Compyl
GRC Your Way

PCI Compliance Levels Explained: Levels 1–4 and Why Visa and Mastercard Disagree

By Compyl Research · Last reviewed September 2026

PCI compliance levels determine how much validation your business owes each year: Level 1 requires an audited Report on Compliance, Levels 2 to 4 generally require a Self-Assessment Questionnaire and quarterly scans. The complication most guides skip is that there is no single set of levels — each card brand publishes its own, and Visa’s and Mastercard’s do not match.

Key takeaways

  • Levels are set by the card brands, not by the PCI Security Standards Council. The Council writes PCI DSS; Visa, Mastercard, American Express, Discover and JCB each decide who sits at which level and what they must file.
  • Visa has three merchant levels. Mastercard has four. The same business can be a Visa Level 3 merchant and a Mastercard Level 4 merchant on the same day.
  • Level 1 is the only tier that normally requires an audited Report on Compliance. Everyone else self-assesses, with quarterly external scans by an Approved Scanning Vendor.
  • Your acquirer has the final say. Thresholds are guidance; the bank that processes your transactions sets your obligation, and it can escalate you after a breach regardless of volume.
  • The controls do not change by level. PCI DSS v4.0.1 applies in full to everyone who touches cardholder data. Only the proof burden changes.

The thing most guides get wrong

Search for “PCI compliance levels” and you will find four neat tiers presented as universal fact. They are not. The PCI Security Standards Council maintains the standard — the twelve requirements, the SAQ types, the assessor programs — but it has never defined merchant levels. Each payment brand does that independently, and they have drifted apart.

Visa restructured to three merchant levels. Mastercard retains four. Their thresholds overlap but do not align, and American Express and Discover publish their own again, generally with lower entry points than Visa or Mastercard. A merchant processing 30,000 e-commerce transactions a year can therefore carry a different level designation from each brand it accepts, simultaneously, with different filing obligations attached to each.

This is not a technicality. It is the single most common reason businesses either over-invest in validation they do not owe, or discover mid-audit that one brand expects more than they prepared for. The practical answer is at the end of this page: ask your acquirer, in writing, per brand.

Merchant levels by card brand

LevelVisaMastercardTypical validation
Level 1Over 6 million transactions a yearOver 6 million combined Mastercard/Maestro transactions, or any merchant Mastercard designatesAnnual Report on Compliance, plus quarterly ASV scans
Level 21 to 6 million transactions a year1 to 6 million transactions a yearAnnual SAQ, plus quarterly ASV scans. Mastercard requires QSA or ISA validation for some SAQ types
Level 3Up to 1 million transactions a year20,000 to 1 million e-commerce transactions a yearAnnual SAQ, plus quarterly ASV scans
Level 4No Level 4 — Visa operates three levelsAny merchant not in Levels 1 to 3Annual SAQ; Mastercard validation optional, but your acquirer may still require it

American Express and Discover set their own thresholds, and American Express in particular escalates at lower volumes than Visa or Mastercard. If you accept those brands, confirm your designation with each rather than assuming your Visa level carries across.

Level 1: what it is and what it requires

Level 1 is the highest tier and the only one that normally requires an independent audit. You are Level 1 if you exceed roughly six million transactions a year with a brand — or, critically, if you have suffered a breach. Brands can and do escalate merchants to Level 1 after a card-data compromise regardless of volume, and that designation typically persists for at least a year.

What Level 1 owes annually:

  • A Report on Compliance (ROC) produced through an on-site assessment. Mastercard permits this to be signed by a Qualified Security Assessor, a certified Internal Security Assessor, or in some cases an executive officer; Visa expects a QSA-led assessment in most circumstances.
  • An Attestation of Compliance (AOC) submitted to the acquirer and, where required, to the brand.
  • Quarterly external vulnerability scans by an Approved Scanning Vendor from the PCI SSC’s published list.
  • Internal and external penetration testing at least annually and after significant infrastructure change.

The distinction that matters commercially: a QSA is an external firm, an ISA is your own employee who has completed PCI SSC certification. Larger merchants often train an ISA to reduce recurring assessment cost, which is only worth doing if you are staying at Level 1.

