PCI DSS compliance validation requirements vary based on your merchant level, which is determined primarily by the volume of payment card transactions your organization processes annually. Understanding your merchant level is the first step in determining your compliance obligations, including whether you need a full on-site assessment by a Qualified Security Assessor or can self-validate using a Self-Assessment Questionnaire. This guide explains the four merchant levels, how they are determined, and the specific validation requirements for each.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
Monthly billing · cancel anytime · 30-day money-back guarantee
Your merchant level is determined by the number of payment card transactions you process annually. Level 1: over 6 million, Level 2: 1-6 million, Level 3: 20,000-1 million, Level 4: under 20,000 e-commerce or up to 1 million total. Contact your acquiring bank for your exact classification.
SAQ A is the simplest questionnaire for merchants that fully outsource all cardholder data functions to compliant third parties. SAQ D is the most comprehensive, covering all PCI DSS requirements, for merchants that store, process, or transmit cardholder data and do not fit other SAQ categories.
Yes. All merchants that accept payment cards must comply with PCI DSS regardless of transaction volume. Level 4 merchants have streamlined validation requirements (SAQ instead of QSA assessment), but the underlying security requirements apply in full.
Costs vary significantly: Level 1 QSA assessments typically range from $50,000 to $500,000+. Level 2-3 SAQ completion and ASV scans may cost $5,000 to $50,000. Level 4 merchants with simple setups may spend $1,000 to $10,000. Costs depend on environment complexity and scope.
Yes. Merchant levels can change due to transaction volume growth, acquirer reclassification, or security incidents. Merchants that suffer a data breach are typically elevated to Level 1 regardless of volume. Your acquirer can also elevate your level based on risk considerations.
E-commerce merchants typically need SAQ A if they fully outsource payment processing (e.g., redirect to PayPal/Stripe hosted page), SAQ A-EP if they have a website that can impact payment security (e.g., embedded iframe), or SAQ D if they directly handle cardholder data.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
PoliWriter creates all the policies you need for PCI DSS compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free