Menu

4 PCI DSS Levels: Requirements and Validation Explained

4 PCI DSS Levels: Requirements and Validation Explained

A business can process thousands or millions of card transactions every year, but that does not automatically tell you what PCI DSS validation is required. The answer depends on factors such as the payment brands involved, transaction volumes, payment environment, and the requirements set by the relevant acquirer or payment brand. This is where the PCI DSS compliance levels can become confusing. Businesses often search for PCI DSS levels explained as though PCI DSS itself assigns every merchant to one of four universal categories. In reality, the commonly referenced Levels 1 through 4 come from payment-brand and acquirer compliance programs, and the exact criteria can differ.

For businesses operating across Europe, understanding this distinction matters. A European retailer, e-commerce company, or marketplace may work with multiple payment brands, processors, and acquiring banks, each with its own validation expectations. So, what are the 4 PCI DSS Level categories commonly discussed, what do they mean, and how should a merchant determine which validation requirements apply?

What Are PCI DSS Merchant Levels?

PCI DSS merchant levels are categories used by payment brands and acquirers to determine how merchants validate their compliance with the Payment Card Industry Data Security Standard. PCI DSS itself establishes technical and operational requirements designed to protect payment account data. It applies to entities that store, process, or transmit cardholder data or could affect the security of the cardholder data environment. The important distinction is that merchant levels relate primarily to validation and reporting requirements, not to four different versions of PCI DSS.

The PCI Security Standards Council states that compliance-accepting entities, typically payment brands and acquirers, determine the validation and reporting methods applicable to merchants. These may include a Report on Compliance (ROC), Self-Assessment Questionnaire (SAQ), or other methods. Therefore, when discussing the PCI DSS 4 merchant levels, businesses should treat Levels 1–4 as a commonly used classification rather than assuming that every payment brand applies exactly the same structure.

Demonstrate stronger protection of cardholder data with PCI DSS assessment from INTERCERT. Contact us to discuss your PCI DSS requirements.

PCI DSS Level 1

Level 1 generally represents merchants with the highest transaction volumes or merchants otherwise designated as Level 1 under a payment-brand program. For example, Visa's current merchant criteria identify Level 1 merchants as those processing more than 6 million Visa transactions annually. Visa also states that its merchant-level criteria have changed over time, illustrating why businesses should confirm their current classification with the relevant payment brand or acquirer.

PCI DSS Level 1 Requirements

Level 1 merchants typically face the most rigorous validation expectations. Depending on the applicable payment-brand program, this can include an annual PCI DSS assessment and a completed ROC and AOC. Mastercard, for example, states that Level 1 merchants must undergo an annual PCI DSS assessment resulting in a ROC and AOC signed by an appropriately qualified assessor or authorized individual under its program. For large European retailers, financial platforms, travel businesses, and other high-volume merchants, the complexity may extend beyond transaction volume. Multiple payment channels, cloud services, third parties, applications, and geographically distributed operations can make defining the cardholder data environment particularly important.

PCI DSS Level 2

Level 2 generally applies to merchants processing fewer transactions than Level 1, although the precise threshold depends on the payment brand and program. For example, Visa identifies merchants processing between 1 million and 6 million Visa transactions annually as Level 2 under its merchant program.

PCI DSS Level 2 Requirements

The PCI DSS Level 2 requirements are not a separate, lighter version of the PCI DSS standard. Instead, the merchant's validation method may differ from that of a Level 1 merchant. Depending on the applicable program and the merchant's environment, validation may involve an SAQ or other prescribed documentation and testing. Businesses should not select an SAQ simply because they believe they fall into Level 2. PCI SSC specifically states that merchants should confirm their validation and reporting requirements with their acquirer or relevant payment brand. For European businesses with growing online sales, Level 2 can represent an important stage where payment security processes need to become more formalized as transaction volumes and system complexity increase.

PCI DSS Level 3

Level 3 has historically been associated primarily with lower-volume e-commerce merchants under certain payment-brand programs. However, this is an area where businesses should be particularly careful when reading older PCI DSS merchant levels explained articles. Payment-brand classifications can change. For example, Visa announced that, effective April 25, 2024, it consolidated its former merchant Levels 3 and 4 into a unified Level 3 classification. Visa stated that this consolidation did not change the existing PCI DSS compliance requirements.

