PCI DSS Levels Explained: Which Level Applies to Your Business (2026)

PCI DSS Levels Explained: Which Level Applies to Your Business

PCI DSS Levels : Every business that touches cardholder data gets sorted into a PCI DSS level, and that level — not company size, industry, or revenue — decides how much validation work sits ahead of you. Get the level wrong and you either under-comply and carry real risk, or over-engineer a compliance program you didn’t need yet. This guide walks through exactly how merchant and service provider levels are set, how the five major card brands differ, what happens after a breach, and which Self-Assessment Questionnaire fits your environment.

Quick idea –PCI DSS levels are assigned by annual transaction volume, not company size. Merchants have four levels (1–4); service providers have two (1–2).

Merchants:  Level 1 (6M+ transactions/year) needs a full QSA-led audit; Levels 2–4 use a Self-Assessment Questionnaire.

Service providers:  Level 1 (300,000+ transactions/year) also needs a QSA-led Report on Compliance; Level 2 self-assesses via SAQ D.

Multi-brand rule:  If you accept multiple card brands, your organization is classified at the highest level triggered by any single brand.

Context:  B4Q Assurance works with SaaS and fintech clients to confirm their PCI level, select the correct SAQ, and prepare for QSA-led assessments where required.

Why PCI DSS Levels Exist

The card brands — Visa, Mastercard, American Express, Discover, and JCB — created PCI DSS levels as a risk-based way to scale compliance effort to compliance exposure. A business processing 50 million transactions a year represents a fundamentally different breach blast radius than one processing 5,000. Levels let the payment ecosystem apply lighter validation (a self-assessment) where risk is contained, and heavier validation (an independent QSA audit) where a compromise could ripple across millions of cardholders.

Two separate scales exist because merchants and service providers carry different kinds of risk. A merchant’s exposure is usually confined to its own transactions. A service provider — a payment gateway, hosting platform, or SaaS tool that touches cardholder data on behalf of many merchants — can affect the security of every client it serves, which is why service provider thresholds are set far lower than merchant thresholds.

Merchant Levels: 1 Through 4

Merchant levels are set by annual transaction volume across a trailing 12-month period, and the specific thresholds are published by each card brand rather than by the PCI Security Standards Council itself. In practice, Visa, Mastercard, and Discover use closely aligned criteria, while American Express and JCB run their own variations.

PCI DSS Merchant Levels
Level Typical Transaction Threshold Validation Requirement
Level 1 Over 6 million card transactions/year across all channels, or any merchant that has suffered a data breach involving account data Annual Report on Compliance (RoC) by a QSA, quarterly ASV network scans, signed Attestation of Compliance
Level 2 1 million to 6 million transactions/year across all channels Annual Self-Assessment Questionnaire (SAQ), quarterly ASV scans, Attestation of Compliance
Level 3 20,000 to 1 million e-commerce transactions/year Annual SAQ appropriate to processing method, quarterly ASV scans, Attestation of Compliance
Level 4 Fewer than 20,000 e-commerce transactions/year, or up to 1 million transactions/year across all other channels Annual SAQ, quarterly ASV scans where applicable — enforcement varies by acquirer

What Actually Changes Between Levels

It’s worth being precise about what the level controls, because it’s a common point of confusion for teams new to PCI DSS Levels.

  • The underlying security requirements are identical at every level. A Level 4 merchant and a Level 1 merchant follow the same 12 PCI DSS requirements.
  • What changes is how you prove compliance — a self-signed questionnaire versus an independent audit — and how often outside parties verify it.
  • Cost and validation effort rise sharply with level. A Level 1 QSA engagement commonly runs from the tens of thousands of dollars into six figures, depending on environment complexity, while lower levels rely on internal effort to complete an SAQ.
  • A breach can move any merchant to Level 1 immediately, regardless of transaction volume, and that reclassification can hold for a fixed period even after remediation.

Service Provider Levels: 1 and 2

Service providers — payment gateways, hosting companies, SaaS platforms, and any vendor whose systems could affect the security of cardholder data — run on a separate, stricter two-tier scale. The Level 1 threshold sits at a fraction of the merchant Level 1 threshold, reflecting the fact that a single compromised service provider can expose every merchant it serves.

