Decorative title card illustration with payment security theme
Back to Blog

PCI DSS Compliance Levels Explained for U.S. Merchants

Merchant Solutions Corp8/11/2026

PCI DSS Compliance Levels Explained for U.S. Merchants

Decorative title card illustration with payment security theme

There are four PCI DSS merchant compliance levels, and your level is determined primarily by how many card transactions your business processes annually. Level 1 covers merchants processing more than 6 million transactions per year, Level 2 covers 1–6 million, Level 3 applies to merchants with 20,000–1 million e-commerce transactions, and Level 4 covers fewer than 20,000 e-commerce transactions or up to 1 million transactions through other channels. Your level controls one specific thing: which validation method and reporting path you must follow. The underlying PCI DSS security requirements apply to every merchant who touches cardholder data, regardless of size.

Two automatic triggers can push any merchant straight to Level 1, regardless of volume: a confirmed data breach or an explicit elevation by a card brand or acquiring bank. The PCI Security Standards Council (PCI SSC) sets the standard itself, but card brands like Visa and Mastercard define the levels and enforce them through your acquiring bank.

  • Level 1: More than 6 million total card transactions per year across all channels
  • Level 2: 1 million to 6 million total transactions per year
  • Level 3: 20,000 to 1 million e-commerce transactions per year
  • Level 4: Fewer than 20,000 e-commerce transactions, or up to 1 million transactions through non-e-commerce channels

Key Takeaways

The four PCI DSS merchant levels assign a validation method based on annual transaction volume, but the underlying security requirements apply to every merchant who handles cardholder data.

Point Details
Four levels, volume-defined Level 1 (>6M), Level 2 (1–6M), Level 3 (20K–1M e-commerce), Level 4 (<20K e-commerce or up to 1M other).
Validation path differs by level Level 1 requires an annual ROC by a QSA; Levels 2–4 typically use an SAQ plus quarterly ASV scans.
Breach triggers Level 1 A confirmed data breach elevates any merchant to Level 1 validation requirements, regardless of transaction volume.
v4 requires continuous evidence PCI DSS v4 mandatory controls (effective March 31, 2025) require ongoing monitoring and documented evidence, not just annual snapshots.
Merchantsolutionscorp reduces scope Preconfigured tokenization and P2PE-capable terminals shrink your CDE, simplifying SAQ selection and annual validation.

Table of Contents

What Are the Levels of PCI Compliance in Detail?

The four PCI DSS merchant levels map transaction volume to a specific validation track. The table below reflects the thresholds and validation requirements most commonly published by card brands, including Mastercard’s Site Data Protection program.

Level Annual Transaction Volume Who Typically Falls Here Primary Validation Method Scan Cadence
1 More than 6 million (any channel) Large national retailers, major e-commerce platforms Annual ROC by a QSA Quarterly ASV scans
2 1 million to 6 million (any channel) Regional chains, mid-size e-commerce merchants Annual SAQ (or ROC at acquirer discretion) Quarterly ASV scans
3 20,000 to 1 million (e-commerce only) Online-only merchants, subscription businesses Annual SAQ Quarterly ASV scans
4 Fewer than 20,000 e-commerce, or up to 1 million other Independent restaurants, boutique retail, micro-merchants Annual SAQ Quarterly ASV scans (commonly required by acquirers)

Comparison diagram of PCI DSS merchant compliance levels

Validation requirements differ meaningfully by level: Level 1 merchants must complete an annual on-site assessment by a Qualified Security Assessor (QSA) that produces a Report on Compliance (ROC). Levels 2 through 4 typically validate using a Self-Assessment Questionnaire (SAQ), though some acquirers require Level 2 merchants to use a QSA as well.

Service providers use different thresholds. A service provider processing more than 300,000 transactions annually is typically classified at the equivalent of Level 1 for service providers. If your business processes payments on behalf of other merchants, confirm your classification directly with your acquirer.

Post-breach elevation is unconditional. A merchant elevated after a breach must complete Level 1 validation requirements regardless of transaction volume, and that classification typically persists for at least one annual assessment cycle.

Pro Tip: Each card brand runs its own compliance program. A merchant can be Level 2 for Visa and Level 3 for Mastercard simultaneously. Always ask your acquiring bank which brand’s thresholds govern your account and whether they apply stricter requirements on top of the card-brand baseline.


Which Validation Documents Does Your Business Actually Need?

Understanding the document types is where many merchants lose time. The PCI DSS validation ecosystem produces four core documents, and each serves a distinct purpose.

SAQ types and when they apply

The Self-Assessment Questionnaire is a structured checklist a merchant completes without a QSA. PCI SSC publishes multiple SAQ variants, and choosing the wrong one is one of the most common compliance mistakes.

  • SAQ A: Card-not-present merchants who have fully outsourced all payment functions to a PCI-validated third party. No direct cardholder data handling.
  • SAQ A-EP: E-commerce merchants who outsource payment processing but whose website could affect transaction security (e.g., scripts that load on the payment page).
  • SAQ C: Merchants with payment application systems connected to the internet but no electronic cardholder data storage.
  • SAQ C-VT: Merchants who process transactions via a virtual terminal on an isolated, dedicated computer.
  • SAQ D: Applies to all merchants who do not qualify for a simpler SAQ type. It covers the full set of PCI DSS requirements and is the most demanding questionnaire.

ROC, AoC, and what a QSA produces

A Report on Compliance (ROC) is the formal output of a Level 1 on-site assessment. A QSA documents every tested control, evidence reviewed, and finding in the ROC template published by PCI SSC. The ROC is not submitted publicly; it goes to your acquiring bank.

The Attestation of Compliance (AoC) is a shorter summary document signed by the merchant and, for Level 1, co-signed by the QSA. The AoC is what most acquirers actually request on file. Submitting an incomplete or unsigned AoC is a frequent compliance gap.

ASV scans and penetration testing

Quarterly external vulnerability scans must be performed by an Approved Scanning Vendor (ASV) listed by PCI SSC. These scans test your external-facing IP addresses and domains for known vulnerabilities. A clean scan result (passing report) is required before you can complete your annual validation.

Technician connecting device for external security scan

Penetration testing is a separate requirement. PCI DSS v4 requires merchants with in-scope networks to conduct penetration testing at least annually and after significant infrastructure changes. This is distinct from an ASV scan and typically requires a qualified internal or external tester.

Pro Tip: The most common documentation mistake is submitting an SAQ for the wrong environment type. If your website loads any third-party payment scripts, SAQ A likely does not apply to you. Review your payment page architecture with your acquirer or a QSA before selecting your SAQ type.


How Do You Calculate Your PCI Compliance Level?

Your level is not self-declared in isolation. It is calculated from transaction data and confirmed with your acquirer. Here is a practical process.

  1. Pull a 12-month transaction report from your payment processor or gateway. Include all card brands: Visa, Mastercard, American Express, Discover, and any other networks you accept.
  2. Separate e-commerce from card-present transactions. Level 3 and Level 4 thresholds for e-commerce are distinct from general transaction counts. If you run both channels, you may need to evaluate each independently.
  3. Sum transactions by card brand if needed. Some card brands apply their thresholds per-brand rather than combined. Visa and Mastercard each publish their own level definitions. Confirm with your acquirer whether they apply combined or per-brand counting.
  4. Check for automatic Level 1 triggers. If your business has experienced a breach, or if a card brand has notified you of elevation, your level is Level 1 regardless of volume.
  5. Contact your acquiring bank. Ask specifically: which card brand’s thresholds govern your account, whether they apply any stricter requirements, and what validation documentation they require on file.
  6. Document your calculation. Keep the transaction report, the date of your acquirer communication, and the resulting level determination in your compliance records.

Common counting pitfalls to avoid:

  • Refunds and chargebacks are not separate transactions for level-counting purposes. Count the original authorization, not the reversal.
  • Subscription billing counts each individual charge as a transaction, not each subscriber.
  • Payment facilitators (PayFacs): If you process through a PayFac rather than a direct merchant account, your transaction count may be aggregated differently. Confirm how your PayFac reports your volume to card brands.
  • Seasonal peaks can push a merchant across a threshold in a single quarter. Use a full 12-month rolling count, not a single month extrapolated.

Because each card brand runs its own program, a merchant can be a different level for Visa versus Mastercard. Always confirm with your acquirer which network’s thresholds apply to your account and whether the bank imposes additional requirements.


What Changed in PCI DSS v4 That Affects Your Validation?

PCI DSS v4.0 replaced v3.2.1 as the active standard, and previously future-dated requirements became mandatory on March 31, 2025. If your last assessment was completed under v3.2.1 assumptions, several controls now require updated evidence.

Key changes that directly affect merchant validation and ongoing compliance:

  • Script management (Requirement 6.4.3 and 11.6.1): Merchants with payment pages must maintain an inventory of all scripts, authorize each one, and implement change-detection mechanisms. This is a significant new burden for e-commerce merchants using SAQ A-EP or SAQ D.
  • Continuous compliance emphasis: v4 shifts the expectation from annual point-in-time assessment to ongoing control operation. Evidence of continuous monitoring is now expected, not just a clean snapshot at assessment time.
  • Stronger authentication requirements: Multi-factor authentication (MFA) is now required for all access into the cardholder data environment (CDE), not just remote access.
  • Customized approach: v4 introduces a “customized approach” option that allows merchants to meet the intent of a control through alternative methods, but this path requires significantly more documentation and is generally suited to organizations with mature security programs.
  • Targeted risk analyses: Several requirements now call for a formal, documented risk analysis to justify the frequency of specific controls (e.g., how often you review logs or test security systems).

The core shift in PCI DSS v4 is this: compliance is no longer something you demonstrate once a year and then set aside. The standard now expects controls to operate continuously, with documented evidence that they are working between assessments. Merchants who treat their SAQ as an annual checkbox exercise will find v4 requirements harder to satisfy at their next validation cycle. The practical response is to build lightweight, repeatable processes for logging, monitoring, and evidence collection into your daily operations rather than scrambling to reconstruct evidence before each assessment.


How to Prepare for Validation and Maintain Compliance Over Time

Preparation for PCI validation is most effective when treated as a project with defined phases rather than a single annual event. The timeline below reflects a realistic 6–12 week readiness cycle for a merchant pursuing SAQ-based validation; a Level 1 ROC engagement typically requires 3–6 months.

Phase Weeks Key Activities
Scope definition 1–2 Map all systems that store, process, or transmit cardholder data; identify CDE boundaries
Gap analysis 2–4 Compare current controls against PCI DSS v4 requirements; document deficiencies
Remediation 4–6 Address gaps: patch systems, implement MFA, update policies, configure logging
ASV scan and remediation 6 Run external scan, remediate any failing findings, obtain passing scan report
Evidence collection and SAQ/ROC completion 8 Compile evidence, complete SAQ or engage QSA for ROC, obtain signed AoC

Scope reduction tactics that actually work

Reducing the scope of your cardholder data environment (CDE) is the fastest path to simpler validation. Three approaches deliver the most consistent results:

Tokenization replaces card data with a non-sensitive token after the initial transaction. If your processor handles tokenization before data reaches your systems, your CDE shrinks significantly. Most modern retail payment solutions and POS platforms support processor-side tokenization.

Hand holding card near payment terminal edge

Point-to-Point Encryption (P2PE): A PCI-validated P2PE solution encrypts card data at the point of swipe or dip before it enters your network. Merchants using a validated P2PE solution can typically complete SAQ P2PE-HW, which is substantially shorter than SAQ D. Note that the solution must appear on PCI SSC’s validated P2PE solutions list to qualify.

Fully outsourced payment pages: Redirecting customers to a hosted payment page operated by a PCI-compliant processor removes your web server from scope for card data. This is the basis for SAQ A eligibility.

Segmentation through firewalls and VLANs can isolate your CDE from the rest of your network, reducing the number of systems in scope. Segmentation must be tested and documented; untested segmentation does not reduce scope for PCI purposes.

Ongoing maintenance tasks

Quarterly ASV scans, monthly patch reviews, annual access-rights reviews, and log monitoring are the recurring tasks that keep controls current between assessments. Evidence retention matters: keep scan reports, patch logs, access review records, and policy documents for at least 12 months so they are available at your next validation cycle.

Pro Tip: For a Level 1 ROC, engage a QSA at least 90 days before your target completion date. QSAs need time to review your environment, request evidence, and complete the ROC template. Engaging one two weeks before your deadline is the single most common reason ROC timelines slip. For SAQ-based merchants, an internal security officer (ISA) or a compliance consultant can guide the process at a fraction of the cost of a full QSA engagement.


The Compliance Misconceptions U.S. Merchants Get Wrong Most Often

The most persistent misunderstanding about PCI DSS levels is that a lower level means fewer security requirements. It does not. Your level controls your validation method, not the controls you must implement. The obligation to implement PCI DSS security controls applies to every entity that stores, transmits, or processes cardholder data, whether you process 500 transactions a year or 500 million.

A few other misconceptions worth correcting directly:

  • “SAQ means lower security.” False. SAQ D covers the full set of PCI DSS requirements. Even SAQ A merchants must ensure their third-party processors are PCI-compliant and that their own website cannot be compromised to redirect payment data.
  • “We outsource payments, so we’re not in scope.” Partial outsourcing does not remove you from scope. If your website loads scripts that interact with the payment page, or if you store any transaction data, you remain in scope for those elements.
  • “Passing our ASV scan means we’re compliant.” A passing scan is one evidence item among many. It does not substitute for completing your SAQ, maintaining your policies, or addressing non-scan controls.
  • “Our processor handles PCI for us.” Processors handle their own compliance. Your merchant account, your systems, and your network remain your responsibility.

The practical priorities for most U.S. small and mid-size businesses are: reduce scope first, get your third-party contracts documented (your processor’s AoC on file), build repeatable logging and monitoring, and collect evidence continuously rather than reconstructing it annually. Scope reduction and evidence collection consistently yield the fastest path to demonstrable compliance, and they reduce cost at every subsequent validation cycle.


Merchantsolutionscorp Helps You Reduce PCI Scope from Day One

Fewer systems in your cardholder data environment means a shorter SAQ, lower validation costs, and less remediation work each year. Merchantsolutionscorp configures secure payment processing solutions with tokenization and P2PE-capable terminals that keep card data out of your network from the first transaction. POS hardware from brands like Clover, PAX, and Dejavoo arrives preconfigured for your environment, reducing the number of in-scope systems you need to document and defend.

Merchantsolutionscorp’s security compliance resources and onboarding support help you understand your CDE boundaries, select the right SAQ type, and maintain the evidence your acquirer needs on file. Whether you are a restaurant owner completing your first SAQ or a retail compliance officer preparing for a Level 2 assessment, the right payment infrastructure makes the process faster and the ongoing maintenance lighter. Contact Merchantsolutionscorp to review your current setup and identify where scope reduction is possible before your next validation cycle.


Sources

The following primary sources are the authoritative references for PCI DSS thresholds, validation requirements, and official forms.

Note: Enforcement and reporting requirements vary by acquiring bank and card brand. Always confirm your specific validation obligations directly with your acquirer in addition to consulting the sources above.


This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

FAQ

How many PCI compliance levels are there?

There are four PCI DSS merchant compliance levels (Level 1 through Level 4), each defined by annual card transaction volume and enforced by card brands through your acquiring bank.

What is Level 3 PCI compliance?

Level 3 applies to merchants processing between 20,000 and 1 million e-commerce transactions annually. These merchants typically validate using an SAQ and conduct quarterly ASV scans.

What are the main PCI DSS v4 requirements merchants need to know?

PCI DSS v4 made previously future-dated controls mandatory as of March 31, 2025, including script management for payment pages, continuous monitoring evidence, and multi-factor authentication for all CDE access.

Does a lower PCI level mean fewer security controls are required?

No. Your PCI level determines your validation method (SAQ vs. ROC), not the security controls you must implement. The full PCI DSS requirements apply to every merchant who handles cardholder data.

When does a merchant automatically become Level 1?

A merchant is elevated to Level 1 after a confirmed data breach, or when a card brand or acquiring bank explicitly requires it, regardless of transaction volume.

levels of pci compliance

Share this article: