The 4 PCI Compliance Levels Explained: Where a Merchant Falls and What Each Level Requires
Published on
February 15, 2026
/
updated on
September 18, 2026

How the card brands set PCI compliance levels 1 to 4, the 2 service provider tiers and what each level has to file.
The card brands sort online retailers, restaurant groups, clinic chains and every other merchant into PCI compliance levels by the number of card transactions they process in a year (1, 4, 6, 7). Your level decides what you have to file. Below Level 1 that is a Self-Assessment Questionnaire you complete yourself unless a brand requires an assessor; at Level 1 it is a Report on Compliance produced by a Qualified Security Assessor (QSA) or, where the brand allows it, an internal assessor (1, 4). Your level does not change the work of protecting customer payment data: the standard reaches every entity that stores, processes or transmits cardholder data, whatever its volume (11, 12).
If you take cards through an acquiring bank, you meet this through its request for your questionnaire or your attestation, on a deadline the bank sets. A payment gateway or a hosting provider meets the same question from the brands, as a service provider (4, 10). One business can get a different answer from each brand.
The confusion is built in: levels are set by the individual card brands, not by the PCI Security Standards Council (PCI SSC) that writes the standard, as the Council's own FAQ on compliance validation states (18). The brands do not even agree on where Level 1 starts (1, 4, 5). Choosing wrong goes badly either way: validate below your level and your acquirer lacks the documentation Visa requires it to collect from you (1); validate above it and you have paid for an assessor-led report nobody asked you for.
What Are the PCI DSS Levels of Compliance?
The levels are the card brands' way of scaling the proof they ask for to the amount of payment card data that passes through you. The PCI Security Standards Council writes the Payment Card Industry Data Security Standard (PCI DSS) and publishes the forms you report on, and its FAQ on compliance validation puts the rest of the job somewhere else (18):
"Compliance validation programs are maintained by the individual payment brands, including requirements on how and who needs to validate compliance."
Visa's Account Information Security program page says the same from the other side: the Council "owns, maintains and manages the PCI DSS and all its supporting documents; however, Visa manages all data security compliance enforcement and validation initiatives" (1). Each participating brand runs its own program: Visa, Mastercard, American Express and Discover, and JCB International and UnionPay as well (19).
So a level settles two questions, and two things do not depend on it.
- It sets the document you file. A Report on Compliance at the top tier, a Self-Assessment Questionnaire below it (1, 4).
- It sets who signs off on that document. An external assessor, a certified internal one or an officer of your own company, depending on the brand and the tier (1, 4, 6, 8).
- The card brand and what you are, not your level, set who receives it. Mastercard has merchants file through their acquiring bank, American Express asks merchants to send the documents to American Express and Discover asks for its forms at its own compliance address (4, 6, 8). Service providers file to the brand and hand the attestation to the customers who ask (4, 20).
- It does not change the standard. Every PCI DSS requirement that covers your environment is in force at Level 4 exactly as it is at Level 1 (12). Only the proof burden moves.
Four documents carry the whole scheme, and your level decides which of the first two you produce.
- Self-Assessment Questionnaire (SAQ). The reporting tool the PCI SSC glossary defines as "used to document self-assessment results from an entity's PCI DSS assessment" (10).
- Report on Compliance (ROC). The reporting tool "used to document detailed results from an entity's PCI DSS assessment" (10). A QSA tests the controls for it, or your own internal assessor where the brand allows it.
- Attestation of Compliance (AOC). The short official form on which you attest to those results, whichever of the two produced them. This is the document your acquirer and your customers ask to see.
- ASV scan report. The external vulnerability scan, run by an Approved Scanning Vendor from the PCI SSC list (22), where your questionnaire type or your brand program calls for one.
Nothing in this scheme is a certificate, even though the market speaks of PCI DSS certification levels: the Council states that "The only documentation recognized for PCI DSS validation are the official form documents from the PCI SSC website" (32). The AOC is what stands behind the market's phrase "PCI DSS Level 1 certification": a Level 1 attestation of compliance, one of those official forms, not a certificate the Council issues.
PCI Merchant Levels: Who Counts as a Merchant and What the 4 Tiers Are
Before any threshold matters, settle what you are. The brands keep separate levels for merchants and service providers: PCI DSS merchant levels for businesses that accept cards, and levels of their own for service providers (1, 4). One business can be both.
Merchant or service provider: which category are you?
One test decides which of the two PCI categories you are in, and your size has nothing to do with it. Each definition is the Council's own (10).
- Merchant. You accept payment cards bearing a participating brand's logo as payment for your goods or services.
- Service provider. You store, process or transmit cardholder data for somebody else, or your service could affect the security of theirs.
- Both. You take cards for your own sales and also handle cardholder data for other merchants or service providers, so the glossary says you can be a service provider as well.
In the PCI SSC glossary a service provider is any business other than a payment brand that handles cardholder data or sensitive authentication data "on behalf of another entity", payment gateways included (10).
What are the 4 merchant tiers?
Mastercard's Site Data Protection program sets out 4 tiers by volume, counted on the most recent 52 weeks of Mastercard and Maestro transactions, and each of the top 3 also takes any merchant that meets Visa's criteria for the same level (4).
- Level 1. More than 6 million transactions a year.
- Level 2. More than 1 million and up to 6 million.
- Level 3. More than 20,000 and up to 1 million e-commerce transactions.
- Level 4. All other merchants.
Visa's program page, read in September 2026, carries only the first 3, and Discover runs 3 levels of its own (1, 7). American Express also publishes 4, with Level 1 from 2.5 million and its lower lines at 50,000 and 10,000; a count exactly on one of its lines takes the higher tier (6). Service providers sit on a separate 2-tier scale, which turns at 300,000 transactions at Visa and Discover and at 2.5 million at American Express (1, 6, 9).
PCI DSS Compliance Levels Compared: What Each Level Must File
Find the row that matches your transactions with a brand, then read across to that brand's column. Each brand sets PCI compliance merchant levels on its own transactions, so one business can sit on one row for Visa and another for American Express.
Table 1. PCI merchant levels by card brand and annual volume
| Your transactions with that brand in a year | Visa | Mastercard | American Express | Discover |
|---|---|---|---|---|
| Over 6 million | Level 1 | Level 1 | Level 1 | Level 1 |
| 2.5 million to 6 million | Level 2 | Level 2 | Level 1 | Level 2 |
| 1 million to 2.5 million | Level 2 | Level 2 | Level 2 | Level 2 |
| 20,000 to 1 million | Level 3, on e-commerce transactions | Level 3 above 20,000 e-commerce transactions, otherwise Level 4 | Level 2 above 50,000, Level 3 below it | Level 3 |
| 10,000 to 20,000 | Level 3, on e-commerce transactions | Level 4 | Level 3 | Level 3 |
| Under 10,000 | Level 3, on e-commerce transactions | Level 4 | Level 4 | Level 3 |
Sources: Visa AIS page (1), Mastercard SDP page (4), American Express DSOP Table 2-1 (6), Discover merchant levels page (7); read September 2026.
Note. Exactly 6 million is Level 2 at Visa and Mastercard, Level 1 at Discover; exactly 1 million is Level 2 at Visa, not at Mastercard.
Three things can override the grid.
- A designation by another brand. Mastercard's Levels 1 to 3 each take any merchant meeting Visa's criteria for the same level, and Discover's Level 1 takes merchants another brand or acquirer requires to validate as Level 1 merchants (4, 7).
- The brand's own discretion. Mastercard, Discover and American Express each reserve the right to place a merchant higher than its volume would (4, 6, 7).
- A breach, whatever the count says (7).
At American Express the levels work as PCI reporting levels: "the PCI DSS status reporting requirements are determined by the number of American Express Card transactions you process in a given year" (5).
The level then decides what you file.
Table 2. What each PCI level files
| Level | What you file |
|---|---|
| Level 1, merchant or service provider | A Report on Compliance and its AOC, from an assessment by a QSA or, where the brand allows it, by your own internal assessor, with an officer's signature where the brand asks for one (1, 4, 6, 8), plus a quarterly ASV scan where the brand program calls for one, its report sent to Discover only on request (8) |
| Levels 2 to 4, and service provider Level 2 | A Self-Assessment Questionnaire and its AOC, completed by you on the questionnaire that matches how you take payments, plus an ASV scan report where the questionnaire type or the brand program calls for one (1, 4, 6, 8), with the exceptions below |
Sources: as numbered in each cell; read September 2026.
Behind the second row sit two exceptions and a default.
- Mastercard Level 2 on SAQ A, SAQ A-EP or SAQ D needs a QSA or an Internal Security Assessor (ISA) as well (4).
- At Levels 3 and 4, Mastercard does not require validation and American Express asks for documents only at its discretion (4, 6).
- Everywhere else below Level 1, the questionnaire is filed each year the brand or your acquirer requires it (1, 4, 6).

The highest level any brand puts you in decides what you file, and you produce it once: American Express states on its PCI compliance and data security page that "the standard PCI validation documents are universal which means you can use the same validation document to report to all the payment brands" (5).
How to Determine Your PCI Compliance Level
The answer may already be in the email that brought you here. Your acquiring bank helps set the level and collects the documents: Mastercard tells acquirers to "Help merchants determine their SDP merchant level" (4), and Visa requires them to "ensure that their merchants validate at the appropriate level and obtain the required compliance validation documentation from their merchants" (1).
So the form the bank asks for tells you which tier it has you in. A Self-Assessment Questionnaire means below Level 1, and a Report on Compliance means Level 1, unless you chose one where the brand allows it (4) or a brand asked for one (8).
If the deadline is short, send three questions back to the relationship manager the same day.
- Which level have you assigned us, on which brand's transaction count, and over which period?
- Which questionnaire type do you expect from us?
- Where does the completed document go, and does your compliance program include the quarterly scan or do we arrange it?
To check the bank's answer, work out where you sit among the PCI levels of compliance, brand by brand, in five steps.
- Decide what you are. Merchant, service provider or both. The two schemes are counted and validated separately (1, 4).
- Count the last year of transactions, brand by brand. Visa counts 12 months of Visa transactions for the corporate entity (1); Mastercard uses "the most recent 52-week period" of Mastercard and Maestro volume (4); American Express and Discover count their own cards (5, 7). Count e-commerce transactions separately, because Visa and Mastercard both count Level 3 on e-commerce volume.
- For each brand, find the row its own count falls in and read that brand's column. Then check Mastercard against your Visa level too (4). One document serves every brand (5): Discover says a merchant required "to perform an on-site assessment for another card brand" does not also have to self-assess for Discover (25).
- Check the escalation clauses. A breach, a brand's discretion or another brand's Level 1 can raise your level, whatever your annual transaction volume says (4, 6, 7).
- Put your answer to the acquiring bank in writing, with the per-brand counts you used.