PCI DSS Service Provider Levels
Level Transaction Threshold Validation Requirement
Level 1 More than 300,000 card transactions/year (stored, processed, transmitted, or otherwise impacted) Annual Report on Compliance (RoC) by a QSA, annual penetration testing, quarterly ASV scans, Attestation of Compliance
Level 2 Fewer than 300,000 card transactions/year Annual SAQ D for Service Providers, annual penetration testing, quarterly ASV scans, Attestation of Compliance

Two details catch SaaS and fintech teams off guard here. First, Level 1 service providers are typically listed on the payment brand’s public registry of validated providers — Visa’s Global Registry of Service Providers, for example — which merchants increasingly check before signing a vendor contract. Second, even Level 2 service providers may be asked by a customer or acquirer to have their SAQ attested by a QSA, particularly if they serve regulated or high-risk merchants, so “Level 2” doesn’t always mean “self-assessment closes the conversation.”

Brand-by-Brand Differences

Visa, Mastercard, and Discover broadly mirror each other’s thresholds, but American Express and JCB diverge in ways that matter if you accept multiple brands.

  • Visa — sets the baseline four-level merchant structure most other brands follow; distinguishes e-commerce transaction counts from total transaction counts for Levels 3 and 4.
  • Mastercard — closely mirrors Visa’s thresholds; layers in its own Site Data Protection (SDP) program with separate registration requirements.
  • American Express — uses a lower Level 1 threshold, around 2.5 million transactions/year, under its Data Security Operating Policy (DSOP).
  • Discover — follows the same four-level structure as Visa, but determines levels based on Discover-brand transactions specifically.
  • JCB — has no formal Level 3 designation; merchants processing under 1 million JCB transactions/year are treated as Level 2.

The Multi-Brand Rule: Highest Level Wins

Every card brand applies the same principle: if you accept more than one brand, your organization is classified at the highest level triggered by any single brand, not an average or a blend.

Quick idea –PCI DSS levels are assigned by annual transaction volume, not company size. Merchants have four levels (1–4); service providers have two (1–2).

Merchants:  Level 1 (6M+ transactions/year) needs a full QSA-led audit; Levels 2–4 use a Self-Assessment Questionnaire.

Service providers:  Level 1 (300,000+ transactions/year) also needs a QSA-led Report on Compliance; Level 2 self-assesses via SAQ D.

Multi-brand rule:  If you accept multiple card brands, your organization is classified at the highest level triggered by any single brand.

Context:  B4Q Assurance works with SaaS and fintech clients to confirm their PCI level, select the correct SAQ, and prepare for QSA-led assessments where required.

How to Determine Your PCI DSS Levels

For most SaaS and fintech teams, working out the correct level is a five-step exercise rather than a single lookup.

  1. Identify whether you’re a merchant, a service provider, or both — some SaaS platforms are both if they sell their own product and also process payments on behalf of customers.
  2. Pull your transaction volume for the most recent 52-week period, across every channel: card-present, card-not-present, e-commerce, and phone orders.
  3. Check that volume against each card brand you accept, since thresholds differ by brand, especially for American Express and JCB.
  4. Apply the highest level triggered by any brand — this is your organization-wide PCI DSS level.
  5. Confirm the classification with your acquiring bank or the relevant payment brand directly. Acquirers hold final authority and can impose stricter requirements than the published thresholds.

Two situations that don’t show up in a simple transaction count also deserve a look: telephone payments count toward your total volume just like any other channel, and a business sitting near a threshold boundary should generally plan for the more stringent level, since a mid-year reclassification after volumes grow is far messier than validating one level up from the start.

Choosing the Right Self-Assessment Questionnaire (SAQ)

Your PCI level determines whether you need a QSA-led audit or can self-assess — but for merchants and Level 2 service providers who self-assess, the specific SAQ you complete depends entirely on how you handle cardholder data, not your transaction volume. There are currently ten SAQ variants published by the PCI Security Standards Council.

SAQ Types
SAQ Type Who It's For
SAQ A Card-not-present merchants (e-commerce, mail/phone order) that fully outsource cardholder data handling to a validated third party and never touch the data themselves
SAQ A-EP E-commerce merchants that outsource payment processing but whose own website can still affect the security of the payment transaction (e.g., via redirects or iframes they control)
SAQ B Merchants using only imprint machines or standalone, dial-out terminals with no electronic cardholder data storage
SAQ B-IP Merchants using only standalone, IP-connected, PTS-approved payment terminals with no electronic data storage
SAQ C Merchants with internet-connected payment applications (POS systems, card readers) that do not electronically store cardholder data
SAQ C-VT Merchants that manually key single transactions into a virtual terminal hosted by a validated third party, on an isolated computer
SAQ P2PE Merchants using only hardware payment terminals managed through a validated, PCI-listed Point-to-Point Encryption (P2PE) solution
SAQ D (Merchant) Any merchant that doesn't meet the criteria for the SAQs above, including those storing cardholder data electronically on their own systems
SAQ D (Service Provider) All Level 2 service providers eligible to self-assess
SAQ SPoC Merchants using PCI-listed Secure Card Reader–PIN (SPoC) solutions on a commercial off-the-shelf mobile device

