PCI-DSS

PCI-DSS Merchant Levels: Determine Yours & 2025 Requirements

David Kim September 18, 2026 9 min read
Diagram illustrating PCI-DSS merchant levels classification tiers for 2025 compliance requirements
Understanding your PCI-DSS merchant level is the first step toward achieving full payment security compliance in 2025.

Understanding your PCI-DSS merchant levels is the critical first step toward achieving payment card compliance — and getting it wrong can expose your business to fines, data breaches, and the loss of your ability to accept card payments altogether. Whether you process ten transactions a month or ten million, the Payment Card Industry Data Security Standard applies to you, and the specific requirements you must meet depend entirely on which merchant level you fall into. This guide breaks down exactly how to determine your level, what 2025 compliance requirements look like at each tier, and how to build a realistic path to validation.

What Are PCI-DSS Merchant Levels?

The PCI Security Standards Council (PCI SSC) and the major card brands — Visa, Mastercard, American Express, Discover, and JCB — use a tiered classification system to categorize merchants based on their annual transaction volume. These tiers, known as PCI-DSS merchant levels, determine the rigor of compliance validation required. Higher transaction volumes mean greater risk exposure, which translates to more stringent assessment requirements.

It's important to note that while the PCI SSC sets the overarching standard, each card brand maintains its own merchant level definitions and enforcement mechanisms. The thresholds below reflect the most widely adopted framework, primarily based on PCI Security Standards Council guidelines and Visa's merchant level program, which most other brands closely mirror.

The Four Merchant Levels at a Glance

Merchant Level Annual Transaction Volume Validation Requirements
Level 1 Over 6 million transactions per year (any channel) Annual on-site QSA audit + quarterly network scan by ASV
Level 2 1 million to 6 million transactions per year Annual SAQ + quarterly ASV scan + penetration test
Level 3 20,000 to 1 million e-commerce transactions per year Annual SAQ + quarterly ASV scan
Level 4 Fewer than 20,000 e-commerce transactions, or up to 1 million total transactions Annual SAQ (recommended) + quarterly ASV scan (recommended)

Note that any merchant that has suffered a data breach resulting in account data compromise may be automatically elevated to Level 1, regardless of transaction volume. This is a critical detail that many SMBs overlook when assessing their compliance posture.

How to Accurately Determine Your PCI-DSS Merchant Level

Determining your merchant level sounds straightforward, but there are several nuances that trip up business owners and finance teams alike. Here's a practical framework for getting it right.

Step 1: Count All Card Transactions Across Every Channel

Your transaction count must include all card-present, card-not-present, and e-commerce transactions processed under your merchant ID (MID). If your business operates multiple locations or subsidiaries under separate MIDs, each entity may be assessed independently — but some card brands aggregate across a corporate umbrella. Confirm this with your acquiring bank.

Step 2: Identify Which Card Brands Apply

Each major card brand has its own merchant level program. Visa and Mastercard use the four-level framework above. American Express uses a slightly different structure. If you accept multiple card types, you may technically fall under different levels for different brands. In practice, most merchants comply with the most stringent requirement that applies to them.

Step 3: Check for Automatic Level 1 Elevation

Beyond transaction volume, the following circumstances can trigger automatic elevation to Level 1:

  • A confirmed cardholder data breach or security incident
  • Designation by a card brand due to identified risk factors
  • Processing transactions on behalf of other merchants (aggregators or payment facilitators)

Step 4: Confirm with Your Acquiring Bank

Your acquiring bank (the financial institution that processes your card payments) is ultimately responsible for enforcing PCI-DSS compliance on your behalf. They will formally assign your merchant level and communicate the specific validation deadlines and documentation they require. Never rely solely on your own calculation — always verify with your acquirer.

2025 PCI-DSS Requirements by Merchant Level

PCI-DSS v4.0 became the only active standard as of March 31, 2024, with several future-dated requirements becoming mandatory on March 31, 2025. This means that in 2025, merchants at every level are operating under a more demanding compliance framework than they were just two years ago. Here's what each level must address.

Level 1: Full QSA Assessment

Level 1 merchants face the most comprehensive requirements. A Qualified Security Assessor (QSA) must conduct an annual on-site audit and produce a Report on Compliance (ROC). Additionally, an Approved Scanning Vendor (ASV) must perform quarterly external vulnerability scans, and an annual penetration test is required. Under PCI-DSS v4.0, Level 1 merchants must also demonstrate:

  • Targeted risk analysis for all customized implementation controls
  • Authenticated internal vulnerability scanning (new in v4.0)
  • Formal roles and responsibilities documented for every PCI-DSS requirement
  • Enhanced multi-factor authentication (MFA) across all access to the cardholder data environment (CDE)
  • Automated log review mechanisms where technically feasible

Level 2: SAQ with Increased Rigor

Level 2 merchants complete an annual Self-Assessment Questionnaire (SAQ), but the specific SAQ type depends on how they accept and process payments. Common SAQ types include SAQ A (fully outsourced card processing), SAQ B (imprint or standalone terminals), SAQ C (payment application systems), and SAQ D (all other merchants). Under v4.0, Level 2 merchants must also complete an annual penetration test and may be required by their acquirer to have their SAQ validated by a QSA or Internal Security Assessor (ISA).

Level 3: E-Commerce Focus

Level 3 applies specifically to merchants processing between 20,000 and 1 million e-commerce transactions annually. The primary concern at this level is the security of the payment page and the prevention of web-based skimming attacks — a threat that PCI-DSS v4.0 addresses directly with new requirements around script integrity monitoring and content security policies. Level 3 merchants typically complete SAQ A or SAQ A-EP, depending on whether their payment page is fully hosted by a third party or includes any merchant-controlled scripts.