The bank's view carries weight because the brands hold it answerable for your validation. Visa's Core Rules add that the acquirer must report merchant compliance status to Visa "at least every 6 months" (3), and Mastercard has acquirers report on Level 1 and Level 2 merchants semi-annually (4).

Two worked examples, from a number to a document
An online retailer with one figure from a gateway dashboard. 900,000 card transactions a year, all e-commerce, and the dashboard does not split them by brand. Ask the gateway for the split, and suppose it comes back like this. Each brand's bands are its own, as Table 1 sets them out (1, 4, 5, 7).
- Visa, 500,000: e-commerce transactions under 1 million, so Level 3.
- Mastercard, 300,000: e-commerce transactions above the 20,000 floor and under 1 million, so Level 3.
- American Express, 60,000: inside its 50,000 to 2.5 million band, so Level 2.
- Discover, 40,000: its lowest tier, Level 3.
The strictest assignment is American Express Level 2, under which the retailer files a questionnaire and its AOC, plus a scan every 90 days where its questionnaire type requires one (6). Mastercard has this retailer at Level 3, so Mastercard's Level 2 assessor rule does not apply, and no brand here requires an assessor.
A retailer with a large share of American Express cards. 9 million card transactions a year across channels, and no single brand above 6 million (1, 4, 5, 7).
- Visa, 4 million: inside Visa's 1 to 6 million band, so Level 2.
- Mastercard, 2 million: combined Mastercard and Maestro volume above 1 million, so Level 2.
- American Express, 2.6 million: over its 2.5 million threshold, so Level 1.
- Discover, 400,000: Level 3 on volume, but Discover's Level 1 includes "All merchants required by another payment brand or acquirer to validate and report their compliance as a Level 1 merchant" (7), so American Express's Level 1 makes it Discover Level 1 too.
Visa and Mastercard would have taken a questionnaire. American Express would not: its Level 1 asks for an annual on-site assessment and a Report on Compliance with its AOC, and that one report answers the other three brands as well (5). One brand decides the whole exercise, and it is not the one with the most volume, which is why the count is done brand by brand rather than on one total.
The transactions that count
Visa answers which transactions count in a footnote to its own criteria on the Account Information Security program page, and the answer cuts both ways (1):
"Merchant level identification is based on the corporate entity's total volume of Visa transactions (inclusive of credit, debit and prepaid) meeting the transaction thresholds in one country or with one acquirer per year. Volume from independently-owned and operated merchant locations (e.g., franchisee, licensee) may be excluded if it is not processed by the corporate entity."
Credit card transactions are not the whole count: Visa includes debit and prepaid volume and lets the corporate entity exclude volume it does not process. American Express counts a franchisor's franchisee volume as its own (6). It also leaves Buyer Initiated Payments, a solution that lets buyers schedule payments to their suppliers on corporate cards, out of the count entirely (6). Check the payment channels and business processes that touch cards before you trust a number from a dashboard.
What This Involves, and What to Tell Leadership
Once the level is settled, leadership wants a size before it wants a plan. There is no honest average to give: the effort follows the document your level requires and the size of the cardholder data environment behind it.
- A questionnaire. American Express's Data Security Operating Policy lets it be completed by "personnel within your Company qualified to answer the questions accurately and thoroughly" (6). Whoever answers it needs the payment flow, the systems around it and the people who run them.
- A Report on Compliance. The same policy describes "a detailed onsite examination" of the systems in scope, performed by "a QSA, or an Internal security assessor (ISA) and attested to by your chief executive officer, chief financial officer, chief information security officer, or principal" (6).
- The scan. An ASV scan is "a remote test to help identify potential weaknesses, vulnerabilities, and misconfigurations of internet-facing components of your Cardholder Data Environment" (6). Where it applies, it recurs rather than running once: American Express states that "Scans are mandatory if required by the applicable SAQ" and wants the scan summary "at least once every 90 days", though from Level 3 and Level 4 merchants only on request.
- The clock. Validation is annual, and Discover states the rule plainly: "The due date to report your PCI DSS compliance to Discover Network is one year from the date of prior compliance validation" (8).
In two lines for the briefing:
- Below Level 1. A questionnaire your own people complete each year the brand or acquirer requires one, unless a brand requires an assessor, plus a 90-day scan where the questionnaire calls for one.
- At Level 1. An annual assessment by a QSA or, where the brand allows it, an internal assessor, with a report your leadership signs where the brand asks for one.
PCI DSS Level 1: Over 6 Million Transactions and an Assessor-Led Report
A Report on Compliance is the document behind Level 1 PCI compliance. Each brand sets its own way in.
- Visa. Merchants processing "over 6 million Visa transactions annually across all channels", or "Global merchants identified as Level 1 by any Visa region" (1).
- Mastercard. More than 6 million combined Mastercard and Maestro transactions, or Visa's own Level 1 criteria (4).
- American Express. 2.5 million or more American Express Card transactions a year (5).
Volume is not the only route in. Mastercard can place in the tier any merchant that it, "in its sole discretion, determines should meet the Level 1 merchant requirements" (4), so a business nowhere near 6 million transactions can still land at PCI compliance Level 1.
Under the PCI DSS Level 1 requirements for validation you file documents, not extra controls: a Report on Compliance from an annual PCI DSS assessment (4) and the AOC filed with it. Discover also names a quarterly network scan by an Approved Scanning Vendor for its Level 1 merchants (8). Check who may sign that report before you engage anyone.
- Mastercard names all three options. The AOC for the Report on Compliance must be "signed by a PCI SSC-approved Qualified Security Assessor (QSA), PCI SSC-certified Internal Security Assessor (ISA), or, unless prohibited by law or regulation, an executive officer of the merchant" (4).
