Service Provider Level

PCIComplianceHubLast updated

The tier a payment brand assigns a service provider, determining how it must validate compliance. Level 1 service providers, typically those handling more than 300,000 transactions a year, require an annual onsite assessment producing a Report on Compliance. Level 2 service providers may generally self-assess using SAQ D for Service Providers. As with merchant levels, thresholds are set by each payment brand rather than by the PCI Security Standards Council. PCI DSS also contains requirements that apply only to service providers, independent of level.