Level 4: The Most Common — and Most Overlooked

The vast majority of SMBs fall into Level 4, and this is where compliance gaps are most prevalent. While the validation requirements are technically "recommended" rather than mandated by the PCI SSC, most acquiring banks contractually require Level 4 merchants to complete an annual SAQ and quarterly ASV scans. Failure to comply can result in non-compliance fees, increased transaction rates, or termination of your merchant account.

Key 2025 requirements that Level 4 merchants frequently miss include:

  • Maintaining an up-to-date inventory of all system components in scope
  • Implementing a formal vulnerability management program
  • Ensuring all third-party service providers (TPSPs) are PCI-DSS compliant and maintaining a list of their compliance status
  • Applying MFA for all non-console administrative access to the CDE
  • Reviewing and updating security policies at least annually

Scoping: The Hidden Complexity Behind Merchant Levels

One of the most consequential decisions in PCI-DSS compliance is defining your cardholder data environment (CDE) scope. Your scope includes all systems, people, and processes that store, process, or transmit cardholder data — as well as any systems that could impact the security of those systems. Scope creep is a real and costly problem: the larger your scope, the more controls you must implement and validate.

Effective scope reduction strategies include:

  • Network segmentation: Isolating your CDE from the rest of your network using firewalls, VLANs, or other controls so that out-of-scope systems cannot communicate with in-scope systems.
  • Tokenization: Replacing sensitive card data with non-sensitive tokens so that most of your systems never touch actual cardholder data.
  • Outsourcing payment processing: Using a fully hosted payment page or a payment service provider that handles all card data, potentially qualifying you for the simpler SAQ A.

Getting scoping right is where many SMBs benefit most from expert guidance. Platforms like ComplyGuard provide automated scoping tools that map your technology stack, identify in-scope systems, and flag unnecessary scope expansion — saving you significant time and reducing your compliance burden before you even begin your assessment.

Common Mistakes SMBs Make with PCI-DSS Merchant Levels

After working with hundreds of small and mid-sized businesses on payment card compliance, certain patterns of error emerge consistently:

  1. Underreporting transaction volume: Forgetting to include transactions from all channels — particularly phone orders, recurring billing, or transactions processed through a secondary payment processor — leads to incorrect level assignment.
  2. Choosing the wrong SAQ type: Selecting an SAQ that doesn't match your actual payment environment results in a compliance attestation that doesn't accurately reflect your risk posture and may be rejected by your acquirer.
  3. Treating compliance as a one-time event: PCI-DSS compliance is an ongoing program, not an annual checkbox. Quarterly scans, continuous monitoring, and policy reviews must happen throughout the year.
  4. Ignoring third-party risk: Every vendor that touches your CDE — from your e-commerce platform to your cloud hosting provider — must be assessed for PCI-DSS compliance. Under v4.0, you must maintain a documented list of all TPSPs and their compliance status.
  5. Failing to account for v4.0 future-dated requirements: Several requirements that were optional in 2023 and 2024 became mandatory on March 31, 2025. Merchants who haven't reviewed the PCI-DSS v4.0 Summary of Changes may be unknowingly non-compliant.

How Technology Can Accelerate PCI-DSS Compliance

The traditional approach to PCI-DSS compliance — hiring a QSA consultant, manually gathering evidence, and managing spreadsheets of controls — is slow, expensive, and error-prone. For SMBs operating at Level 2, 3, or 4, this approach often costs more than the compliance program is worth, leading to shortcuts that create real security risk.

Modern compliance automation platforms change this equation dramatically. ComplyGuard automates evidence collection, maps your controls to PCI-DSS v4.0 requirements, monitors your environment continuously for gaps, and generates audit-ready documentation — all without requiring a dedicated compliance team or expensive external consultants. You can compare how ComplyGuard stacks up against traditional compliance approaches to see the time and cost savings in concrete terms.

For businesses that also handle protected health information or operate internationally, ComplyGuard's multi-framework support means you can pursue PCI-DSS alongside HIPAA, SOC 2, or ISO 27001 compliance without duplicating effort — a significant advantage given how much these frameworks share in common controls. The NIST Cybersecurity Framework provides a useful reference for understanding how these overlapping controls can be managed efficiently.

Conclusion

Navigating PCI-DSS merchant levels doesn't have to be overwhelming. By accurately determining your transaction volume, understanding which validation requirements apply to your level, and building a continuous compliance program that accounts for PCI-DSS v4.0's 2025 requirements, you can protect your customers, your reputation, and your ability to accept card payments — without breaking your budget. The key is to start with clarity on your scope, choose the right SAQ type, and treat compliance as an ongoing operational discipline rather than an annual scramble.

Ready to stop guessing and start complying with confidence? Talk to a ComplyGuard compliance specialist today or explore our pricing plans to see how our AI-powered platform can get your business PCI-DSS compliant up to 10x faster than the traditional approach — at a fraction of the cost of hiring a QSA consultant.

#pci-dss#payment security#merchant compliance#data security#cardholder data

Frequently Asked Questions

See your compliance gaps in minutes

Run an AI-powered gap analysis and get audit-ready for SOC 2, HIPAA, ISO 27001, GDPR & PCI-DSS 10x faster — no expensive consultants required.

14-day free trial • No credit card required • Cancel anytime

Related Articles