Merchant Level

PCIComplianceHubLast updated

The tier a payment brand assigns a merchant, which determines how that merchant must validate PCI DSS compliance. Levels are based mainly on annual transaction volume per brand. Broadly: Level 1 covers the largest merchants, typically above six million transactions a year, and requires an annual Report on Compliance; Levels 2 to 4 cover progressively smaller volumes and generally allow a Self-Assessment Questionnaire. Any merchant that suffers a breach can be moved to Level 1 regardless of volume. Levels are set and enforced by each payment brand rather than by the PCI Security Standards Council, so thresholds and validation rules differ between brands, and an acquirer may impose stricter terms than the brand minimum.

Applies to. Every merchant. The level is assigned by each payment brand, usually through the acquirer, on annual transaction volume per brand.
Example. A merchant processing eight million card transactions a year is Level 1 with the major brands and validates with a ROC by a QSA. One processing 50,000 e-commerce transactions sits at a lower level and validates with an SAQ, if its acquirer agrees.
Limits. Levels belong to the brands, not to PCI DSS or the Council, so the thresholds and the validation each level requires differ by brand, can be changed by the brand and tightened by an acquirer. A breach can move a merchant to Level 1 regardless of volume. The level decides how you validate; the SAQ eligibility criteria decide which questionnaire; the standard decides what must be done, and that is the same at every level.