PCI Compliance Levels: Know Your Level of PCI Compliance
Blog post from Basis Theory
PCI DSS 4.0 merchant compliance levels, established by the PCI Security Standards Council, categorize organizations primarily by annual card transaction volume to determine the effort required to demonstrate compliance, rather than the underlying security requirements, which apply to all entities that store, process, or transmit cardholder data. Using general Visa-based thresholds, Level 1 covers merchants processing more than 6 million transactions annually, Level 2 covers 1–6 million, Level 3 covers 20,000–1 million, and Level 4 covers fewer than 20,000, although card brands and acquirers may apply different thresholds or impose stricter levels after incidents or for high-risk businesses. Level 1 generally requires quarterly network scans, external penetration testing, and an on-site Qualified Security Assessor review resulting in a Report on Compliance, while Levels 2 through 4 commonly rely on quarterly Approved Scanning Vendor scans and Self-Assessment Questionnaires, with Level 2 sometimes subject to additional acquirer requirements. Merchants should use historical or projected volume to identify their level and confirm it with their acquirer, while recognizing that PCI-compliant payment service providers and tokenization technologies can reduce the systems exposed to card data and therefore lessen assessment, testing, cost, and operational burden without changing the merchant level itself.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.