PCI Merchant Levels: Requirements for Each Level
Learn the four PCI compliance merchant levels, transaction limits, SAQ and scan rules, QSA reports, and ongoing PCI DSS v4.0 duties.
How PCI Compliance Levels Work
PCI compliance for merchants has four levels. The level usually depends on yearly card payment volume.
Each level brings different checks and records. Card brands and acquiring banks may also set stricter rules.
The four levels cover both card-present and online payments. Some programs count transactions by card brand, while others use total volume.
Ask your acquirer how it counts payments before choosing a validation path. That step can prevent costly rework.
The PCI Security Standards Council's PCI DSS overview explains the wider standard. PCI DSS means Payment Card Industry Data Security Standard.
- Level 1: More than 6 million card transactions each year
- Level 2: 1 million to 6 million transactions each year
- Level 3: 20,000 to 1 million online transactions each year
- Level 4: Fewer than 20,000 online transactions each year
These bands are not the whole risk picture. A data breach can lead to a higher level or extra checks.
Merchant Criteria for Levels 1 Through 4
Level 1 covers merchants with over 6 million yearly card transactions. It also covers some merchants after a major data breach.
Large payment volumes create more chances for a security failure. Banks therefore expect a formal review by an outside expert.
Level 2 covers merchants with 1 million to 6 million yearly transactions. This range often includes growing retailers and large service firms.
Level 3 covers 20,000 to 1 million e-commerce transactions each year. It applies to online sellers with a smaller total card volume.
Level 4 covers merchants with fewer than 20,000 e-commerce transactions each year. It can also cover merchants below the Level 3 range.
Not every bank applies these bands in the same way. Your bank may place you in a higher PCI merchant level.
| Merchant level | Typical yearly volume | Common example |
|---|---|---|
| Level 1 | Over 6 million transactions | Large retail network |
| Level 2 | 1 million to 6 million | National online seller |
| Level 3 | 20,000 to 1 million online | Busy online shop |
| Level 4 | Under 20,000 online | Small web store |
Validation Rules for Each PCI Merchant Level
Validation proves that your controls meet PCI DSS requirements. The exact forms depend on your bank, card brands, and payment setup.
Level 1 merchants need an annual Report on Compliance. A Qualified Security Assessor, or QSA, completes this review.
A QSA checks systems, staff rules, network controls, and payment flows. The assessor then records findings in the report.
Level 1 merchants may also need quarterly network scans. An Approved Scanning Vendor, or ASV, runs these scans.
Level 2 merchants usually complete a Self-Assessment Questionnaire each year. They also need quarterly scans from an approved scanning vendor.
The right questionnaire depends on how your business handles card data. A hosted checkout may need a different form from a store with its own payment system.
Level 3 merchants also use an SAQ and quarterly ASV scans. The SAQ asks about access rules, patching, passwords, backups, and other controls.
Level 4 merchants generally complete an SAQ. They do not usually need a full Report on Compliance.
Still, Level 4 does not mean low risk. A small shop must protect card data and fix weak controls.
- Confirm your level with the acquiring bank.
- Pick the SAQ that matches your payment flow.
- Book quarterly scans when your level requires them.
- Keep scan results, policies, and fixes in one secure record.
- Submit an Attestation of Compliance when your bank requests it.
What Changes Under Ongoing PCI Compliance
PCI merchant compliance is no longer just an annual paperwork task. Security teams must keep key controls active all year.
That means checking access, fixing flaws, and watching payment systems often. A yearly review cannot catch every new threat.
PCI DSS v4.0 puts more weight on clear tests and ongoing checks. It also gives some firms more choice in how they meet goals.
The standard places stronger focus on multi-factor authentication. This adds another proof step after a user enters a password.
Strong password policies also matter more. Businesses should set length rules, block weak passwords, and remove old accounts.
Keep a simple record of each check. Note the date, owner, result, and fix date.
A practical year-round plan can include these tasks:
- Review user access each quarter.
- Remove access after staff leave or change roles.
- Patch payment devices and related systems on a set schedule.
- Run required ASV scans and track failed results.
- Test backups and incident response steps.
- Train staff to spot fake payment and sign-in requests.
These steps support PCI compliance merchant work between formal reviews. They also make the next SAQ or audit far easier.
Why PCI Compliance Matters to Merchants
PCI compliance helps limit the risk of stolen payment card data. It also gives staff a clear set of security tasks.
A breach can bring bank reviews, card replacement costs, fines, and lost trust. Recovery can take much longer than prevention.
Good controls also reduce everyday mistakes. Access limits can stop one stolen account from exposing the whole payment system.
Compliance does not promise perfect safety. It gives merchants a tested base for better payment security.
Start by mapping every payment path. Include stores, websites, phone orders, refunds, and third-party tools.
Then find where card data enters, moves, and leaves your business. Reduce those points when a trusted payment provider can handle the data.
Use this short review before your next PCI compliance check:
- Count yearly transactions by payment channel.
- Confirm your PCI merchant level with your acquirer.
- Choose the correct SAQ or hire a QSA.
- Schedule scans and fix failed findings.
- Store proof of each control and review.
- Repeat key checks throughout the year.
A Practical Path to Merchant PCI Compliance
The best path starts with scope. Scope means every system, device, person, and provider tied to card payments.
Many small merchants reduce scope through hosted payment pages or point-to-point tools. These choices do not remove the merchant's duties.
You still need safe passwords, limited access, staff training, and vendor checks. Your bank may also ask for yearly proof.
Keep your records ready before the deadline. Last-minute work often leads to missed scans or incomplete answers.
Review your payment setup after major changes. New stores, new checkout tools, and new vendors can change your PCI requirements.
When unsure, ask your acquirer which form and deadline apply. A QSA can help with complex systems or Level 1 merchant PCI compliance.
In short, merchant levels PCI rules set the check you must complete. Ongoing security work keeps those checks meaningful.
Frequently asked questions
- What are the four PCI compliance merchant levels?
- PCI compliance has four merchant levels. The level usually depends on yearly card transaction volume and the rules set by your acquirer.
- What does Level 1 merchant PCI compliance require?
- Level 1 merchants process over 6 million yearly transactions. They need an annual Report on Compliance from a Qualified Security Assessor.
- What are the PCI requirements for a Level 2 merchant?
- Level 2 merchants process 1 million to 6 million yearly transactions. They usually complete an SAQ and quarterly scans from an Approved Scanning Vendor.
- What does a Level 3 PCI compliance merchant need to do?
- Level 3 merchants process 20,000 to 1 million online transactions. They usually need an SAQ and quarterly ASV scans.
- Does a Level 4 merchant need a Report on Compliance?
- Level 4 merchants generally complete an SAQ. They usually do not need a full Report on Compliance, but their bank may ask for more proof.
- What changed for merchant PCI compliance under PCI DSS v4.0?
- PCI DSS v4.0 places more focus on ongoing checks, multi-factor authentication, and strong password rules. Merchants should review key controls throughout the year.
Related reading
How Cryptocurrency Payments Work for Modern Businesses
A clear guide to accepting crypto payments, managing risk, and meeting tax rules.
Mastercard vs Maestro: What Cardholders Need to Know
See how Mastercard and Maestro differ, and why Maestro cards are being replaced.
How PayID Works: A Guide to Fast Australian Bank Payments
Learn how PayID links simple identifiers to fast, safer bank payments.