As a rule of thumb: the more of the cardholder data journey you’ve outsourced to a validated third party, the shorter your SAQ. SAQ A runs about two dozen questions; SAQ D, the most comprehensive, runs into the hundreds. Architecture choices — routing payments through a PSP, adopting P2PE terminals, or tokenizing card data — can move a merchant from a long SAQ D onto a short SAQ A without changing transaction volume at all, which is often the fastest way to cut compliance effort.

Scope reduction tip

Before assuming you need SAQ D, check whether your payment architecture already qualifies you for something shorter.

Redirect or iframe checkout:  fully outsourced payment pages typically qualify for SAQ A.

P2PE-validated terminals:  hardware that encrypts card data at the point of interaction usually qualifies for SAQ P2PE, one of the shortest questionnaires available.

Tokenization:  replacing stored card numbers with tokens removes raw cardholder data from your environment and can shrink both your SAQ and your QSA audit scope at Level 1.

What Happens After a Data Breach

Card brands reserve the right to immediately reclassify any merchant to Level 1 following a confirmed account data compromise, regardless of prior transaction volume. That reclassification typically triggers a forensic investigation by a PCI Forensic Investigator, a formal remediation plan, and an annual QSA-led Report on Compliance — sometimes for a fixed multi-year period before the merchant can be reassessed back down to its original level. This is one of the few places where PCI DSS level is driven by incident history rather than volume alone, and it’s worth planning for even at Level 3 or 4.

Common Mistakes When Determining Your Level

  • Counting only one card brand’s transactions and missing that a different brand’s lower threshold actually governs your classification.
  • Assuming a payment processor or PSP removes your organization from PCI scope entirely, without confirming exactly what still sits inside your cardholder data environment.
  • Treating your assigned level as permanent instead of monitoring transaction volume and re-checking annually, since crossing a threshold changes your validation requirement.
  • Not accounting for phone-order transactions when calculating total volume, which can quietly push a business into a higher level.
  • Selecting an SAQ based on merchant level rather than on how cardholder data is actually handled, which is the criterion that actually determines SAQ eligibility.

Why Getting the Level Right Matters

Misclassifying your PCI DSS level cuts both ways. Under-classifying leaves gaps an acquirer or card brand can flag later, sometimes after a breach has already occurred — the worst possible time to discover you needed a QSA audit. Over-classifying means spending on validation effort, and sometimes external audit fees, that your actual transaction volume and risk profile don’t yet require. Getting the classification right the first time, and re-confirming it as volume grows, keeps compliance proportionate to actual exposure.

How B4Q Assurance Helps

B4Q Assurance works with SaaS and fintech organizations to confirm PCI DSS merchant and service provider classification, select the correct SAQ for their cardholder data environment, and prepare for QSA-led assessments where Level 1 status applies. That includes reviewing transaction volume across card brands, mapping the cardholder data environment, and identifying scope-reduction opportunities — such as tokenization or outsourced payment pages — that can move a business onto a lighter-weight SAQ.

Resources

FAQs

How do I find out my exact PCI DSS level?

Pull your transaction volume for the trailing 52 weeks, check it against each card brand’s published thresholds, and confirm the result with your acquiring bank — acquirers have final say and can require a stricter level than the published criteria suggest.

Yes. If your product stores, processes, transmits, or could otherwise impact the security of cardholder data on behalf of another business, you’re a service provider under PCI DSS, and the 300,000-transaction Level 1 threshold is far lower than the merchant scale.

It significantly reduces scope when implemented correctly — often qualifying a merchant for the short SAQ A — but it rarely eliminates PCI obligations entirely, since the surrounding systems (your website, your APIs, your logging) are usually still part of your cardholder data environment.

An SAQ is a self-signed questionnaire completed internally; a Report on Compliance (RoC) is prepared by an independent QSA after a formal audit. Level 1 merchants and Level 1 service providers need a RoC; other levels typically use the appropriate SAQ.

Not necessarily. Card brands can reclassify a breached merchant to Level 1 immediately, which usually means a forensic investigation, a remediation plan, and an annual QSA-led RoC — sometimes for a fixed period even after the incident is resolved.

 

What do you think?