Merchant Level
PCIComplianceHubLast updated
The tier a payment brand assigns a merchant, which determines how that merchant must validate PCI DSS compliance. Levels are based mainly on annual transaction volume per brand. Broadly: Level 1 covers the largest merchants, typically above six million transactions a year, and requires an annual Report on Compliance; Levels 2 to 4 cover progressively smaller volumes and generally allow a Self-Assessment Questionnaire. Any merchant that suffers a breach can be moved to Level 1 regardless of volume. Levels are set and enforced by each payment brand rather than by the PCI Security Standards Council, so thresholds and validation rules differ between brands, and an acquirer may impose stricter terms than the brand minimum.