PCI Merchant and Service-Provider Levels, Explained
Level 1 through 4 — what each level means for your certification path, who sets the thresholds, and why your acquirer gets the last word.
What the levels decide
Your level decides your validation path: Level 1 means a ROC from a QSA; lower levels generally mean a SAQ. The thresholds are set by each card brand by annual transaction volume — and they're not identical across brands, so determine your level per brand.
Merchant levels
| Level | Visa / Mastercard threshold | Validation |
|---|---|---|
| 1 | 6M+ transactions/year | Annual on-site QSA assessment → ROC |
| 2 | 1M–6M/year | Annual SAQ (acquirer may require ROC) |
| 3 | 20K–1M e-commerce/year | Annual SAQ |
| 4 | Below Level 3 | Annual SAQ |
Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.
Request quotesService-provider levels
| Level | Threshold | Validation |
|---|---|---|
| 1 | 300K+ transactions/year | Annual on-site QSA assessment → ROC |
| 2 | Below 300K/year | Annual SAQ (varies by brand) |
The acquirer override
Your acquirer can — and often does — require more than the brand minimum: a ROC from a Level 2 merchant, quarterly scans for a SAQ filer, or an earlier re-assessment after a breach. The levels are the floor, not the ceiling. Get your requirements in writing from your acquirer, not from a blog post.
Growing through the levels
Crossing into Level 1 is the big transition: from self-attestation to an independent on-site assessment, from a weeks-long SAQ effort to a 4–9 month ROC cycle. Companies usually see it coming a year out — that's when to start the certification process, not when the acquirer's letter arrives.
Keep reading
ROC vs SAQ: Which PCI Validation Path Are You On?
The two roads through PCI DSS certification — what happens on each, who decides, and the expensive mistake of picking the wrong one.
SAQ Types A Through D, Explained
Eight questionnaires, one choice that shapes your whole PCI workload. Which SAQ type fits your payment setup — and what each one demands.
What QSAs Actually Test: Inside ROC Fieldwork
Phase 4 demystified — the testing procedures, the evidence requests, and how to walk into fieldwork with everything ready.
Questions
We're Level 2 — do we need a QSA?
Usually not for validation (SAQ), but your acquirer may require a ROC anyway. And a QSA-guided SAQ is often worth it for first-timers.
Do the levels differ by card brand?
The thresholds are broadly aligned but not identical — check each brand's criteria for your transaction mix.
Turn reading into quotes
Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.