PCI DSS Level 3 Requirements

Where a payment-brand program uses a Level 3 category, the applicable validation method depends on that program and the merchant's payment environment. E-commerce merchants should also pay close attention to how their payment page, scripts, third-party providers, and payment-processing arrangements affect PCI DSS scope. Under PCI DSS v4.0.1, for example, specific SAQ A eligibility criteria apply to certain e-commerce payment-page arrangements. This is particularly relevant to European online businesses that rely heavily on hosted payment pages, embedded payment forms, payment gateways, and third-party service providers.

PCI DSS Level 4

Level 4 has traditionally represented lower-volume merchants within payment-brand programs. However, PCI DSS Level 4 requirements should not be interpreted as meaning that smaller businesses are outside PCI DSS. PCI SSC explicitly states that PCI DSS applies to entities involved in payment processing regardless of size or transaction volume. Smaller merchants may have simpler environments and therefore potentially face less compliance effort, but they remain responsible for protecting payment data.

The validation obligations for Level 4 merchants can vary significantly by payment brand and acquirer. Mastercard, for instance, currently states that it does not require Level 3 and Level 4 merchants to validate PCI compliance under its SDP program, while acquirers remain responsible for managing payment-security risk across those merchant portfolios.

PCI DSS Levels and Requirements: Does Your Level Change the Standard?

This is one of the most important points when considering PCI DSS requirements by level. Your merchant level does not mean that Level 4 businesses receive a separate, less secure version of PCI DSS. PCI DSS establishes a baseline of security requirements covering areas such as network security, account-data protection, vulnerability management, access control, monitoring, testing, and security policies. What can change is how compliance is validated and reported.

For example, one merchant may be required to complete a formal assessment and ROC, while another may be eligible for a particular SAQ. But SAQ eligibility is tied to the merchant's specific payment environment and eligibility criteria—not simply its transaction volume. PCI SSC states that SAQs should not be used to determine requirement applicability unless this has been reviewed and agreed with the relevant compliance-accepting entity. Therefore, the difference between PCI DSS levels and requirements is critical: merchant level can influence validation expectations, while scope and payment-processing activities determine which PCI DSS requirements apply.

How Can a European Business Determine Its PCI DSS Level?

Determining a PCI DSS level is not as simple as matching a business to a Level 1–4 chart. For businesses in Europe, the process should begin with understanding the applicable payment-brand program, transaction volumes, payment environment, and validation obligations.

Identify the Payment Brands

Start by identifying the card brands your business accepts, such as Visa or Mastercard, and the acquiring institutions that process those transactions. Each payment brand can have its own merchant classification and validation criteria, so the applicable level may differ depending on the payment programs involved.

Review Transaction Volumes

Next, determine the volume of payment transactions processed by the business. Transaction thresholds can influence merchant classification, but the calculation should follow the definitions and criteria established by the relevant payment-brand program. A European business should therefore avoid relying on a generic transaction-volume chart without confirming how the applicable card brand defines its levels.

Define the Payment Environment

PCI DSS classification should be considered alongside the scope of the payment environment. Identify the systems, applications, networks, payment pages, service providers, and business processes that store, process, or transmit cardholder data—or could otherwise affect the security of the cardholder data environment. Understanding this scope is essential for determining which PCI DSS requirements apply and what evidence may be needed during validation.

Determine the Validation Method

Once the applicable program and scope are understood, determine how compliance must be validated. Depending on the merchant's circumstances and the payment-brand or acquirer requirements, this could involve a Report on Compliance (ROC), Self-Assessment Questionnaire (SAQ), or another prescribed validation method. The validation method should not be assumed solely from the merchant's level.

Confirm With the Acquirer

Finally, confirm the requirements directly with the acquiring financial institution or other applicable compliance-accepting entity. PCI SSC advises merchants to establish whether validation is required and which reporting method applies through the relevant payment-brand or acquirer program. This final confirmation is particularly important because PCI DSS merchant levels and validation requirements can vary between payment programs.

PCI DSS Level Does Not Equal Security Maturity

A common misconception is that a Level 4 merchant has fewer security responsibilities than a Level 1 merchant. That is not the right way to view PCI DSS. A smaller European e-commerce company could have a highly complex payment architecture involving cloud platforms, APIs, third-party scripts, payment gateways, and multiple service providers. Its transaction volume may be relatively low, but its technology environment can still create meaningful security risks. In other words, PCI DSS validation levels are not security maturity levels. Your classification can influence how compliance is demonstrated. It does not determine how seriously payment data should be protected.

