Fundamentals

PCI Merchant Levels 1–4 (and Service Provider Levels) Explained

The transaction thresholds that decide whether you need a QSA on site — and why your acquirer can override all of it.

Merchant levels

LevelAnnual transactions (Visa/Mastercard)Typical validation
Level 1Over 6 millionAnnual on-site QSA assessment → ROC
Level 21–6 millionAnnual SAQ (acquirer may require ROC)
Level 320,000–1M e-commerceAnnual SAQ
Level 4Under 20,000 e-commerce; up to 1M otherAnnual SAQ

Thresholds are per card brand and count that brand’s transactions — confirm the exact counting rules with your acquirer.

Service provider levels

Service providers have their own two levels: Level 1 (over 300,000 transactions annually) requires an annual on-site QSA assessment and ROC; Level 2 (under 300,000) typically validates with a SAQ. If you’re both a merchant and a service provider, the stricter requirements apply.

Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.

Request quotes

What each level must do

Everyone — all levels — must meet PCI DSS requirements appropriate to their environment, complete the validation method for their level annually, and submit the Attestation of Compliance to their acquirer (or to the payment brands, for Level 1). Level is about validation rigor, not about which requirements apply.

The acquirer override

Levels are floors, not ceilings. Acquirers routinely require QSA-led assessments from Level 2 merchants — after breaches, during hypergrowth, or in high-risk verticals. The level tells you the minimum; your acquirer agreement tells you the reality. Get it in writing.

Keep reading

ROC vs SAQ: Do You Actually Need a QSA On Site?

The real difference between a Report on Compliance and a Self-Assessment Questionnaire, who decides which one you do, and the expensive mistake in between.

How to Choose a PCI QSA Company: 11 Questions Before You Sign

What separates a good QSA company from an expensive rubber stamp — and the exact questions that reveal which one you’re talking to.

PCI DSS Assessment Cost in 2026: What the Fee Actually Covers

Where the money goes in a PCI engagement — the assessment fee, the testing, the remediation nobody budgets for — and how to keep the total down.

Questions

We process 5M Visa + 2M Mastercard — what level are we?

Level 1 with Visa (over 6M). Levels are assessed per brand, and hitting Level 1 with any major brand generally puts you in the ROC path — confirm with your acquirer.

Do the levels differ by card brand?

The thresholds above are Visa/Mastercard’s published criteria; other brands publish their own with minor variations. Your acquirer consolidates them for you.

Turn reading into quotes

Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.

Get a free quote