PCI compliance levels decide how you prove compliance with PCI DSS, not whether you have to comply. Every business that stores, processes or transmits cardholder data must meet the standard. Your level, set by each card brand from your annual transaction count, decides the paperwork: a Report on Compliance from a formal assessment, or a Self-Assessment Questionnaire (SAQ) you complete yourself. Your SAQ type, set by how you take payments, decides which requirements you answer, including whether you need quarterly ASV scans and a penetration test.
This guide covers both halves: the levels for each brand and what each must submit, then the SAQ types, who qualifies for each, and which ones pull in scanning and testing. We deliver the ASV scans, the Requirement 11.4 penetration test and, for organizations that validate with a Report on Compliance, the ROC assessment. Our PCI DSS penetration testing page covers that work; this page is about working out what applies to you.
Who sets PCI compliance levels
Not the PCI Security Standards Council. The Council writes the standard and the SAQs, but its founding payment brands (American Express, Discover, JCB, Mastercard and Visa) each run their own compliance program, and whether a small merchant has to validate “is determined by the individual payment brands” (PCI SSC merchant resources). In practice you deal with your acquirer, the bank or processor that handles your card payments, and it tells you your level and what to submit.
Three consequences follow:
- You can have a different level with each brand. Levels are counted per brand, so a merchant can be Level 2 for Visa and Level 3 for American Express.
- Brands can move you up. American Express, for example, reserves the right to assign Level 1 to any merchant at its discretion.
- Older guides are out of date on Visa. Visa now publishes three merchant levels, not four; the former Level 4 has been folded into Level 3 (Visa security and compliance).
Merchant levels by card brand
Counts are annual transactions with that brand over a 12-month period.
| Level | Visa | Mastercard | American Express |
|---|---|---|---|
| Level 1 | Over 6 million Visa transactions across all channels, or a global merchant identified as Level 1 by any Visa region | Over 6 million combined Mastercard and Maestro transactions, or any merchant that has had an account data compromise | 2.5 million or more, or any merchant American Express assigns to Level 1 |
| Level 2 | 1 million to 6 million across all channels | Over 1 million and up to 6 million | 50,000 to fewer than 2.5 million |
| Level 3 | Everyone below Level 2; Visa describes it as fewer than 1 million e-commerce transactions across all channels | Over 20,000 and up to 1 million combined e-commerce transactions | 10,000 to fewer than 50,000 |
| Level 4 | No longer a separate Visa level | All other merchants | Fewer than 10,000 |
Visa counts the corporate entity’s total Visa volume (credit, debit and prepaid) in one country or with one acquirer; volume from independently owned and operated locations, such as franchisees, may be excluded if the corporate entity does not process it. American Express levels come from its Data Security Operating Policy. Discover and JCB run their own programs; your acquirer confirms how they apply to you.
What each level has to submit
This is where the levels matter. Level 1 means a Report on Compliance; everyone else self-assesses, with extra conditions at Level 2.
| Level | Visa | Mastercard | American Express |
|---|---|---|---|
| Level 1 | Annual Report on Compliance by a Qualified Security Assessor (QSA), or by an internal resource if signed by an officer of the company, plus an Attestation of Compliance (AOC) | Annual onsite assessment resulting in a Report on Compliance | ROC with its AOC, mandatory |
| Level 2 | Annual SAQ | Annual SAQ, with a QSA or a PCI-certified Internal Security Assessor (ISA) involved when the SAQ is A, A-EP or D; or a ROC | SAQ with its AOC mandatory (unless a ROC is submitted), plus quarterly scans where the SAQ type requires them |
| Level 3 | Annual SAQ | Mastercard does not require validation to Mastercard; the acquirer must run a risk management program for these merchants | SAQ optional unless American Express requires it |
| Level 4 | Not applicable | As Level 3 | As Level 3 |
Two points get lost in most summaries. First, “no validation required” never means “no compliance required”: the brands still expect Level 3 and Level 4 merchants to comply with PCI DSS, and your acquirer can ask for an SAQ at any time. Second, quarterly external scans by an Approved Scanning Vendor (ASV) are not set by your level. They come from Requirement 11.3.2 of the standard, so whether you need them depends on your SAQ type or ROC scope, covered below.