- Visa and Discover word it differently. Visa takes a QSA or an "internal resource if signed by officer of the company" (1); Discover takes a QSA or your own ISA and nobody else (8).
Prepare for a PCI audit, requirement by requirement
The guide to the PCI audit walks through how an assessment is prepared for and what evidence gets collected requirement by requirement.
PCI DSS Level 2: 1 to 6 Million Transactions and a Self-Assessment
Self-assessment is the default at this tier, with one catch that depends on the brand. Visa defines PCI compliance Level 2 as "1 to 6 million Visa transactions annually across all channels" (1), and Mastercard as "more than one million but less than or equal to six million total combined Mastercard and Maestro transactions annually", or any merchant meeting Visa's Level 2 criteria (4).
American Express counts much lower, putting merchants with 50,000 to 2.5 million of its transactions in its own Level 2 (5).
If Mastercard puts you at Level 2 and you file SAQ A, SAQ A-EP or SAQ D, budget for an assessor. Mastercard's Site Data Protection program sets out a rule and an option for Level 2 PCI compliance in the same footnote (4):
- The assessor rule. "Level 2 merchants completing SAQ A, SAQ A-EP or SAQ D must additionally engage a PCI SSC-approved QSA or PCI SSC-certified ISA for compliance validation".
- The upgrade option. Level 2 merchants may "at their own discretion, engage a PCI SSC-approved QSA or PCI SSC-certified ISA to complete a ROC instead of performing an SAQ".
In PCI Level 1 vs Level 2, the practical difference is who tests the controls: at Level 1 a QSA or, where the brand allows it, your own internal assessor tests them for a Report on Compliance; at Level 2 you answer for them yourself, unless your questionnaire type pulls an assessor back in.
Where no assessor is required, under the PCI Level 2 requirements you file an annual Self-Assessment Questionnaire with its AOC, as in Table 2. What drives the budget on each path is covered in the breakdown of PCI DSS certification cost.
PCI DSS Level 3: E-Commerce Merchants Under 1 Million Transactions
Visa and Mastercard both define this tier by e-commerce volume, and Mastercard also borrows Visa's definition.
- Visa. It sets PCI compliance Level 3 at "less than 1 million Visa ecommerce transactions annually across all channels" (1). There is no floor under it.
- Mastercard. The tier runs from "more than 20,000 combined Mastercard and Maestro e-commerce transactions annually but less than or equal to one million" (4). At 20,000 e-commerce transactions or fewer you are Level 4, unless you meet Visa's Level 3 criteria, which Mastercard also accepts for its own Level 3: "Any merchant meeting the Level 3 criteria of Visa".
Where validation is required, a Level 3 merchant files the SAQ package in Table 2.
Mastercard's rules for Level 3 PCI compliance also shift the checking to the acquirer: the brand "does not require that Level 3 and Level 4 merchants validate PCI compliance", and requires instead that acquirers "validate to Mastercard that they have a risk management program in place to identify and manage payment security risk within their Level 3 and Level 4 merchant portfolios" (4). The request can still reach you, from the bank rather than from the brand.
PCI DSS Level 4: Every Other Merchant
The four programs treat PCI compliance Level 4 four different ways, and only Mastercard and American Express publish one (1, 4, 6, 7).
- Mastercard. "All other merchants" (4). That leaves merchants with 20,000 or fewer e-commerce transactions a year on its network who meet none of its other criteria, Visa's Level 3 included. Its footnote is the one to read in full: Level 4 merchants "are required to comply with the PCI DSS, although validation of compliance to Mastercard is not required, except as required by applicable law or regulation".
- Visa. No Level 4 row on the program page as it stands in September 2026, and a Level 3 defined by e-commerce volume, so a card-present merchant should confirm its Visa level with the acquirer, which Visa makes responsible for validation "at the appropriate level" (1).
- Discover. It runs 3 levels, because its Level 3 is "all other merchants" (7), which catches everyone the first 2 do not.
- American Express. Its Level 4 covers merchants that process fewer than 10,000 American Express Card transactions a year, and its Data Security Operating Policy makes documentation optional for Level 3 and Level 4 merchants "unless required in American Express' discretion" (6).
This is where complying and validating come apart. The tier counts transactions, not the sensitive payment card data you store. The PCI SSC merchant resources page is unambiguous that the standard still applies (12):
"PCI DSS is intended for all entities involved in payment processing, including merchants, regardless of their size or transaction volume. [...] Whether a small merchant is required to validate compliance is determined by the individual payment brands."
So the checks on Level 4 merchant PCI compliance run through the acquirer's risk program at Mastercard, and through a request from the brand at American Express and at Discover's lowest tier (4, 6, 8). When the request comes, you file the SAQ package in Table 2, and the questionnaire type named in the request sets the PCI DSS Level 4 requirements you answer.
Scanning is one of the PCI Level 4 requirements that depends on the brand and the questionnaire. Discover names a quarterly external scan at every one of its merchant levels (8), and American Express ties its scan to the questionnaire type (6). If your acquirer has never asked you for anything, the duty of Level 4 PCI compliance still stands; only the filing waits for a request.
See how small businesses handle PCI compliance
The guide to PCI compliance for small businesses covers the Level 3 and Level 4 case end to end, from identifying your transaction level to picking the questionnaire.
PCI DSS Service Provider Levels: The 2-Tier Scheme
The brands sort the companies that handle payment data for somebody else into 2 PCI service provider levels, not 4 (1, 4, 6, 9). Visa, Mastercard and Discover turn on 300,000 transactions rather than 6 million for volume-based providers, while Mastercard also puts whole categories of provider in Level 1 at any volume and American Express counts on its own scale.
Table 3. PCI service provider levels by card brand
| Level | Visa | Mastercard | American Express | Discover | What it files |
|---|---|---|---|---|---|
| Level 1 | VisaNet processors, or any service provider that "stores, processes and/or transmits over 300,000 Visa transactions annually" | Third-party processors, merchant payment gateways, staged digital wallet operators, digital activity service providers, business payment service providers, token service providers, 3-D Secure and installment service providers, at any volume; plus anti-money laundering (AML) and sanctions providers, data storage entities and payment facilitators over 300,000 | 2.5 million or more American Express Card transactions a year, or any provider American Express deems Level 1 | Over 300,000 Discover Network transactions a year, or Discover's designation | Annual assessment and a ROC; Visa asks for an AOC signed by both the provider and the QSA |
| Level 2 | Any service provider under 300,000 Visa transactions annually | AML and sanctions providers, data storage entities and payment facilitators at 300,000 transactions or fewer, plus terminal servicers | Fewer than 2.5 million American Express Card transactions a year | Under 300,000 Discover Network transactions a year | Annual SAQ D for Service Providers and its AOC; Visa also accepts an AOC carrying a QSA signature; American Express and Discover add a quarterly network scan |
Sources: Visa AIS page (1), Mastercard SDP page (4), American Express DSOP Tables 2-1 and 2-3 (6), Discover service provider page (9); read September 2026.
Mastercard adds a recommendation on top of the level: that each Level 1 and Level 2 provider "also demonstrate to Mastercard its compliance with the Designated Entities Supplemental Validation (DESV) appendix of the PCI DSS" (4).
Every 12 months, at every brand. Visa puts the monitoring duty on the financial institutions: "Issuer and acquirers must ensure all their service providers demonstrate PCI DSS compliance at least every 12 months" (1). Service provider validation requirements are annual at each brand on its own terms: Mastercard requires its Level 1 providers to "validate compliance with the PCI DSS annually" (4), the American Express policy sets an annual cycle for both provider levels (6) and Discover asks for an annual assessment at Level 1 and an annual self-assessment at Level 2 (9).
How a service provider gets onto a brand registry
Being PCI DSS compliant and being listed as compliant are two different things. The Visa Account Information Security page ties the listing to who validated you, not to your level, so a Level 2 provider that filed its SAQ D alone is not eligible (1):
"PCI DSS compliance validation by a QSA is required before a service provider can be listed on the Visa Global Registry of Service Providers (the Registry)."
So a listing is not a Level 1 marker. If a customer asks whether you are Level 1 PCI compliant, the document that answers is your AOC, which the PCI SSC confirms "is intended to be shared externally to requesting entities" (20).
The Four Validation Documents: SAQ, ROC, AOC and Scans
Whether a request speaks of PCI certification levels or PCI assessment levels, each tier ends in some combination of the four documents. The level, the brand and the questionnaire type decide which ones you file and who signs them.
Table 4. PCI DSS validation documents and where each goes
| Document | Who produces it | How often | Who receives it |
|---|---|---|---|
| Self-Assessment Questionnaire (SAQ) | The entity itself, on the PCI SSC form that matches its environment (13) | Annually, where the brand or acquirer requires it (1, 4, 6) | The acquirer or the brand (13) |
| Report on Compliance (ROC) | A QSA or, where the brand allows it, your own internal assessor, with an officer's signature where the brand asks for one (1, 4, 6, 8) | Annually (1, 4) | The acquirer or the brand (4) |
| Attestation of Compliance (AOC) | Signed by the entity, and by the assessor where one was involved (1) | With every questionnaire or report (10) | The acquirer, the brand and customers who ask a service provider for it (4, 20) |
| ASV scan report | An Approved Scanning Vendor from the PCI SSC list (22) | At least once every three months (17) | The acquirer or brand: Discover on request (8); American Express every 90 days from Level 2 merchants whose questionnaire requires a scan and from Level 2 service providers filing SAQ D, but from Levels 3 and 4 only when it asks (6) |
Sources: as numbered in each cell; read September 2026.
Who has to assess you: a QSA, an ISA or yourself?
- A Qualified Security Assessor (QSA). The PCI SSC's QSA program page describes QSA companies as "independent security organizations that have been qualified by the PCI Security Standards Council to validate an entity's adherence to PCI DSS" (21). Discover requires a PCI Qualified Security Assessor or your own ISA and states that "no other third party is authorized to perform a PCI assessment for your organization" (8).
- An Internal Security Assessor (ISA). An employee of your own company, trained and qualified through the PCI SSC program "to perform internal assessments for your company and recommend solutions to remediate issues related to PCI DSS compliance" (23). Mastercard accepts an ISA at Level 1 and requires either an ISA or a QSA for three of the Level 2 questionnaire types (4).
- Yourself. At the questionnaire tiers the work is internal, though American Express lets you engage a QSA to assist (6).
Scanning is a separate job from assessment. An Approved Scanning Vendor is a "company approved by the PCI SSC to conduct external vulnerability scanning services", validating what the Council's program page calls "the external scanning requirements of PCI DSS Requirement 11.3.2" (10, 22). A passing scan report proves that one requirement and says nothing about the others, which is why it accompanies a questionnaire or a report rather than replacing either.
Which SAQ applies to you?
