An Overview of the Four PCI Compliance Levels

April 15, 2025

These days, credit card payments are an inseparable part of doing business. In the U.S., consumers conducted more than 250 billion transactions in 2023 with Visa cards alone. In B2B, nearly 80% of small businesses use credit cards. Before your company can benefit from lucrative processing fees, increased sales, or streamlined billing, it must meet strict Payment Card Industry Data Security Standards. The first step is understanding how PCI compliance levels impact your business.

What Are the Differences Between PCI Compliance Levels?

What are the four PCI compliance levels​

There are four levels of PCI DSS compliance. The elevated data security standards that merchants must follow don’t change between the different PCI compliance levels, but assessment and validation requirements do. Find out more about each category by consulting our in-depth PCI DSS level guides.

PCI DSS Compliance Level 4

Businesses that process fewer than 20,000 online transactions, or 1 million total credit card transactions annually, belong to PCI compliance Level 4. Like other processors, Level 4 merchants must fill out a Self-Assessment Questionnaire. The SAQ outlines current PCI DSS compliance, remediation plans for potential vulnerabilities, and any corrective actions requested.

PCI compliance requirements at this level vary considerably by card issuer, so merchants need to consult with their acquiring banks. For example, Mastercard does not require annual PCI DSS validation for Level 4 merchants as long as the business doesn’t have a recent history of data theft or breaches.

Some card issuers, including Discover and Visa, only maintain three PCI compliance merchant levels, combining Level 3 and Level 4 merchants in one group.

PCI Compliance Merchant Level 3

How does self assessment fit into PCI compliance levels​?

Organizations that process more than 20,000 but fewer than 1 million online transactions a year must adhere to Level 3 PCI compliance standards. The specific requirements vary by acquirer, but in broad strokes, this PCI DSS level usually requires:

  • Self-Assessment Questionnaire: Level 3 merchants must complete the SAQ that corresponds to their type of processing environment, such as SAQ A, SAQ C, and SAQ D.
  • External vulnerability scan: An Approved Scanning Vendor must carry out a comprehensive network and web application scan every three months.
  • Attestation of Compliance: Along with the annual SAQ, merchants must submit an AoC to validate the accuracy of all PCI compliance information provided.

Keep in mind that not all card brands and acquiring banks use the Level 3 designation, though the requirements based on transaction volume are often the same. For example, JCB Global divides PCI DSS documentation requirements into just two levels: one for merchants with more than 1 million annual transactions and another for all other merchants.

PCI DSS Compliance Level 2

Merchants that process between one and six million credit card or online transactions annually belong to PCI compliance Level 2. The validation requirements for Level 2 merchants always include the following:

Depending on the organization’s cardholder data environment, PCI DSS scope, and history of cybersecurity, Level 2 merchants may need to meet additional requirements, such as qualified assessments for noncompliance.

PCI DSS Compliance Level 1

The strictest level of PCI validation requirements for merchants, Level 1 PCI compliance applies to organizations that process a high volume of annual transactions. For Visa and Mastercard, the threshold is 6 million online and/or credit card transactions. American Express assigns Level 1 status to any merchant processing over 2.5 million combined transactions.

How do PCI compliance requirements change at Level 1? Instead of (or in addition to) filling out an SAQ, Level 1 merchants must submit an annual Report on Compliance. The RoC is a complex and detailed report on the organization’s PCI framework and program implementation, network defenses, cybersecurity practices, and ongoing PCI DSS compliance. 

To obtain a valid RoC, the highest PCI compliance merchant levels require businesses to conduct an onsite assessment. This means hiring an external Qualified Security Assessor or using a PCI SSC-certified Internal Security Assessor for an in-depth audit. Quarterly scans by an ASV are still necessary for all Level 1 merchants.

What Are PCI DSS Compliance Levels for Service Providers?

Service providers have a different set of criteria than merchants for PSS compliance validation. Some card networks require all service providers to undergo strict onsite audits. Others divide service providers into two PCI DSS levels based on transaction volume.

Visa

Service providers that handle fewer than 300,000 transactions annually must adhere to Level 2 PCI compliance requirements. This means filling out the SAQ and submitting an annual AoC.

Businesses that process or manage more than 300,000 transactions must meet Level 1 PCI validation standards, conducting an annual audit with a QSA and submitting a RoC. Both groups must carry out four ASV network scans a year. 

Mastercard

What are Mastercard's PCI compliance levels?

In addition to looking at annual transaction volume (300,000 or more), Mastercard groups service provider PCI compliance levels based on the type of transactions offered. The following service providers must meet Level 1 PCI DSS requirements regardless of volume:

  • Merchant Payment Gateways
  • Installment Service Providers
  • Token Service Providers
  • Digital Wallet Operators
  • Business Payment Service Providers
  • Third-Party Processors

These organizations must pass an onsite PCI DSS audit once a year performed by a PCI SSC-approved QSA or ISA.

American Express

American Express uses the same four PCI compliance merchant levels for service providers:

  • Level 4: Under 10,000 annual transactions
  • Level 3: 10,000 to 50,000 transactions
  • Level 2: 50,000 to 2.5 million transactions a year
  • Level 1: Over 2.5 million online and/or credit card transactions

Level 1 PCI compliance requires an onsite audit and RoC (plus AoC) every year. Other tiers must complete an annual self-assessment and carry out regular network scans.

How To Determine Your PCI Compliance Level Accurately

Adhering to PCI DSS is critical for merchants and service providers. Compliance is vital to serving your clients efficiently and securely. The last thing your organization needs is to fail PCI requirements because of mischaracterizing your merchant PCI compliance level.

Cybersecurity compliance platforms like Compyl can help you accurately measure your PCI DSS scope for auditing purposes and meet the reporting requirements of the right PCI compliance levels cost-effectively. Learn more about Compyl’s powerful PCI DSS compliance features today.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies