← All postsHow-to

PCI compliance levels: work out which one you are before anything else

Your level decides whether you fill in a questionnaire or hire an assessor. Getting it wrong in either direction costs money — one way in fees, the other in a failed validation.

How-toP

PCI compliance levels classify merchants by how many card transactions they process in a year, and the level determines how compliance must be validated: a self-assessment questionnaire completed internally, or a formal report on compliance produced by a qualified assessor. Everything else about the annual exercise follows from that classification.

The classification is per card brand and is applied by your acquirer, which is the detail merchants miss. You do not choose your level, and a business can sit at different levels with different brands. If you have never been told your level, the acquirer is the party to ask — and the answer arrives faster than most people expect, because they already know it.

How PCI compliance levels work

  • Level 1 — the largest transaction volumes, and any merchant that has suffered a breach where the brand requires it. Validation is a formal report on compliance by a qualified security assessor or an internal assessor, plus quarterly external scans.
  • Levels 2 to 4 — descending volume bands, validated by the appropriate self-assessment questionnaire and an attestation of compliance, with external scanning where the environment requires it.
  • The thresholds are set by each card brand, are stated in transactions per year, and differ between brands and between card-present and e-commerce channels.
  • Service providers have their own separate level scheme, which is why a business that is both a merchant and a provider has two obligations rather than one.
  • A breach can move you up a level regardless of volume.

Scope drives the cost more than level does

Two merchants at the same level can face wildly different work depending on how much of their environment touches card data. A shop that has outsourced payment entirely to a hosted page, never seeing a card number, is in a far smaller scope than one that captures cards in its own form and passes them to a gateway — even at identical transaction volumes. Reducing scope is the highest-leverage decision available: it is usually a payment integration change, and it shrinks the questionnaire, the scanning obligation and the ongoing evidence burden at once.

Compliance is validated annually and evidenced continuously. A questionnaire completed once and filed proves nothing about the following eleven months, and the scans, policy reviews and access reviews it attests to have their own cadence.

Who actually enforces it

The card brands set the standard, but the party that enforces it against a merchant is the acquirer, through the merchant agreement. That is why penalties arrive as fees on a statement rather than as regulatory fines, and why the practical questions — which level, which questionnaire, what evidence, by when — are answered by the acquirer rather than by the standards body. Ask them in writing and keep the answer; it is the document that defines your obligation.

Keeping the annual file

What you need to be able to produce is small and specific: the level as confirmed by your acquirer, the completed questionnaire and attestation, the scan reports, and the evidence for the controls you attested to. Ettex Records holds that file per year with the renewal date visible, Ettex Sheets tracks the scan and review cadence, and the questionnaire itself is covered in pci saq, with the working list in pci compliance checklist.

Being direct: this is a records tool, not a compliance product. We do not scan, assess, attest or advise. Level determination and validation requirements come from your acquirer and the card brands, and a qualified assessor is the authority above the self-assessment tier.

Frequently asked

What are PCI compliance levels?

Classifications by annual card transaction volume that determine how a merchant validates compliance — self-assessment questionnaire or a formal assessor report.

Who decides my level?

Your acquirer applies the card brands’ thresholds. It is not self-selected, and it can differ by brand.

Does a breach change my level?

It can. Card brands may require the highest validation level from a merchant that has suffered a compromise, regardless of volume.

How do I reduce the work?

Reduce scope. Outsourcing card capture so your systems never touch card data shrinks the questionnaire, the scanning and the evidence burden more than anything else.

SL
Written by Sofia L.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.