How Do I Determine My PCI Merchant Level

Answer :  Merchant Levels are based on the number of transactions (not dollar amount) processed in one calendar year.  Each Credit Card brand has their own Merchant Level qualifications.  It is important to note that all merchants who fall under Level 2, 3, or 4 are eligible to complete the Self-Assessment Questionnaire (SAQ) to determine their compliance status.

General Guidelines

(For greater detail, see merchant levels for each card brand following this general guidelines section)

Level Description On-site Security Audit from QSA or SAQ BackboneLockQuarterly PCI Scanning
1 Any merchant-regardless of acceptance channel-processing more than 6,000,000 transactions per year. Any merchant that recently suffered a security breach, resulting in account compromise. QSA Required
2 Any merchant processing between 1,000,000 to 6,000,000 transactions per year. QSA or SAQ completed by ISA Required
3 Any merchant processing 20,000 to 1,000,000 transactions per year. SAQ Required
4 All other merchants not in Levels 1, 2, or 3 regardless of acceptance channel. SAQ Required

 

VISA Merchant Levels Defined

Level Description
1 Any merchant-regardless of acceptance channel-processing over 6,000,000 Visa transactions per year. Any merchant that Visa, at its sole discretion, determines should meet the Level 1 merchant requirements to minimize risk to the Visa system.
2 Any merchant-regardless of acceptance channel-processing 1,000,000 to 6,000,000 Visa transactions per year.
3 Any merchant processing 20,000 to 1,000,000 Visa e-commerce transactions per year.
4 Any merchant processing fewer than 20,000 Visa e-commerce transactions per year, and all other merchants-regardless of acceptance channel-processing up to 1,000,000 Visa transactions per year.

American Express, Discover, JCB, MasterCard Merchant Levels Defined

Level AMEX Discover JCB MasterCard
1 Merchants processing over 2.5 million American Express Card transactions annually or any merchant that American Express otherwise deems a Level 1 All merchants processing more than 6 million card transactions annually on the Discover network. Any merchant that Discover, in its sole discretion1, determines should meet the Level 1 compliance validation and reporting requirements All merchants required by another payment brand or acquirer to validate and report their compliance as a Level 1 merchant Merchants processing over 1 million JCB transactions annually, or compromised merchants Merchants processing over 6 million MasterCard transactions annually, identified by another payment card brand as Level 1, or merchants that have experienced an account data compromise
2 Merchants providing 50,000 to 2.5 million American Express transactions annually or any merchant that American Express otherwise deems Level 2 All merchants processing between 1 million and 6 million card transactions annually on the Discover network Merchants processing less than 1 million JCB transactions annually Merchants processing 1 million to 6 million MasterCard transactions annually
3 Merchants processing less than 50,000 American Express transactions annually All merchants processing between 20,000 and 1 million card-not-present only transactions annually on the Discover network N/A Merchants processing 20,000 to 1 million MasterCard e-commerce transactions annually
4 N/A  All other merchants N/A All other MasterCard Merchants