PCI Merchant Levels 1–4 (and Service Provider Levels) Explained
The transaction thresholds that decide whether you need a QSA on site — and why your acquirer can override all of it.
Merchant levels
| Level | Annual transactions (Visa/Mastercard) | Typical validation |
|---|---|---|
| Level 1 | Over 6 million | Annual on-site QSA assessment → ROC |
| Level 2 | 1–6 million | Annual SAQ (acquirer may require ROC) |
| Level 3 | 20,000–1M e-commerce | Annual SAQ |
| Level 4 | Under 20,000 e-commerce; up to 1M other | Annual SAQ |
Thresholds are per card brand and count that brand’s transactions — confirm the exact counting rules with your acquirer.
Service provider levels
Service providers have their own two levels: Level 1 (over 300,000 transactions annually) requires an annual on-site QSA assessment and ROC; Level 2 (under 300,000) typically validates with a SAQ. If you’re both a merchant and a service provider, the stricter requirements apply.
Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.
Request quotesWhat each level must do
Everyone — all levels — must meet PCI DSS requirements appropriate to their environment, complete the validation method for their level annually, and submit the Attestation of Compliance to their acquirer (or to the payment brands, for Level 1). Level is about validation rigor, not about which requirements apply.
The acquirer override
Levels are floors, not ceilings. Acquirers routinely require QSA-led assessments from Level 2 merchants — after breaches, during hypergrowth, or in high-risk verticals. The level tells you the minimum; your acquirer agreement tells you the reality. Get it in writing.
Keep reading
ROC vs SAQ: Do You Actually Need a QSA On Site?
The real difference between a Report on Compliance and a Self-Assessment Questionnaire, who decides which one you do, and the expensive mistake in between.
How to Choose a PCI QSA Company: 11 Questions Before You Sign
What separates a good QSA company from an expensive rubber stamp — and the exact questions that reveal which one you’re talking to.
PCI DSS Assessment Cost in 2026: What the Fee Actually Covers
Where the money goes in a PCI engagement — the assessment fee, the testing, the remediation nobody budgets for — and how to keep the total down.
Questions
We process 5M Visa + 2M Mastercard — what level are we?
Level 1 with Visa (over 6M). Levels are assessed per brand, and hitting Level 1 with any major brand generally puts you in the ROC path — confirm with your acquirer.
Do the levels differ by card brand?
The thresholds above are Visa/Mastercard’s published criteria; other brands publish their own with minor variations. Your acquirer consolidates them for you.
Turn reading into quotes
Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.