PCI DSS v4.0.1 and Current Validation Expectations

PCI DSS v4.0.1 is the current version listed in the PCI SSC document library. The updated version and its associated SAQs should therefore be considered when planning current PCI DSS assessments. PCI DSS v4.0.1 also places greater emphasis on areas relevant to modern payment environments, including e-commerce security. For example, updated SAQ A criteria address whether certain merchant websites are susceptible to attacks involving scripts that could affect e-commerce systems. For European organizations operating sophisticated digital commerce platforms, this reinforces an important point: determining the merchant level is only one part of the compliance process.

Build customer confidence in your payment card security controls with PCI DSS. Connect with INTERCERT to discuss your assessment requirements.

Common Mistakes When Interpreting PCI DSS Levels

Understanding PCI DSS merchant levels requires more than looking at transaction thresholds. Several common assumptions can lead businesses to select the wrong validation approach or underestimate their actual PCI DSS obligations.

Assuming PCI DSS Has One Universal Level 1–4 Classification

PCI DSS itself does not establish a single, universal Level 1–4 classification for all merchants. Merchant levels and validation requirements are generally determined through individual payment-brand and acquirer programs. A business operating in Europe may therefore need to consider the requirements of each applicable payment program rather than relying on one generic PCI DSS level chart.

Treating Transaction Volume as the Only Factor

Transaction volume is an important factor in many payment-brand programs, but it is not the only consideration. The type of transactions, payment channels, merchant status, and specific program criteria can also influence how a business is classified and what validation is required. Businesses should assess their circumstances against the criteria of the applicable payment-brand program.

Choosing an SAQ Without Confirming Eligibility

Self-Assessment Questionnaires (SAQs) are designed for specific payment environments and eligibility criteria. Selecting an SAQ simply because it appears to match a business model can result in incomplete or inappropriate validation. Before using an SAQ, the organization should confirm that its payment processes and technical environment meet the questionnaire's eligibility conditions.

Assuming Outsourcing Payments Removes PCI DSS Responsibilities

Using a third-party payment processor can reduce the amount of cardholder data an organization directly handles, but it does not automatically remove PCI DSS responsibilities. Businesses still need to understand their remaining scope, ensure relevant third-party relationships are properly managed, and address the PCI DSS requirements that apply to their own environment.

Treating a Vulnerability Scan as PCI DSS Compliance

A vulnerability scan is one component of PCI DSS validation where applicable; it is not equivalent to demonstrating overall PCI DSS compliance. PCI DSS covers a broader set of technical and operational controls, including access management, secure configurations, monitoring, authentication, data protection, and ongoing security processes. Passing a scan alone does not demonstrate that these requirements have been met.

Assuming Smaller Businesses Do Not Need PCI DSS

PCI DSS applies to entities involved in storing, processing, or transmitting payment card data, regardless of business size or transaction volume. Smaller merchants may have different validation obligations depending on the applicable payment-brand or acquirer program, but being a small business does not automatically remove PCI DSS responsibilities.

Relying on Outdated Merchant-Level Thresholds

Payment-brand programs can change their merchant classifications and validation requirements over time. Visa, for example, consolidated its former Levels 3 and 4 into a unified Level 3 classification effective April 25, 2024. Businesses should therefore verify current requirements with the applicable payment brand or acquirer rather than relying on older articles, checklists, or PCI DSS level charts.

Understanding Your PCI DSS Level Is Only the Starting Point

The 4 PCI DSS Level categories commonly referenced by businesses can provide a useful starting point for understanding merchant validation, but they should not be treated as four universal tiers defined by PCI SSC. The key is to distinguish between PCI DSS compliance levels, validation obligations, and the actual security requirements applicable to your cardholder data environment. Level 1, Level 2, Level 3, and Level 4 classifications can vary across payment-brand programs, while PCI DSS itself establishes the security baseline organizations must address.

For businesses operating across Europe, getting this distinction right can prevent incorrect assumptions about scope, SAQ eligibility, assessment obligations, and evidence requirements. INTERCERT brings experienced assessment expertise to organizations seeking a structured approach to PCI DSS compliance, with assessments focused on understanding the organization's payment environment, applicable requirements, and evidence of security controls. A PCI DSS level is only one part of the compliance picture. What matters most is understanding the systems within scope, applying the relevant controls, and being able to demonstrate their effectiveness during validation.

 

Frequently Asked Questions

How Can We Help You?

We are here to answer all your questions.


©2026 Intercert. All Rights Reserved