Service provider levels
If you store, process or transmit cardholder data on behalf of other businesses, such as a payment gateway, a hosting provider or a SaaS platform that touches card data, you are a service provider, and the levels are simpler.
| Brand | Level 1 | Level 2 |
|---|---|---|
| Visa | VisaNet processors, or any service provider handling over 300,000 Visa transactions a year: annual onsite assessment, with an AOC signed by the service provider and the QSA | Fewer than 300,000: SAQ D for Service Providers, or an AOC including a QSA signature. QSA validation is required to be listed on the Visa Global Registry of Service Providers |
| American Express | 2.5 million transactions or more a year, or any provider American Express deems Level 1 | Fewer than 2.5 million |
SAQ D for Service Providers is the only SAQ a service provider can use. Service providers also carry a testing obligation merchants do not: where segmentation reduces PCI scope, it must be penetration tested at least every six months and after any change to segmentation controls (Requirement 11.4.6), not just once a year. Our network segmentation testing service covers both the annual test and that six-monthly re-test.
The SAQ types: which one fits your payment setup
The SAQ is chosen by payment channel, not by level. Each SAQ has eligibility criteria; if you cannot confirm every criterion for a channel, you drop to a broader SAQ, and SAQ D is the one that fits everyone else. A merchant with more than one channel may need more than one SAQ, or SAQ D for the whole environment.
The scanning and testing columns show which Requirement 11 items each SAQ includes, taken from the Council’s SAQ documents for PCI DSS v4.x. Always confirm against the revision your acquirer asks for.
| SAQ | Who it is for | ASV scans (11.3.2) | Penetration testing (11.4) |
|---|---|---|---|
| A | Card-not-present merchants (e-commerce or mail and telephone order) that fully outsource all account data handling; every element of the payment page comes only and directly from a PCI DSS compliant provider, for example a full redirect to the provider’s page or the provider’s embedded form | Yes | No |
| A-EP | E-commerce merchants that outsource processing but whose own website delivers part of the payment page or controls how card data reaches the provider, for example a form on the merchant’s page that posts card data directly to the provider | Yes | Yes: methodology, external test, retest and segmentation (11.4.1, 11.4.3, 11.4.4, 11.4.5); not the internal test |
| B | Merchants using only imprint machines or standalone dial-out terminals, not connected to the internet or other systems | No | No |
| B-IP | Merchants using only standalone, PCI-approved payment terminals connected over IP to the processor, isolated from other systems | Yes | Segmentation test only (11.4.5), if segmentation isolates the terminals |
| C-VT | Merchants keying transactions one at a time into a provider-hosted virtual terminal, on an isolated computer with no card readers attached | No | No |
| C | Merchants with a payment application system and internet connection on the same device or single-store network, isolated from other systems, with no electronic card data storage | Yes, plus internal scans (11.3.1) | Segmentation test only (11.4.5), if segmentation is used |
| P2PE | Merchants using only the terminals of a validated, PCI-listed point-to-point encryption solution | No | No |
| SPoC | Merchants accepting card-present payments with PIN entry on a commercial phone or tablet, through a validated software-based solution and secure card reader | Confirm in the SAQ | Confirm in the SAQ |
| D for Merchants | Every merchant that does not meet another SAQ’s criteria, including e-commerce sites that receive card data and merchants that store it electronically | Yes, plus internal scans | Yes, in full |
| D for Service Providers | Every service provider eligible to self-assess | Yes, plus internal scans | Yes, in full, including six-monthly segmentation testing (11.4.6) |
The most common mistake in this table is between A and A-EP. If your checkout is a full redirect or the provider’s embedded form, and every element of the payment page comes from your payment provider, you are usually SAQ A. If your own site serves any element of the payment page, or posts card data to the provider directly from your page, you are usually A-EP, and A-EP brings in an external penetration test and, in practice, a web application test of the checkout.
SAQ A changed in 2025
The Council revised SAQ A in January 2025, effective 31 March 2025. The revision removed the payment-page script requirements, 6.4.3 and 11.6.1, and the related targeted risk analysis in 12.3.1 from SAQ A, and added an eligibility criterion instead: the merchant must confirm its site is not susceptible to attacks from scripts that could affect its e-commerce systems (PCI SSC on the SAQ A update). The underlying requirements still exist in PCI DSS; they simply no longer appear on SAQ A. Our PCI compliance checklist covers how 6.4.3 and 11.6.1 work for everyone else.
Which levels and SAQs need a penetration test
Your level alone never answers this. The validation document does:
- Report on Compliance (every Level 1, and anyone who chooses a ROC): the full Requirement 11.4: internal and external tests at least every 12 months and after significant change, segmentation testing where segmentation reduces scope, and a retest of exploitable findings.
- SAQ D, merchant or service provider: the full Requirement 11.4, the same as a ROC.
- SAQ A-EP: an external test, segmentation testing if used, a documented methodology and a retest. No internal test.
- SAQ B-IP and SAQ C: segmentation testing only, and only if segmentation is what keeps the rest of your network out of scope.
- SAQ A, B, C-VT and P2PE: no penetration test on the SAQ, though an acquirer or a large customer can still ask for one.
For an SAQ A-EP storefront, the test usually means an external network penetration test from $4,200 and a web application penetration test of the checkout from $5,200. For SAQ D and ROC scopes, our breakdown of PCI penetration testing cost prices each component, including internal and segmentation testing, and every test includes a free retest. The detail of each sub-requirement, including what the assessor checks in the report, is in our guide to PCI DSS penetration testing requirements.
Scans and tests are separate requirements with separate evidence: a clean ASV scan does not satisfy 11.4, and a penetration test does not replace the quarterly scan. Our comparison of an ASV scan vs a penetration test explains why.
Worked examples
These illustrative scenarios show how level and SAQ combine. Your acquirer makes the final call.
| Business | Level | SAQ | Scanning and testing |
|---|---|---|---|
| Online store, 60,000 Visa e-commerce transactions a year, checkout in the payment provider’s embedded form | Visa Level 3 | A | Quarterly ASV scans; no penetration test on the SAQ |
| The same store after moving to a checkout form on its own page that posts card data directly to the provider | Visa Level 3 | A-EP | Quarterly ASV scans, an annual external test and a checkout web application test |
| Restaurant group, 1.5 million Visa transactions a year, integrated POS across 12 connected locations | Visa Level 2 | D (SAQ C is limited to a single location) | Quarterly internal and ASV scans, annual internal and external tests, and segmentation testing if segmentation keeps the rest of the network out of scope |
| SaaS platform processing 400,000 Visa transactions a year for its customers | Visa service provider Level 1 | ROC | Full 11.4, with segmentation tested every six months if segmentation is used |
How to work out your level and SAQ
- Count transactions per brand over the last 12 months, by channel: e-commerce, card-present, mail and telephone order.
- Check each brand’s thresholds in the table above, then confirm your level with your acquirer.
- List every payment channel and how card data moves in each one, including who serves each element of the payment page.
- Match each channel to an SAQ by its eligibility criteria. If any criterion fails, move to the broader SAQ.
- Read the SAQ’s Requirement 11 rows to see which scans and tests apply, then schedule them before the attestation is due, with time to fix findings and retest.
Frequently asked questions
What are the 4 levels of PCI compliance? Mastercard and American Express each have four merchant levels, based on annual transactions with that brand. Visa now has three: Level 1 above 6 million transactions, Level 2 from 1 million to 6 million, and Level 3 below that, with the former Level 4 folded into Level 3.
Is PCI compliance required for Level 4 merchants? Yes. Every merchant that accepts card payments must comply with PCI DSS. Level 4 only changes how, or whether, you report compliance, and your acquirer decides what you submit.
Who decides my merchant level? Each card brand sets the thresholds and your acquirer applies them. If you have processed a large one-off volume or merged with another business, ask the acquirer to confirm your level rather than assuming it.
What is the difference between SAQ A and SAQ A-EP? Who delivers the payment page. Under SAQ A every element of it comes only and directly from your PCI compliant provider. Under A-EP your own website delivers part of it or controls how card data reaches the provider, so your site’s security affects the transaction, and the SAQ adds requirements including an external penetration test.
Does SAQ D require a penetration test? Yes. SAQ D for Merchants and SAQ D for Service Providers both include Requirement 11.4 in full: internal and external tests at least annually and after significant change, segmentation testing where used, and a retest of exploitable findings.
Can a Level 1 merchant self-assess? Not with an SAQ. Visa allows the Level 1 Report on Compliance to be completed by an internal resource if an officer of the company signs it; otherwise a QSA performs it.
Can Invadel handle the scans and the assessment as well as the test? Yes. We deliver the quarterly ASV scans, the Requirement 11.4 penetration test and, where you validate with a ROC, the ROC assessment, on one calendar. The penetration test is still scoped and reported on its own, at a fixed price with a free retest.
Not sure which SAQ your checkout puts you in? Send us your payment setup and we will map it to the SAQ and the testing it requires before you commit to anything.
Written by
Invadel Team
Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →