PCI DSS · 6 min read · Updated 2026-06-04

PCI DSS Compliance Levels and Validation

Not every business validates PCI DSS the same way. The card brands assign merchants to one of four levels based on annual transaction volume, and the level sets how you must prove compliance.

The four merchant levels

Level 1: roughly over 6 million card transactions per year (or any merchant that has suffered a breach). The most rigorous.

Level 2: roughly 1 to 6 million transactions per year.

Level 3: roughly 20,000 to 1 million e-commerce transactions per year.

Level 4: fewer than 20,000 e-commerce transactions, or up to 1 million total transactions per year.

How each level validates

Level 1 merchants generally need an annual on-site assessment by a Qualified Security Assessor (QSA) or an internal assessor, producing a Report on Compliance (ROC) plus quarterly network scans by an Approved Scanning Vendor (ASV).

Levels 2 to 4 typically complete the appropriate Self-Assessment Questionnaire (SAQ) and an Attestation of Compliance, with quarterly ASV scans where card data is in scope.

A note on exact thresholds

Each card brand sets its own thresholds and they can differ slightly, so confirm your level with your acquiring bank. Volumes are also assessed per brand, not just in aggregate.

PCI DSS policy templates

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map

Automate PCI DSS with Vanta

Vanta maps the controls, collects evidence automatically, and keeps you audit-ready. The market-leading compliance automation platform.

FAQ

How do I know my PCI DSS level?
Your acquiring bank determines it based on your annual transaction volume per card brand. When in doubt, ask them directly.
What is an SAQ?
A Self-Assessment Questionnaire. There are several types (A, A-EP, B, C, D and more) matched to how you handle card data.