Level 2: the tier that is not always self-service

Level 2 covers merchants between roughly one and six million transactions a year with a brand. The common assumption is that Level 2 means “fill in the questionnaire yourself” — and that is often but not always true.

Mastercard requires that certain SAQ types at Level 2 be validated by a QSA or a certified ISA rather than completed unaided. So a Level 2 merchant whose environment falls under one of those SAQ types has an assessor requirement that looks much more like Level 1 than like Level 3. Check which SAQ type applies to your environment before you budget.

Level 2 otherwise requires an annual SAQ, an AOC, and quarterly ASV scans — the scans are not optional at any level with external-facing systems in scope.

Level 3: e-commerce, and where the brands split hardest

Level 3 is where Visa and Mastercard diverge most visibly. Mastercard defines it as 20,000 to one million e-commerce transactions a year — a channel-specific test. Visa’s Level 3 is a volume band with no e-commerce qualifier. A card-present retailer with modest online sales can land in different tiers depending on which brand is asking.

Requirements are an annual SAQ matched to your processing environment, quarterly ASV scans, and an AOC. The SAQ type does the real work here: SAQ A for fully outsourced e-commerce, SAQ A-EP where your site affects the payment page, SAQ D where you store cardholder data. The difference between SAQ A and SAQ D is the difference between roughly two dozen questions and several hundred.

Level 4: the largest group and the least supervised

Level 4 is a Mastercard designation — Visa has no equivalent — covering merchants below the Level 3 thresholds. It is the largest population of merchants by count and the least externally validated: Mastercard does not require validation to be submitted, though your acquirer frequently does.

Being unsupervised is not the same as being exempt. Level 4 merchants must still comply with PCI DSS in full, complete an annual SAQ, and run quarterly ASV scans where they have external-facing systems in scope. Small merchants are also disproportionately targeted precisely because their controls are assumed to be weaker, and a breach at Level 4 escalates you to Level 1 the same as anyone else.

Service provider levels are a separate scheme again

If you store, process or transmit cardholder data on behalf of others — a payment gateway, a hosting provider, a SaaS platform in the payment path — you are a service provider, and service providers have their own two-tier structure rather than the merchant levels:

  • Service Provider Level 1: more than 300,000 transactions a year. Annual on-site assessment producing a ROC, plus quarterly ASV scans.
  • Service Provider Level 2: fewer than 300,000 transactions a year. Annual SAQ D for Service Providers, plus quarterly ASV scans.

Service providers face additional PCI DSS v4.0.1 requirements that do not apply to merchants at all, including more frequent scoping reviews and specific obligations around supporting customers’ compliance. If you are both a merchant and a service provider, you are assessed as both.

What each validation artifact actually is

ArtifactWho produces itFrequencyWhat it proves
SAQ — Self-Assessment QuestionnaireYou, sometimes validated by a QSA or ISAAnnualYou have assessed yourself against the requirements in scope for your environment
ROC — Report on ComplianceQSA, or certified ISA where permittedAnnualAn assessor tested your controls and documented the evidence
AOC — Attestation of ComplianceYou and, for a ROC, the assessorAnnualA signed declaration of your compliance status, filed with the acquirer
ASV scanApproved Scanning Vendor from the PCI SSC listQuarterlyExternal-facing systems have no known exploitable vulnerabilities
Penetration testQualified internal or external testerAnnual and after significant changeSegmentation holds and the environment resists active attack

Choosing the wrong SAQ type is a more common and more expensive mistake than misjudging your level. SAQ A assumes your payment page is entirely outsourced; if your own JavaScript touches the page, SAQ A-EP applies and the question count multiplies.

How to determine your level accurately

  1. Count transactions per brand, not in total. Levels are assessed against each brand’s own volume. Six million transactions split across Visa, Mastercard and Amex is not six million with any of them.
  2. Separate e-commerce from card-present. Mastercard’s Level 3 test is e-commerce-specific. Your channel mix can change your designation.
  3. Use a rolling twelve months, not the calendar year, and use gross transaction count rather than value.
  4. Ask your acquirer in writing, per brand. They hold the definitive answer, they can impose stricter requirements than the brand minimum, and a written answer is itself useful evidence.
  5. Confirm your SAQ type before you start filling anything in. This decision drives more work than the level does.
  6. Re-check annually, and after any change to your payment flow. Adding a hosted checkout, bringing payments in-house, or a growth year can all move you.

