PCI DSS Compliance Levels 1-4: Requirements and Costs Explained

Shubham S.
September 3, 2026
17
mins

Someone on your team just asked, out of nowhere, what PCI compliance level you're at, and you realized nobody actually knows. You know you accept cards. You don't know which of the four tiers that puts you in, or what it actually requires.

PCI DSS compliance levels are the four tiers, Level 1 through Level 4, that card brands use to classify merchants by annual transaction volume. Your level determines how much validation you owe each year: a simple self-assessment questionnaire at the low end, a full annual on-site audit by a Qualified Security Assessor at the high end.

Quick answer Your PCI DSS compliance level is set by your annual card transaction volume, determined separately by each card brand you accept. Level 1 starts at 6 million transactions a year for Visa, Mastercard, and Discover, but the threshold is lower for American Express (2.5 million) and lower still for JCB (1 million). You're classified at the highest level triggered by any brand you accept, not an average across them.

Most guides stop at the transaction thresholds and a one-line validation summary. This one goes further: what each level actually costs, how the thresholds genuinely differ by card brand, how service provider levels work separately from merchant levels, and what to do when your volume is sitting right at a boundary.

Here's what's ahead:

  • What PCI DSS compliance levels are, and who actually sets them
  • How your merchant level gets determined, and when it gets reassessed
  • Levels 1 through 4, with a real requirements-at-a-glance table
  • PCI DSS levels for service providers, a separate and often-skipped scale
  • Choosing the right SAQ type for your level
  • What each level actually costs, named honestly
  • How the thresholds differ by card brand
  • Common mistakes that cost more than getting the level right the first time

What PCI DSS Compliance Levels Actually Are

PCI DSS compliance levels are the classification system card brands use to determine how rigorously a merchant or service provider has to validate its compliance with the Payment Card Industry Data Security Standard, based on how many card transactions it processes annually.

This article reflects PCI DSS 4.0.1, the current version of the standard since June 2024. PCI DSS 4.0 was retired December 31, 2024, and 3.2.1 before that. None of the major competitor guides on this exact topic state the 4.0.1 version explicitly, worth knowing if you're cross-checking guidance elsewhere.

Who Sets PCI DSS Compliance Levels

Here's a distinction most explanations blur: the PCI Security Standards Council writes the PCI DSS standard itself, but it doesn't set the compliance levels. The individual card brands, Visa, Mastercard, American Express, Discover, and JCB, each define their own merchant levels independently. They align closely on the broad strokes, but the exact thresholds genuinely differ, covered in full further down.

Note The PCI SSC sets the security standard everyone validates against. The card brands set the levels that determine how much validation you owe. Two different organizations, two different jobs.

Merchant Levels vs. Service Provider Levels: Not the Same Scale

Merchants and service providers are classified on two separate scales. A merchant sells goods or services and accepts cards directly. A service provider, a payment gateway, a hosting company, a SaaS platform processing payments on another business's behalf, is classified on its own two-tier scale, not the four-tier merchant scale. Mixing the two up is a common early mistake, covered in full in its own section below.

How PCI DSS Compliance Levels Get Determined for Merchants

Here's how to determine your PCI compliance level in practice, not just in theory. It starts with one number: your annual card transaction volume, counted across every channel you process through, card-present, card-not-present, and e-commerce combined.

Each card brand you accept sets its own PCI DSS merchant levels thresholds against that volume. You don't get to pick the friendliest one. You're classified at the highest level triggered by any card brand you accept, even if that brand represents a small slice of your total volume.

Three-step flow showing how a PCI compliance level gets determined: count annual transaction volume, check each card brand's threshold, then get classified at the highest level triggered by any brand accepted.
  • Historical volume is what most merchants actually get assessed against: your transaction count from the prior 12 months.
  • Projected volume matters when you don't have 12 months of history yet, a new business, a business entering card payments for the first time, or one anticipating a large volume jump from a new channel or a major customer.
Watch out Using last year's volume when this year's growth has already pushed you into a higher tier is one of the more common ways merchants get caught under-validated at renewal time. If you can already see the threshold coming, assess against where you're headed, not just where you've been.

