commerce merchant that collects cardholder data through their own application and transmits it to a third party would complete SAQ A-EP.
The number of questions varies by SAQ type, with SAQ A being the shortest at 24 questions, while SAQ D contains 328 questions.
Certification Requirements Summary:
Level 3 merchants process between 20,000 and 1 million transactions annually. Merchants at this level must complete a Self-Assessment Questionnaire (SAQ) for their business, along with the relevant ASV scanning and penetration testing requirements.
Additionally, they are required to conduct quarterly scans by an Approved Scanning Vendor (ASV) and complete an Attestation of Compliance (AoC).
Certification Requirements Summary:
Level 4 merchants process fewer than 20,000 transactions per year and have the least stringent reporting requirements of all four compliance levels. Small businesses often fall into this compliance category and only require an SAQ including applicable ASV scanning and penetration testing requirements.
Certification Requirements Summary:
RoC – Report on Compliance
AoC – Attestation of Compliance
ASV – Approved Scanning Vendor
SAQ – Self Assessment Questionnaire
Level 1 service providers store, process, transmit, or have an impact on more than 300,000 card transactions per year.
Similar to a Level 1 merchant, Level 1 service providers must undergo an annual audit led by a QSA. Once the audit is completed, the QSA will issue an RoC.
Level 1 service providers must also complete annual penetration testing, quarterly network scans by an ASV, and an AoC form.
Certification Requirements Summary:
Level 2 service providers store, process, transmit, or have an impact on fewer than 300,000 card transactions per year.
This level must complete an SAQ D for Service Providers and an AoC form to prove PCI compliance. It is possible at this level that customers would require the SAQ to be attested by a QSA. Level 2 service providers also need to perform annual penetration testing and conduct quarterly network scans by an ASV.
Certification Requirements Summary:
Send us any question you have, we’ll annonymize it and post an answer in 72h or less on our “Ask us anything” page.
Embarking on the PCI compliance journey requires a structured approach. Here are five essential steps to guide your business to successful adherence.
Determine if PCI DSS applies to your business by assessing how you handle cardholder data and transactions.
Educate your team on the importance of PCI compliance and cybersecurity best practices to ensure secure cardholder data handling.
Implement necessary technical and operational safeguards, such as firewalls, encryption, and access controls, to meet PCI DSS standards.
Assign dedicated personnel, tools, and budget to manage PCI compliance, ensuring all requirements are met efficiently.
Regularly audit and test your systems to maintain compliance, addressing any vulnerabilities and staying updated with PCI requirements.
Meet with Matt and book a free 15-min call below to better understand how to implement PCI DSS compliance in your company
Curated by PCIcompliant.org, this page provides publicly-sourced information on everything related to the PCI DSS Directive. Presented in a clear and concise manner for easy consumption.
Disclaimer
The information provided on this website is intended for educational and informational purposes only. The content is not intended to be a substitute for professional advice or any other legal advisory, service, etc. The site’s administrators and contributors make no representations or warranties of the information on the site. Any reliance you place on such information is therefore strictly at your own risk.
Copyright By PCIcompliant.org