What happens if you get it wrong

Under-validating is treated as non-compliance rather than as an honest mistake. The consequences run in a predictable order: monthly non-compliance fees from your acquirer, higher transaction rates, mandatory forensic investigation if a breach occurs, liability for fraud losses and card reissuance, and — at the far end — termination of your merchant account, which is an existential problem for a business that takes cards.

The more common failure is quieter: a merchant validates correctly for Visa, never checks Mastercard or American Express, and discovers a gap only when an acquirer’s annual review surfaces it. That is avoidable with one email.

Where Compyl fits

PCI DSS is rarely the only framework in play — most teams carrying a PCI obligation are also carrying SOC 2, ISO 27001 or HIPAA, and the underlying controls overlap heavily. Compyl maps one control library across 70+ frameworks, so an access-control or logging control written once is tested once and proves itself against PCI DSS requirement 8, ISO 27001 Annex A and the SOC 2 criteria simultaneously. Evidence for ASV scans, configuration state and access reviews is collected from your systems rather than screenshotted each quarter, and scope decisions and level designations live in one place with owners and review dates.

See how one control satisfies PCI DSS, ISO 27001 and SOC 2 at the same time in a 20-minute walkthrough — request a demo, or read the PCI DSS 4.0.1 compliance guide for the requirement-by-requirement detail.

Frequently asked questions

What are the four PCI compliance levels?

Mastercard defines four merchant levels: Level 1 above six million transactions a year, Level 2 between one and six million, Level 3 between 20,000 and one million e-commerce transactions, and Level 4 for everyone below that. Visa uses only three levels, so “the four levels” is a Mastercard framing rather than a universal one.

Who sets PCI compliance levels?

The card brands, not the PCI Security Standards Council. The Council maintains PCI DSS itself; Visa, Mastercard, American Express, Discover and JCB each define their own merchant levels and validation requirements, and your acquiring bank enforces them and can impose stricter terms.

How do I know what PCI level I am?

Count your transactions per card brand over a rolling twelve months, separating e-commerce from card-present, then confirm in writing with your acquirer for each brand you accept. Your acquirer holds the definitive answer and can escalate you above the published thresholds.

What is the difference between PCI Level 1 and Level 2?

Level 1 requires an annual Report on Compliance from an on-site assessment by a Qualified Security Assessor or certified Internal Security Assessor. Level 2 generally requires only a Self-Assessment Questionnaire — though Mastercard requires QSA or ISA validation for certain SAQ types at Level 2. Both require quarterly ASV scans.

Do Level 4 merchants have to comply with PCI DSS?

Yes. Every merchant that stores, processes or transmits cardholder data must comply with PCI DSS in full. What changes at Level 4 is the validation burden: Mastercard does not require validation to be filed, but your acquirer usually does, and an annual SAQ plus quarterly ASV scans remains the working expectation.

Can a business be a different level for Visa and Mastercard?

Yes, and it is common. Visa operates three merchant levels and Mastercard four, with different thresholds and an e-commerce-specific test at Mastercard Level 3. The same merchant can be Visa Level 3 and Mastercard Level 4 at the same time, with different obligations attached to each.

Does a data breach change my PCI level?

It can, immediately. Card brands routinely escalate breached merchants to Level 1 regardless of transaction volume, which brings a full on-site assessment and a Report on Compliance, typically for at least a year afterwards.

What are PCI service provider levels?

A separate two-tier scheme for organizations handling cardholder data on behalf of others. Level 1 service providers process more than 300,000 transactions a year and require an annual on-site assessment and ROC; Level 2 process fewer and complete SAQ D for Service Providers. Both require quarterly ASV scans, and service providers carry additional PCI DSS v4.0.1 obligations that do not apply to merchants.

Sources: PCI Security Standards Council documentation; Visa and Mastercard published merchant level definitions (Visa restructured to three levels in 2024); PCI DSS v4.0.1. Card brand thresholds change — confirm your designation with your acquirer rather than relying on any published summary, including this one.

By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies