Someone on your team just asked, out of nowhere, what PCI compliance level you're at, and you realized nobody actually knows. You know you accept cards. You don't know which of the four tiers that puts you in, or what it actually requires.
PCI DSS compliance levels are the four tiers, Level 1 through Level 4, that card brands use to classify merchants by annual transaction volume. Your level determines how much validation you owe each year: a simple self-assessment questionnaire at the low end, a full annual on-site audit by a Qualified Security Assessor at the high end.
Most guides stop at the transaction thresholds and a one-line validation summary. This one goes further: what each level actually costs, how the thresholds genuinely differ by card brand, how service provider levels work separately from merchant levels, and what to do when your volume is sitting right at a boundary.
Here's what's ahead:
- What PCI DSS compliance levels are, and who actually sets them
- How your merchant level gets determined, and when it gets reassessed
- Levels 1 through 4, with a real requirements-at-a-glance table
- PCI DSS levels for service providers, a separate and often-skipped scale
- Choosing the right SAQ type for your level
- What each level actually costs, named honestly
- How the thresholds differ by card brand
- Common mistakes that cost more than getting the level right the first time
What PCI DSS Compliance Levels Actually Are
PCI DSS compliance levels are the classification system card brands use to determine how rigorously a merchant or service provider has to validate its compliance with the Payment Card Industry Data Security Standard, based on how many card transactions it processes annually.
This article reflects PCI DSS 4.0.1, the current version of the standard since June 2024. PCI DSS 4.0 was retired December 31, 2024, and 3.2.1 before that. None of the major competitor guides on this exact topic state the 4.0.1 version explicitly, worth knowing if you're cross-checking guidance elsewhere.
Who Sets PCI DSS Compliance Levels
Here's a distinction most explanations blur: the PCI Security Standards Council writes the PCI DSS standard itself, but it doesn't set the compliance levels. The individual card brands, Visa, Mastercard, American Express, Discover, and JCB, each define their own merchant levels independently. They align closely on the broad strokes, but the exact thresholds genuinely differ, covered in full further down.
Merchant Levels vs. Service Provider Levels: Not the Same Scale
Merchants and service providers are classified on two separate scales. A merchant sells goods or services and accepts cards directly. A service provider, a payment gateway, a hosting company, a SaaS platform processing payments on another business's behalf, is classified on its own two-tier scale, not the four-tier merchant scale. Mixing the two up is a common early mistake, covered in full in its own section below.
How PCI DSS Compliance Levels Get Determined for Merchants
Here's how to determine your PCI compliance level in practice, not just in theory. It starts with one number: your annual card transaction volume, counted across every channel you process through, card-present, card-not-present, and e-commerce combined.
Each card brand you accept sets its own PCI DSS merchant levels thresholds against that volume. You don't get to pick the friendliest one. You're classified at the highest level triggered by any card brand you accept, even if that brand represents a small slice of your total volume.
- Historical volume is what most merchants actually get assessed against: your transaction count from the prior 12 months.
- Projected volume matters when you don't have 12 months of history yet, a new business, a business entering card payments for the first time, or one anticipating a large volume jump from a new channel or a major customer.
Who actually assigns your level in practice is usually your acquiring bank or payment processor, not something you self-declare in isolation. They monitor your processing volume and will notify you when your level changes, but that doesn't mean you can wait for the notification.
Do PCI compliance levels still apply if you use a payment processor? Yes. A processor can reduce how much of the cardholder data environment touches your own systems, but it doesn't remove your validation obligation, it just changes what's actually in scope.
Knowing how to determine your PCI compliance level once isn't the end of it. It's worth revisiting anytime your business changes shape, not just at renewal.
When PCI DSS Compliance Levels Get Reassessed
Three things reliably trigger a reassessment: crossing a volume threshold (in either direction), adding a new sales channel that changes your transaction mix, and a security incident involving cardholder data. That last one is worth calling out specifically: a breach can push a merchant to Level 1 validation requirements regardless of actual transaction volume, a detail most competitor guides on this topic leave out entirely.
PCI Compliance Level Requirements: The Four Levels Explained
These PCI compliance level requirements cover PCI compliance level 1, PCI compliance level 2, PCI compliance level 3, and PCI compliance level 4 side by side, before the detail underneath each one.
| Level | Transaction Threshold (Visa/Mastercard/Discover) | Validation Required | Who Validates |
|---|---|---|---|
| Level 1 | 6M+ transactions annually | Annual Report on Compliance (ROC), quarterly ASV scans, annual penetration test | Qualified Security Assessor (QSA) or Internal Security Assessor (ISA) |
| Level 2 | 1M-6M transactions annually | Annual SAQ, quarterly ASV scans; some acquirers require a ROC | Self-assessed, or QSA/ISA if a ROC is required |
| Level 3 | 20K-1M e-commerce transactions annually | Annual SAQ, quarterly ASV scans | Self-assessed |
| Level 4 | Under 20K e-commerce transactions annually | Annual SAQ, quarterly ASV scans (requirements set by acquirer) | Self-assessed |
PCI Compliance Level 1: The Highest-Volume Tier
Level 1 is the strictest tier, and it isn't only about volume. Any merchant that Mastercard or another brand determines poses elevated risk can be placed at Level 1 regardless of transaction count, and any merchant that's had a card-data breach is typically escalated here too.
Level 1 requires an annual on-site assessment resulting in a signed Report on Compliance (ROC), completed by a QSA or a qualified Internal Security Assessor, plus quarterly vulnerability scans by an Approved Scanning Vendor and an annual penetration test.
PCI Compliance Level 2: High Volume Without the Full Audit
Level 2 merchants complete an annual Self-Assessment Questionnaire rather than a full QSA-led audit, plus quarterly ASV scans. Some acquiring banks still require a formal ROC at this level, so confirm directly with yours rather than assuming the lighter path applies by default.
PCI Compliance Level 3: The Mid-Market E-Commerce Tier
Level 3 applies specifically to e-commerce transaction volume, not total volume across all channels the way Levels 1 and 2 are counted. A business with significant in-person sales and modest e-commerce volume may land here even if its total processing volume looks larger. Requirements are the same shape as Level 2: SAQ plus quarterly scans.
PCI Compliance Level 4: The Smallest-Merchant Tier
Level 4 is the baseline every new card-accepting business starts at. Requirements are typically the lightest and often guided directly by the acquiring bank through a simplified SAQ process, though the exact SAQ type still depends on how payments are actually processed, covered below.
PCI DSS Levels for Service Providers
This is the section most competitor guides shorten to a paragraph or skip outright. Service providers, businesses that store, process, or transmit cardholder data on behalf of another company, are classified on their own two-tier scale, separate from the four-tier merchant scale above.
| Service Provider Level | Transaction Threshold | Validation Required |
|---|---|---|
| Level 1 | 300,000+ transactions annually | Annual ROC by a QSA, quarterly ASV scans, annual penetration test |
| Level 2 | Under 300,000 transactions annually | Annual SAQ D for service providers, quarterly ASV scans |
Who actually counts as a service provider here: payment gateways, hosting providers with access to the cardholder data environment, and SaaS platforms that process payments on behalf of their own merchant customers all typically qualify. A vendor that only ever sees tokenized data, with no access to raw cardholder data, usually doesn't carry the same obligation, though that determination depends on the specific data flow, not just the vendor's category.
PCI DSS SAQ Types: Choosing the Right One for Your Level
Your level determines whether you need a full audit or a Self-Assessment Questionnaire, but it doesn't tell you which SAQ. That depends on how payments actually flow through your systems.
| SAQ Type | Who It Fits |
|---|---|
| SAQ A | Fully outsourced card-not-present payments; your systems never touch cardholder data |
| SAQ A-EP | Partially outsourced e-commerce; your website controls how payment data is collected, even if it doesn't store it |
| SAQ B | Standalone dial-out terminals or imprint machines only, no electronic cardholder data storage |
| SAQ B-IP | Standalone, PTS-approved payment terminals with an IP connection, no electronic storage |
| SAQ C | Payment application systems connected to the internet, no electronic cardholder data storage |
| SAQ C-VT | Web-based virtual terminals only, manually entered, no electronic storage |
| SAQ P2PE | Validated point-to-point encryption hardware terminals only |
| SAQ D | Every other scenario, including anyone storing, processing, or transmitting cardholder data directly |
A common and costly mistake is picking a shorter, simpler SAQ than the business actually qualifies for, usually because the business hasn't precisely mapped where cardholder data actually flows. SAQ A is the shortest questionnaire in the set, and it only applies when your systems genuinely never touch card data at all, not just when a payment processor is involved somewhere in the chain.
Understanding the different PCI DSS SAQ types before your first assessment saves a genuine amount of rework later, since switching questionnaire types mid-cycle usually means restarting evidence collection under the correct one.
What PCI DSS Compliance Levels Actually Cost
No competitor guide on this topic publishes a real cost breakdown across all four levels, and this one won't invent numbers to fill that gap either. Here's what's actually known and where the honest gap is.
Levels 2 through 4 don't have an equivalent published breakdown anywhere reviewed for this article. The honest answer is that costs at those levels scale down with the validation burden itself: no QSA assessment fee, since it's self-assessed, but still real internal time for SAQ completion and the same quarterly ASV scan cost most levels share. Treat any specific Level 2-4 figure you're quoted as the number to actually compare against, not an industry average, since one doesn't reliably exist.
Card Brand Differences in PCI DSS Compliance Levels
Every competitor guide researched for this article gestures at card-brand-specific thresholds without stating them. Here's the actual breakdown, verified independently rather than repeated as a vague "it varies" line.
| Card Brand | Level 1 Threshold |
|---|---|
| Visa | 6 million or more transactions annually |
| Mastercard | 6 million or more combined Mastercard and Maestro transactions annually |
| Discover | 6 million or more transactions annually (no separate Level 4 designation) |
| American Express | 2.5 million or more transactions annually |
| JCB | 1 million or more transactions annually (only recognizes two levels, 1 and 2) |
American Express and JCB matter more than their transaction share might suggest. Because you're classified at the highest level triggered by any brand you accept, a merchant with modest overall volume but 1 million-plus JCB transactions is a JCB Level 1 merchant, regardless of how small that slice looks next to their Visa and Mastercard volume.
Discover also skips a Level 4 designation entirely, so a merchant with low Discover volume is typically evaluated under whichever other brand's thresholds actually apply.
Common Mistakes With PCI DSS Compliance Levels
- Using last year's transaction volume when this year's growth has already crossed a threshold. Assess against where you're actually headed once the trend is clear, not just historical data that's already stale.
- Picking a shorter SAQ than the business qualifies for. SAQ A only applies when systems never touch cardholder data at all; a payment processor being involved somewhere doesn't automatically qualify a business for it.
- Assuming a payment processor removes all validation burden. It changes what's in scope, not whether validation is required at all.
- Not reassessing after a security incident. A breach involving cardholder data can trigger Level 1 requirements regardless of transaction volume, a detail most competitor guides skip entirely.
- Confusing merchant levels with service provider levels. They're two separate scales; a business processing payments on behalf of other merchants is evaluated as a service provider for that activity, not folded into its own merchant-level count.
- Not confirming what the acquiring bank actually expects at Level 2. Some acquirers require a full ROC at Level 2 even though a SAQ is technically permitted; assuming the lighter path applies without checking is a common surprise at renewal.
- Assuming your level is the same across every card brand you accept. American Express and JCB use meaningfully lower thresholds than Visa, Mastercard, and Discover, and the highest level triggered by any brand governs.
How ComplyJet Supports PCI DSS Compliance Levels
Unlike some of the frameworks covered elsewhere on this blog, PCI DSS is a framework ComplyJet directly supports, at every merchant and service provider level.
We work with growth-stage companies to map their actual cardholder data flow, determine the right level and SAQ type, and build the evidence trail an acquiring bank or QSA will expect, whether that's a Level 4 self-assessment or the deeper documentation a Level 1 ROC requires.
FAQs
Who decides my PCI compliance level?
Each card brand you accept sets its own transaction-volume thresholds and decides your level against them. Your acquiring bank or payment processor typically monitors your volume and communicates your level, but you're responsible for validating at the correct one whether or not you've been formally notified.
Do PCI compliance levels still apply if I use a payment processor?
Yes. A payment processor can significantly reduce how much of your own environment touches raw cardholder data, which changes what's actually in scope for your assessment, but it doesn't remove the requirement to validate at your correct level.
Can a security incident change my PCI compliance level?
Yes. A breach involving cardholder data can push a merchant to Level 1 validation requirements regardless of transaction volume, since card brands treat a demonstrated incident as evidence of elevated risk.
What happens if I assess at the wrong PCI compliance level?
Assessing below your actual level typically surfaces at renewal or during a card-brand audit, and can mean redoing the assessment at the correct, more demanding level under time pressure. Assessing above your actual level isn't a violation, just unnecessary cost and effort.
Should I use historical or projected transaction volume for my PCI compliance level?
Historical volume, usually the prior 12 months, is the standard basis. Projected volume matters when you don't have a full year of history yet or when a known upcoming change, a new channel or a major new customer, will clearly push you past a threshold before your next scheduled review.
What's the difference between PCI merchant levels and service provider levels?
PCI DSS merchant levels run on a four-tier scale (1-4) based on total transaction volume across all channels. Service provider levels run on a separate two-tier scale (1-2) based on a 300,000-transaction threshold. A business can be classified on both scales at once for different parts of its operations.
Can I voluntarily assess at a higher PCI compliance level?
Yes, and some businesses do, usually to satisfy an enterprise customer's security requirements ahead of actually crossing the threshold that would require it. There's no rule against validating more rigorously than your transaction volume strictly requires.
Related Reading
- PCI DSS Compliance, the pillar guide this article extends
- PCI DSS Compliance Requirements, the 12 requirements explained in depth
- PCI DSS Compliance Checklist, the actionable, step-by-step companion checklist