Who actually assigns your level in practice is usually your acquiring bank or payment processor, not something you self-declare in isolation. They monitor your processing volume and will notify you when your level changes, but that doesn't mean you can wait for the notification.

Do PCI compliance levels still apply if you use a payment processor? Yes. A processor can reduce how much of the cardholder data environment touches your own systems, but it doesn't remove your validation obligation, it just changes what's actually in scope.

Knowing how to determine your PCI compliance level once isn't the end of it. It's worth revisiting anytime your business changes shape, not just at renewal.

When PCI DSS Compliance Levels Get Reassessed

Three things reliably trigger a reassessment: crossing a volume threshold (in either direction), adding a new sales channel that changes your transaction mix, and a security incident involving cardholder data. That last one is worth calling out specifically: a breach can push a merchant to Level 1 validation requirements regardless of actual transaction volume, a detail most competitor guides on this topic leave out entirely.

PCI Compliance Level Requirements: The Four Levels Explained

These PCI compliance level requirements cover PCI compliance level 1, PCI compliance level 2, PCI compliance level 3, and PCI compliance level 4 side by side, before the detail underneath each one.

Level Transaction Threshold (Visa/Mastercard/Discover) Validation Required Who Validates
Level 1 6M+ transactions annually Annual Report on Compliance (ROC), quarterly ASV scans, annual penetration test Qualified Security Assessor (QSA) or Internal Security Assessor (ISA)
Level 2 1M-6M transactions annually Annual SAQ, quarterly ASV scans; some acquirers require a ROC Self-assessed, or QSA/ISA if a ROC is required
Level 3 20K-1M e-commerce transactions annually Annual SAQ, quarterly ASV scans Self-assessed
Level 4 Under 20K e-commerce transactions annually Annual SAQ, quarterly ASV scans (requirements set by acquirer) Self-assessed

PCI Compliance Level 1: The Highest-Volume Tier

Level 1 is the strictest tier, and it isn't only about volume. Any merchant that Mastercard or another brand determines poses elevated risk can be placed at Level 1 regardless of transaction count, and any merchant that's had a card-data breach is typically escalated here too.

Level 1 requires an annual on-site assessment resulting in a signed Report on Compliance (ROC), completed by a QSA or a qualified Internal Security Assessor, plus quarterly vulnerability scans by an Approved Scanning Vendor and an annual penetration test.

PCI Compliance Level 2: High Volume Without the Full Audit

Level 2 merchants complete an annual Self-Assessment Questionnaire rather than a full QSA-led audit, plus quarterly ASV scans. Some acquiring banks still require a formal ROC at this level, so confirm directly with yours rather than assuming the lighter path applies by default.

The four PCI compliance levels at a glance: Level 1 at 6 million or more transactions a year requiring an annual QSA audit and ROC, Level 2 at 1 to 6 million requiring an annual SAQ and scans, Level 3 at 20,000 to 1 million requiring an annual SAQ and scans, and Level 4 under 20,000 requiring a simplified SAQ.

PCI Compliance Level 3: The Mid-Market E-Commerce Tier

Level 3 applies specifically to e-commerce transaction volume, not total volume across all channels the way Levels 1 and 2 are counted. A business with significant in-person sales and modest e-commerce volume may land here even if its total processing volume looks larger. Requirements are the same shape as Level 2: SAQ plus quarterly scans.

PCI Compliance Level 4: The Smallest-Merchant Tier

Level 4 is the baseline every new card-accepting business starts at. Requirements are typically the lightest and often guided directly by the acquiring bank through a simplified SAQ process, though the exact SAQ type still depends on how payments are actually processed, covered below.

ComplyJet
PCI DSS support across every merchant level
ComplyJet supports PCI DSS compliance with flat per-company pricing across 25+ frameworks, whichever level you land at.
See the PCI DSS platform

PCI DSS Levels for Service Providers

This is the section most competitor guides shorten to a paragraph or skip outright. Service providers, businesses that store, process, or transmit cardholder data on behalf of another company, are classified on their own two-tier scale, separate from the four-tier merchant scale above.

Service Provider Level Transaction Threshold Validation Required
Level 1 300,000+ transactions annually Annual ROC by a QSA, quarterly ASV scans, annual penetration test
Level 2 Under 300,000 transactions annually Annual SAQ D for service providers, quarterly ASV scans

Who actually counts as a service provider here: payment gateways, hosting providers with access to the cardholder data environment, and SaaS platforms that process payments on behalf of their own merchant customers all typically qualify. A vendor that only ever sees tokenized data, with no access to raw cardholder data, usually doesn't carry the same obligation, though that determination depends on the specific data flow, not just the vendor's category.

Note A SaaS company processing payments for its own customers is a service provider, not a merchant, for that part of its business, even if it's also a merchant for its own subscription billing. It's possible to be both at once, on two different scales.

PCI DSS SAQ Types: Choosing the Right One for Your Level

Your level determines whether you need a full audit or a Self-Assessment Questionnaire, but it doesn't tell you which SAQ. That depends on how payments actually flow through your systems.

SAQ Type Who It Fits
SAQ A Fully outsourced card-not-present payments; your systems never touch cardholder data
SAQ A-EP Partially outsourced e-commerce; your website controls how payment data is collected, even if it doesn't store it
SAQ B Standalone dial-out terminals or imprint machines only, no electronic cardholder data storage
SAQ B-IP Standalone, PTS-approved payment terminals with an IP connection, no electronic storage
SAQ C Payment application systems connected to the internet, no electronic cardholder data storage
SAQ C-VT Web-based virtual terminals only, manually entered, no electronic storage
SAQ P2PE Validated point-to-point encryption hardware terminals only
SAQ D Every other scenario, including anyone storing, processing, or transmitting cardholder data directly

A common and costly mistake is picking a shorter, simpler SAQ than the business actually qualifies for, usually because the business hasn't precisely mapped where cardholder data actually flows. SAQ A is the shortest questionnaire in the set, and it only applies when your systems genuinely never touch card data at all, not just when a payment processor is involved somewhere in the chain.

Understanding the different PCI DSS SAQ types before your first assessment saves a genuine amount of rework later, since switching questionnaire types mid-cycle usually means restarting evidence collection under the correct one.

What PCI DSS Compliance Levels Actually Cost

No competitor guide on this topic publishes a real cost breakdown across all four levels, and this one won't invent numbers to fill that gap either. Here's what's actually known and where the honest gap is.

Quick take Level 1's costs are the most documented, broken into three components: quarterly ASV scans ($500-$5,000/year), an annual penetration test ($5,000-$20,000/year), and the QSA assessment itself ($20,000-$75,000/year), per Basis Theory's published estimates for an in-house cardholder data environment. That's roughly $25,500-$100,000 a year, and it moves with how complex the environment actually is.

Levels 2 through 4 don't have an equivalent published breakdown anywhere reviewed for this article. The honest answer is that costs at those levels scale down with the validation burden itself: no QSA assessment fee, since it's self-assessed, but still real internal time for SAQ completion and the same quarterly ASV scan cost most levels share. Treat any specific Level 2-4 figure you're quoted as the number to actually compare against, not an industry average, since one doesn't reliably exist.

Card Brand Differences in PCI DSS Compliance Levels

Every competitor guide researched for this article gestures at card-brand-specific thresholds without stating them. Here's the actual breakdown, verified independently rather than repeated as a vague "it varies" line.

Card Brand Level 1 Threshold
Visa 6 million or more transactions annually
Mastercard 6 million or more combined Mastercard and Maestro transactions annually
Discover 6 million or more transactions annually (no separate Level 4 designation)
American Express 2.5 million or more transactions annually
JCB 1 million or more transactions annually (only recognizes two levels, 1 and 2)

American Express and JCB matter more than their transaction share might suggest. Because you're classified at the highest level triggered by any brand you accept, a merchant with modest overall volume but 1 million-plus JCB transactions is a JCB Level 1 merchant, regardless of how small that slice looks next to their Visa and Mastercard volume.

Discover also skips a Level 4 designation entirely, so a merchant with low Discover volume is typically evaluated under whichever other brand's thresholds actually apply.

Common Mistakes With PCI DSS Compliance Levels

  • Using last year's transaction volume when this year's growth has already crossed a threshold. Assess against where you're actually headed once the trend is clear, not just historical data that's already stale.
  • Picking a shorter SAQ than the business qualifies for. SAQ A only applies when systems never touch cardholder data at all; a payment processor being involved somewhere doesn't automatically qualify a business for it.
  • Assuming a payment processor removes all validation burden. It changes what's in scope, not whether validation is required at all.
  • Not reassessing after a security incident. A breach involving cardholder data can trigger Level 1 requirements regardless of transaction volume, a detail most competitor guides skip entirely.
  • Confusing merchant levels with service provider levels. They're two separate scales; a business processing payments on behalf of other merchants is evaluated as a service provider for that activity, not folded into its own merchant-level count.
  • Not confirming what the acquiring bank actually expects at Level 2. Some acquirers require a full ROC at Level 2 even though a SAQ is technically permitted; assuming the lighter path applies without checking is a common surprise at renewal.
  • Assuming your level is the same across every card brand you accept. American Express and JCB use meaningfully lower thresholds than Visa, Mastercard, and Discover, and the highest level triggered by any brand governs.
Six common PCI compliance level mistakes in a grid: using stale volume data, picking the wrong SAQ, assuming a payment processor removes all validation burden, skipping reassessment after a security incident, confusing merchant levels with service provider levels, and not confirming what the acquiring bank expects.

How ComplyJet Supports PCI DSS Compliance Levels

Unlike some of the frameworks covered elsewhere on this blog, PCI DSS is a framework ComplyJet directly supports, at every merchant and service provider level.

We work with growth-stage companies to map their actual cardholder data flow, determine the right level and SAQ type, and build the evidence trail an acquiring bank or QSA will expect, whether that's a Level 4 self-assessment or the deeper documentation a Level 1 ROC requires.

ComplyJet
Not sure which PCI DSS level applies to you?
ComplyJet's team helps you confirm your actual level, pick the right SAQ, and build the evidence an assessor or acquirer expects, with flat per-company pricing across 25+ frameworks.
See how it works

FAQs

Who decides my PCI compliance level?

Each card brand you accept sets its own transaction-volume thresholds and decides your level against them. Your acquiring bank or payment processor typically monitors your volume and communicates your level, but you're responsible for validating at the correct one whether or not you've been formally notified.

Do PCI compliance levels still apply if I use a payment processor?

Yes. A payment processor can significantly reduce how much of your own environment touches raw cardholder data, which changes what's actually in scope for your assessment, but it doesn't remove the requirement to validate at your correct level.

Can a security incident change my PCI compliance level?

Yes. A breach involving cardholder data can push a merchant to Level 1 validation requirements regardless of transaction volume, since card brands treat a demonstrated incident as evidence of elevated risk.

What happens if I assess at the wrong PCI compliance level?

Assessing below your actual level typically surfaces at renewal or during a card-brand audit, and can mean redoing the assessment at the correct, more demanding level under time pressure. Assessing above your actual level isn't a violation, just unnecessary cost and effort.

Should I use historical or projected transaction volume for my PCI compliance level?

Historical volume, usually the prior 12 months, is the standard basis. Projected volume matters when you don't have a full year of history yet or when a known upcoming change, a new channel or a major new customer, will clearly push you past a threshold before your next scheduled review.

What's the difference between PCI merchant levels and service provider levels?

PCI DSS merchant levels run on a four-tier scale (1-4) based on total transaction volume across all channels. Service provider levels run on a separate two-tier scale (1-2) based on a 300,000-transaction threshold. A business can be classified on both scales at once for different parts of its operations.

Can I voluntarily assess at a higher PCI compliance level?

Yes, and some businesses do, usually to satisfy an enterprise customer's security requirements ahead of actually crossing the threshold that would require it. There's no rule against validating more rigorously than your transaction volume strictly requires.

Related Reading