PCI merchant levels: how your level is set and what it changes

Your acquirer emails asking for “your Level 1 attestation.” Nobody in the building is certain what level you are, and the answer is not in the PCI DSS standard, because the standard does not contain it.

PCI merchant levels are the part of the standard everyone quotes and almost nobody sources. This article explains who actually assigns your merchant level and the thresholds Visa publishes. It also covers why the same level number can mean very different work depending on the brand, and the five questions that get a usable answer out of your acquirer.

In short

  • The PCI Security Standards Council writes the standard. It does not assign merchant levels. Each payment brand does, and your acquirer tells you.
  • Visa sets your level on Visa transaction volume over 12 months, counted for the corporate entity in one country or with one acquirer.
  • Same level, different work: a Mastercard Level 2 merchant filing SAQ A, A-EP or D must also engage a QSA or ISA. Visa asks Level 2 for a self-assessment.
  • A breach can move you up a level regardless of volume.
6 millionVisa transactions a year, all channels, is the line above which you are Level 1
20,000Visa e-commerce transactions a year separates Level 3 from Level 4
12 monthsthe rolling window your volume is measured over

Who sets PCI merchant levels, and who does not

The PCI Security Standards Council publishes PCI DSS, the self-assessment questionnaires and the ASV program. It does not run a compliance program for merchants. It does not decide who is Level 1 either. Enforcement belongs to the payment brands, each through its own program: Visa runs Account Information Security, Mastercard runs Site Data Protection. The message reaches you through your acquirer, which is why two people in the same industry can be told different things.

The practical consequence is the one most teams miss: you can hold different PCI merchant levels with different brands at the same time. A business doing seven million Visa transactions and half a million Mastercard transactions is Level 1 to one brand and something else to the other. Same year, same systems, two answers.

Visa’s four merchant levels, and the asymmetry inside them

Visa determines your merchant level from total Visa transaction volume over a 12 month period. It counts the corporate entity meeting the threshold in one country, or with one acquirer.

Level Threshold What Visa asks for
Level 1 Over 6 million Visa transactions a year, all channels Annual Report on Compliance by a QSA, quarterly ASV scan, attestation
Level 2 1 million to 6 million Visa transactions a year Annual self-assessment questionnaire, quarterly ASV scan, attestation
Level 3 20,000 to 1 million Visa e-commerce transactions a year Annual self-assessment questionnaire, quarterly ASV scan, attestation
Level 4 Under 20,000 Visa e-commerce transactions a year Self-assessment recommended, scans optional, requirements set by your acquirer

Read the middle column twice. Levels 1 and 2 count all channels. Levels 3 and 4 are defined on e-commerce volume alone. A retailer with two million card-present transactions and four thousand online orders is not Level 4 because of the four thousand. That asymmetry is responsible for a good share of the self-assessments that get rejected.

Same level, different work

Mastercard publishes its own validation rules, and at Level 2 they diverge sharply from Visa’s. In Mastercard’s words, Level 2 merchants completing SAQ A, SAQ A-EP or SAQ D “must additionally engage a PCI SSC-approved QSA or PCI SSC-certified ISA for compliance validation.” A Level 2 merchant can also choose to have a QSA or ISA produce a full Report on Compliance instead of the questionnaire.

The two ends of the ladder differ too. At Level 1 Mastercard accepts a report signed by a QSA, by a certified internal assessor, or, unless law forbids it, by an executive officer of the merchant. At Level 4 it states that merchants are required to comply with PCI DSS “although validation of compliance to Mastercard is not required, except as required by applicable law or regulation.”

PCI merchant levels compared: what Visa and Mastercard each require from a Level 2 merchant
The same two words, “Level 2,” buy you a self-assessment with one brand and an assessor with the other.

“We are Level 2” tells you almost nothing until you say which brand.

A breach can move you up

Volume is not the only input into your merchant level. Visa states that any merchant that has suffered a hack resulting in an account data compromise may be escalated to a higher validation level. A company that spent years filing a questionnaire can find itself owing a full assessment in the same year it is also paying for forensics.

That is worth pricing before it happens rather than after. The cheapest year to build the evidence is any year that is not the year of the incident. It is also the argument for having a response capability and an incident response plan that is actually written down.

Level 4 is where the confusion about merchant levels lives

Most merchants are Level 4, and Level 4 is where the words “compliance” and “validation” get used as if they meant the same thing. They do not. PCI DSS applies to every entity that stores, processes or transmits account data, whatever its level. What the level changes is who asks you to prove it, and in what format.

So a Level 4 merchant with no reporting obligation to Mastercard still has to meet the standard. If a breach happens, the questions asked afterward are about the standard, not about the paperwork nobody requested.

Service providers climb a different ladder

If you process, store or transmit account data on behalf of others, you are a service provider, and PCI merchant levels do not apply to you at all. Service providers climb their own ladder. Mastercard requires Level 1 service providers to validate annually through a Report on Compliance conducted by a QSA. There are narrower routes for specific roles: a qualifying Level 2 data storage entity may submit a PIN Security Requirements attestation from a Qualified PIN Assessor every two years instead.

Merchants who quietly became service providers, usually by hosting or integrating payments for someone else, are the ones this catches.

Five questions that get a usable answer

Your acquirer holds the answer. Ask in writing, and ask for all of it at once, because the follow-up email costs another two weeks.

  1. 1 What is my level with each brand? Not “my level.” Each one, named.
  2. 2 Which SAQ do you expect, by its letter? A, A-EP, B, C, D and the rest are different documents with different scopes.
  3. 3 Do you require the ASV scan report, or only the attestation? Programs differ, and so do deadlines.
  4. 4 Is any group entity or country assessed separately? Visa counts per country or per acquirer, so a group can hold several levels at once.
  5. 5 What is the reporting date? Put it in the same place as the evidence, not in somebody’s inbox.

If the answer comes back as “you are Level 4, do not worry about it,” treat that as the start of the conversation rather than the end. Validation being optional is not the same as the standard not applying.

Questions we get asked about PCI merchant levels

Who decides my PCI merchant level?

Each payment brand does, through its own program, and your acquirer passes the decision on to you. The PCI Security Standards Council writes the standard but assigns nobody a level.

Can I be Level 1 with one brand and Level 3 with another?

Yes, and it is common. PCI merchant levels are counted per brand on that brand’s transaction volume, so a business weighted toward one card network will sit at different heights on each ladder.

Do PCI merchant levels apply to service providers?

No. Service providers have a separate classification with its own thresholds and its own validation rules. If you handle account data on behalf of other businesses, you are reading the wrong ladder.

Does a breach change my merchant level?

It can. Visa states that a merchant which suffered an account data compromise may be escalated to a higher validation level, independently of transaction volume.

Where we fit

Nordstern is listed by the PCI Security Standards Council as an Approved Scanning Vendor with global scope, certificate 50955001-01. That is the part of the program covering the quarterly external scan every level from 3 upward relies on. That scan is a specific exercise with specific pass criteria, and it is the piece most often discovered late.

Before the scan there is the question of what is in scope at all, which is the work that decides how large the rest of the program becomes. If you want that scoped properly, our PCI DSS consulting and PCI DSS practice start there. Talk to the team when you have your acquirer’s answer in hand, or before, if the answer is taking too long.


Sources