Home / Companies / Basis Theory / Blog / Post Details
Content Deep Dive

PCI Compliance Levels: Know Your Level of PCI Compliance

Blog post from Basis Theory

Post Details
Company
Date Published
Author
Basis Theory
Word Count
1,533
Company Posts That Month
11
Language
English
Hacker News Points
-
Post removed?
No
Summary

PCI DSS 4.0 merchant compliance levels, established by the PCI Security Standards Council, categorize organizations primarily by annual card transaction volume to determine the effort required to demonstrate compliance, rather than the underlying security requirements, which apply to all entities that store, process, or transmit cardholder data. Using general Visa-based thresholds, Level 1 covers merchants processing more than 6 million transactions annually, Level 2 covers 1–6 million, Level 3 covers 20,000–1 million, and Level 4 covers fewer than 20,000, although card brands and acquirers may apply different thresholds or impose stricter levels after incidents or for high-risk businesses. Level 1 generally requires quarterly network scans, external penetration testing, and an on-site Qualified Security Assessor review resulting in a Report on Compliance, while Levels 2 through 4 commonly rely on quarterly Approved Scanning Vendor scans and Self-Assessment Questionnaires, with Level 2 sometimes subject to additional acquirer requirements. Merchants should use historical or projected volume to identify their level and confirm it with their acquirer, while recognizing that PCI-compliant payment service providers and tokenization technologies can reduce the systems exposed to card data and therefore lessen assessment, testing, cost, and operational burden without changing the merchant level itself.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.