The questionnaire follows the way card data reaches you, not your level. The PCI SSC states the rule plainly: "all the eligibility criteria for a particular SAQ must be met to use that SAQ" (13), and that "All SAQs (except for SAQ D) are intended for merchants with less complex environments" (14).
Table 5. PCI DSS v4.x self-assessment questionnaires
| Questionnaire | Who it is for |
|---|---|
| SAQ A | "E-commerce or mail-order/telephone-order (MOTO) merchants that outsource all payment processing and do not store, process or transmit cardholder data on their premises or systems" (26), where every element of the payment page comes only from a validated third party (31) |
| SAQ A-EP | E-commerce merchants whose payment page elements each originate "from either the merchant's website or a PCI DSS compliant service provider", the direct-post case where the customer never leaves your site (31) |
| SAQ B | Named in the Council's PCI Perspectives post on the v4 questionnaires (33); its criteria are printed in the questionnaire's own opening section, and your acquirer confirms whether you may use it (13) |
| SAQ B-IP | "Environments using only PTS-approved point-of-interaction (POI) devices (excludes SCRs)" (27) |
| SAQ C | "Environments using only payment application systems (for example, point-of-sale systems) connected to the Internet" (27) |
| SAQ C-VT | "Environments using only web-based virtual payment terminals on a personal computer connected to the Internet" (27), one transaction typed at a time (15) |
| SAQ P2PE | Merchants that "process cardholder data only via a validated PCI-listed P2PE solution" (16) |
| SAQ SPoC | Merchants "using a commercial off-the-shelf mobile device (for example, phone or tablet) with a secure card reader that is part of a SPoC Solution" on the PCI SSC list (33); your acquirer confirms whether you may use it (13) |
| SAQ D for Merchants | The questionnaire with no reduced scope. Every other questionnaire requires "an attestation by the merchant that they do not store cardholder data in electronic format" (28), so storing it puts you here |
| SAQ D for Service Providers | "The only correct SAQ for a service provider is SAQ D for Service Providers. All other SAQs are intended only for merchants" (29) |
Sources: as numbered in each row; read September 2026.
Merchants that store cardholder data electronically are not eligible for SAQ C or SAQ C-VT (15), so settle the storage question before you choose.
Confirm the questionnaire choice with whoever receives it, which the PCI SSC describes as "typically, an acquirer (merchant bank) or a payment brand" (13).
Work through PCI DSS validation step by step
The step-by-step PCI DSS certification guide starts with the questionnaire or report decision and runs to the attestation, and the PCI DSS compliance checklist sets out the evidence each requirement asks for.
What Does Not Change With Your Level
The same PCI compliance requirements reach a Level 4 merchant and a Level 1 merchant (12). The Council's page on the PCI DSS standard describes it as a way to "facilitate the broad adoption of consistent data security measures globally" (11). It names its audience without any reference to volume: every entity that stores, processes or transmits cardholder data, and every entity that could affect the security of the cardholder data environment.
Two things follow from that, whatever tier you are in.
- Scope follows your payment flows. The PCI SSC glossary defines the cardholder data environment as "the system components, people, and processes that store, process, or transmit cardholder data and/or sensitive authentication data", together with any system that has unrestricted connectivity to them (10). The security controls that protect cardholder data are the same at every tier.
- The version is the same for everyone. PCI DSS v4.0.1 was published on June 11, 2024 as a limited revision with "no additional or deleted requirements in this revision", and the Council said that once v4.0 retired on December 31, 2024, "PCI DSS v4.0.1 will be the only active version of the standard supported by PCI SSC" (24). The requirements it carried forward as future-dated took effect on March 31, 2025.
What Moves You Up or Down a Level
Your level is counted over a set window: 12 months at Visa and the most recent 52 weeks at Mastercard (1, 4). Three things can change it.
- A data breach. Discover can require a merchant whose cardholder data was compromised to validate at a higher level (7), and Mastercard keeps a general discretion to place any merchant at Level 1 "to minimize risk to the system" (4).
- Crossing a threshold. A strong season can lift your 12-month or 52-week count past a line.
- A new channel. E-commerce volume is counted separately in two Level 3 definitions (1, 4), so a new web shop can change your tier without changing your revenue.
Shrinking your environment works differently. Level criteria are counted in transactions, while questionnaire eligibility is decided by your environment (13), so shrinking the environment changes which SAQ you may use and how much work it takes, not which level you sit in.
Three brand programs do cut the validation itself for merchants that move card data out of their own systems.
- Visa's Technology Innovation Program. It removes "the requirement to verify compliance with the PCI DSS when at least 75% of yearly transactions originate through EMV chip-enabled terminals, a validated point-to-point encryption solution or integrated industry-standard tokenization solution meeting EMVCo Tokenization Specification" (1, 2). Merchants whose volume is mainly e-commerce or mail and telephone order are excluded and "still required to validate PCI DSS compliance annually" (2).
- Discover's Security Compliance Innovation Program. Reporting relief for merchants that clear four criteria, one of which is a 75% test on secure acceptance technology; the others are a documented and annually tested breach response program, no breach in the past 12 months and no storage of sensitive authentication data after authorization (8). Discover spells out the caveat: "all merchants (including those determined to be eligible for PCI DSS reporting relief) are required to maintain compliance with the PCI DSS at all times". Relief from reporting is not relief from the duty to maintain PCI compliance, and ongoing monitoring is what keeps the controls in the state your last attestation described.
- American Express's Security Technology Enhancement Program (STEP). Qualifying merchants "submit only an annual STEP Attestation form" and "will not be required to submit any other annual PCI document (ROC or SAQ) or a quarterly vulnerability scan" (5).
Falling short of the standard has a cost, and the first bill does not arrive where you would expect: where a merchant "does not comply with the PCI DSS or fails to rectify a security issue", Visa "may assess a non-compliance assessment to the issuer or acquirer" (1). What reaches the merchant reaches it through the bank, and the guide to the consequences of PCI DSS non-compliance follows that bill from the acquirer down to the merchant.
Tokenization or encryption: which shrinks your scope more?
The comparison of tokenization versus encryption answers that for your environment, and the guide to PCI DSS network segmentation covers the other control that takes systems out of scope.
Conclusion
Three steps turn your level into a finished filing.
- Read the bank's request first, then count brand by brand, put your count in writing and file for the highest level you land in.
- Match the questionnaire to how you take payments, because eligibility is decided by the environment and not by the tier.
- Put the annual filing date and the scan cadence in the calendar, since validation lapses on a date rather than on an event.
The security work stays the same at every one of the PCI compliance levels; what your level decides is the paperwork.
Not Sure Which Level Your Acquirer Expects?
That question is where a PCI engagement with us starts. As a PCI DSS Qualified Security Assessor Company, we:
- Settle what you are and how you have to validate: merchant or service provider, questionnaire or Report on Compliance.
- Scope your cardholder data environment and look for the systems that can come out of it.
- Select and validate the right questionnaire, or, where a Report on Compliance is needed, perform the PCI DSS assessment and produce the ROC and AOC.
Our PCI DSS compliance services open with a readiness assessment and a gap analysis, so the areas that need improvement are identified before the formal assessment. Book a call about the request your acquirer has already sent you.
Sources
- Visa. Account Information Security (AIS) Program and PCI. https://corporate.visa.com/en/resources/security-compliance.html
- Visa. Merchant qualifications (Technology Innovation Program). https://corporate.visa.com/en/supporting-info/security-compliance/merchant-qualifications.html
- Visa. Visa Core Rules and Visa Product and Service Rules, edition of April 2026. https://corporate.visa.com/content/dam/VCOM/download/about-visa/visa-rules-public.pdf
- Mastercard. Site Data Protection (SDP) Program & PCI. https://www.mastercard.com/us/en/business/cybersecurity-fraud-prevention/site-data-protection-pci.html
- American Express. Payment Processing: PCI Compliance and Data Security. https://www.americanexpress.com/us/merchant/us-data-security.html
- American Express. Data Security Operating Policy, United States, April 2026. https://www.americanexpress.com/content/dam/amex/us/merchant/new-data-security/DSOP_United_States_EN.pdf
- Discover Network. Identify Your Merchant Level. https://www.discoverglobalnetwork.com/solutions/pci-compliance/identify-merchant-level/
- Discover Network. Determining Your Validation and Reporting Requirements. https://www.discoverglobalnetwork.com/solutions/pci-compliance/validation-reporting-requirements/
- Discover Network. Service Provider Compliance. https://www.discoverglobalnetwork.com/solutions/pci-compliance/service-provider-compliance/
- PCI Security Standards Council. PCI SSC Glossary. https://www.pcisecuritystandards.org/glossary/
- PCI Security Standards Council. PCI Data Security Standard (PCI DSS). https://www.pcisecuritystandards.org/standards/pci-dss/
- PCI Security Standards Council. Merchant Resources. https://www.pcisecuritystandards.org/merchants/
- PCI Security Standards Council. FAQ: What is a PCI DSS Self-Assessment Questionnaire? https://www.pcisecuritystandards.org/faqs/what-is-a-pci-dss-self-assessment-questionnaire/
- PCI Security Standards Council. FAQ: What is the intent of the SAQ eligibility criteria? https://www.pcisecuritystandards.org/faqs/what-is-the-intent-of-the-saq-eligibility-criteria/
- PCI Security Standards Council. FAQ: Does SAQ C-VT replace SAQ C? https://www.pcisecuritystandards.org/faqs/does-saq-c-vt-replace-saq-c/
- PCI Security Standards Council. FAQ: Who can use SAQ P2PE? https://www.pcisecuritystandards.org/faqs/who-can-use-saq-p2pe/
- PCI Security Standards Council. FAQ: Can entities be PCI DSS compliant if they have performed vulnerability scans at least once every three months, but do not have four "passing" scans? https://www.pcisecuritystandards.org/faqs/can-entities-be-pci-dss-compliant-if-they-have-performed-vulnerability-scans-at-least-once-every-three-months-but-do-not-have-four-passing-scans/
- PCI Security Standards Council. FAQ: What is the involvement of the PCI SSC on the compliance validation processes for PCI DSS assessments and scan reports? https://www.pcisecuritystandards.org/faqs/what-is-the-involvement-of-the-pci-ssc-on-the-compliance-validation-processes-for-pci-dss-assessments-and-scan-reports/
- PCI Security Standards Council. FAQ: Where do I direct questions about complying with PCI standards? https://www.pcisecuritystandards.org/faqs/where-do-i-direct-questions-about-complying-with-pci-standards/
- PCI Security Standards Council. FAQ: Is the PCI DSS Attestation of Compliance intended to be shared? https://www.pcisecuritystandards.org/faqs/is-the-pci-dss-attestation-of-compliance-intended-to-be-shared/
- PCI Security Standards Council. Qualified Security Assessors. https://www.pcisecuritystandards.org/assessors_and_solutions/qualified_security_assessors/
- PCI Security Standards Council. Approved Scanning Vendors. https://www.pcisecuritystandards.org/assessors_and_solutions/approved_scanning_vendors/
- PCI Security Standards Council. Internal Security Assessor (ISA) Qualification. https://www.pcisecuritystandards.org/program_training_and_qualification/internal_security_assessor_certification/
- PCI Security Standards Council. PCI Perspectives: Just Published: PCI DSS v4.0.1, June 11, 2024. https://blog.pcisecuritystandards.org/just-published-pci-dss-v4-0-1
- Discover Network. Performing a PCI DSS Compliance Assessment. https://www.discoverglobalnetwork.com/solutions/pci-compliance/pci-dss-compliance-assessment/
- PCI Security Standards Council. FAQ: How do PCI DSS Requirements 2, 6 and 8 apply to SAQ A merchants. https://www.pcisecuritystandards.org/faqs/how-do-pci-dss-requirements-2-6-and-8-apply-to-saq-a-merchants/
- PCI Security Standards Council. FAQ: Can merchants using non-console administrative access be eligible for SAQ B-IP, C-VT, or C? https://www.pcisecuritystandards.org/faqs/can-merchants-using-non-console-administrative-access-be-eligible-for-saq-b-ip-c-vt-or-c/
- PCI Security Standards Council. FAQ: Is storage of encrypted cardholder data considered "cardholder data" per the SAQ eligibility criteria? https://www.pcisecuritystandards.org/faqs/is-storage-of-encrypted-cardholder-data-considered-cardholder-data-per-the-saq-eligibility-criteria/
- PCI Security Standards Council. FAQ: Can service providers use eligibility criteria from a merchant Self-Assessment Questionnaire (SAQ) to determine applicable PCI DSS requirements for the service provider's assessment? https://www.pcisecuritystandards.org/faqs/can-service-providers-use-eligibility-criteria-from-a-merchant-self-assessment-questionnaire-saq-to-determine-applicable-pci-dss-requirements-for-the-service-providers-assessment/
- PCI Security Standards Council. FAQ: Do ASV scans in SAQ A apply to merchants with webpages that redirect to TPSPs or include TPSPs' embedded iframes? https://www.pcisecuritystandards.org/faqs/do-asv-scans-in-saq-a-apply-to-merchants-with-webpages-that-redirect-to-tpsps-or-include-tpsps-embedded-iframes/
- PCI Security Standards Council. FAQ: Why is SAQ A-EP used for Direct Post while SAQ A is used for iFrame or URL redirect? https://www.pcisecuritystandards.org/faqs/why-is-saq-a-ep-used-for-direct-post-while-saq-a-is-used-for-iframe-or-url-redirect/
- PCI Security Standards Council. FAQ: Are compliance certificates recognized for PCI DSS validation? https://www.pcisecuritystandards.org/faqs/are-compliance-certificates-recognized-for-pci-dss-validation/
- PCI Security Standards Council. PCI Perspectives: PCI DSS v4: What's New with Self-Assessment Questionnaires, 27 March 2024. https://blog.pcisecuritystandards.org/pci-dss-v4-whats-new-with-self-assessment-questionnaires


FAQ
How many levels of PCI compliance are there?
The count is 4, 3 or 2, depending on who is counting and what you are. Mastercard and American Express publish 4 merchant levels (4, 6); Visa's program page, read in September 2026, lists 3 and Discover lists 3 (1, 7); every one of those programs uses only 2 levels for service providers (1, 4, 6, 9). The 4-level ladder, with lines at 6 million, 1 million and 20,000 e-commerce transactions, is Mastercard's, and Visa shares its top two lines (1, 4).
How does my PCI level decide whether I need a QSA?
Level 1 calls for an assessment and a Report on Compliance. Visa accepts that report from a QSA or from an "internal resource if signed by officer of the company" (1). Mastercard lets the AOC for that report be signed by a QSA, a certified ISA or an executive officer (4). Below Level 1 you self-assess unless a brand asks for more: Mastercard requires its Level 2 merchants filing SAQ A, SAQ A-EP or SAQ D to engage a QSA or an ISA as well (4). Its Level 2 includes any merchant that meets Visa's Level 2 criteria (4).
Should I count last year's transactions or this year's forecast?
Count what has already happened. Mastercard sets the level on "Mastercard transaction volume from the most recent 52-week period" (4), and Visa on the corporate entity's total Visa volume over a 12-month period (1). A forecast is useful for planning the budget, because crossing a threshold this year means a different filing next year, but it is not what the brand programs measure.
What do I send the bank while I work out my level?
Acknowledge the request and name a date you can meet. Say that you are confirming the per-brand counts behind the level, and put them to the bank in writing once you have them, since the brands ask the bank to help set your level (1, 4). Nothing is lost by answering before the arithmetic is finished. If the date cannot be met, say so early rather than letting it pass: American Express states that "reporting on time, regardless of status, can prevent a nonrefundable, non-validation data-security fee" (5).
Does a Level 4 merchant need quarterly external scans?
Yes where the questionnaire or the brand calls for one, and SAQ A now does: the PCI SSC states that "SAQ A for PCI DSS v4.x includes requirements for external vulnerability scanning by a PCI SSC Approved Scanning Vendor (ASV) for merchant e-commerce webpages, even where payment processing is fully outsourced to a third party" (30). Discover names a quarterly ASV scan at every one of its merchant levels (8). At American Express, "Scans are mandatory if required by the applicable SAQ" (6), so a card-present merchant with no payment page may have none to run there.











