PCI DSS merchant levels (1 through 4), explained
By Sam Rivera, Founder, SentinelPanda · December 9, 2025 · 4 min read · PCI DSS
Your merchant level decides the validation path. Knowing where you sit, and what triggers a promotion, is the difference between a quarter of self-assessment work and a year of ROC fieldwork.
Why levels exist
PCI DSS itself does not assign merchant levels — the card brands (Visa, Mastercard, American Express, Discover, JCB) each publish their own level definitions and the validation requirements that go with them. The four levels broadly align across brands but specific transaction thresholds and rules can differ, particularly for service providers.
Your acquirer applies these definitions to your business and tells you which level you fall into. If you process for multiple brands, the strictest applicable rule generally governs.
Level 1 — over 6 million transactions per year
Most card brands set Level 1 at more than 6 million transactions per brand per year, with some brand-specific thresholds. Level 1 merchants must validate annually with a Report on Compliance issued by a Qualified Security Assessor and an associated Attestation of Compliance. Quarterly ASV scans and an annual penetration test are required.
A merchant at any other level can also be designated Level 1 at the card brand's discretion — typically after a confirmed account-data compromise, or because the brand judges the merchant's profile to warrant it.
If you are Level 1, you can run the full QSA-led ROC programme inside SentinelPanda — your QSA gets auditor-layer seats in your tenant to review evidence, approve controls, and request more information without you exporting anything or duplicating the work in a parallel toolchain.
Level 2 — 1 to 6 million transactions
Level 2 covers merchants processing between 1 and 6 million transactions per brand per year. Validation is typically an annual SAQ (most often SAQ D for merchants that handle card data, or a narrower SAQ where applicable), plus quarterly ASV scans where the SAQ requires them.
Some card brands allow Level 2 merchants to substitute a ROC for the SAQ if they choose — useful when a customer or partner specifically asks for a QSA-issued attestation. When that happens, the same workspace supports it: the QSA joins as an auditor seat and your evidence library doesn't move.
Level 3 — 20,000 to 1 million e-commerce transactions
Level 3 is the e-commerce-specific tier: merchants processing between 20,000 and 1 million e-commerce transactions per brand per year. Validation is via the appropriate SAQ (often SAQ A or A-EP for hosted or iframe-based payment flows), with quarterly ASV scans where required by the SAQ.
A merchant whose volumes span e-commerce and other channels usually finds Level 4 governs the non-e-commerce side — but the more restrictive level applies if there is any ambiguity.
Level 4 — everyone else
Level 4 is the long tail: fewer than 20,000 e-commerce transactions, or fewer than 1 million total transactions across all channels, per brand per year. This is where most small businesses, marketplaces, and SaaS-adjacent operators sit. Validation is the appropriate SAQ — most commonly SAQ A for fully-outsourced e-commerce.
Level 4 does not mean "no PCI obligation." The standard still applies; the validation method is just less burdensome.
Promotion events
- A confirmed account-data compromise — even a single incident — can elevate a merchant to Level 1 indefinitely.
- A significant increase in transaction volume that pushes you over the next threshold.
- A specific request from your acquirer or a card brand, often driven by their own risk policies.
- Sale or merger that combines transaction volumes across previously-separate entities.
Service providers are a separate ladder
PCI DSS treats service providers — companies that store, process, or transmit cardholder data on behalf of others — under a parallel level system, with different thresholds and validation rules. If you process payments for your own business and provide payment-touching services to others, you may carry obligations in both ladders. The separate article on service-provider levels covers that side.