Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

PCI Compliance Levels Explained: Which Merchant Level Are You?

July 14, 2026

Understanding the PCI compliance levels is the first step to securing your payment systems without wasting time on paperwork that does not apply to you. The Payment Card Industry Data Security Standard (PCI DSS) uses a tiered system to classify businesses based on their annual payment card transaction volume.

This framework ensures that the compliance burden matches the actual risk: the more transactions you process, the more scrutiny you face. A massive global retailer processing millions of transactions goes through mandatory on-site audits. A local Chicagoland shop handling a few dozen payments a day qualifies for a much lighter self-assessment process.

The PCI Security Standards Council is the governing body that creates and maintains these rules. It was founded by the major card brands, including Visa, Mastercard, American Express, Discover, and JCB, which require any business that accepts, processes, stores, or transmits payment card data to protect that information. This obligation applies regardless of your business size or transaction volume. it is enforced through the merchant agreement you sign with your payment processor or acquiring bank.

For most small and mid-sized business owners, the compliance process feels overwhelming until they realize where they actually fall on the tier list. Your PCI merchant level is tied directly to your merchant account, if you accept credit cards through a merchant account, you already have a PCI merchant level assigned. There is no separate registration process.

Key Takeaways

  • Most Illinois small and mid-sized businesses are PCI Level 4 merchants (fewer than 20,000 e-commerce transactions or up to 1 million total transactions a year) and validate compliance with a Self-Assessment Questionnaire instead of a costly on-site audit.
  • The card brands sort merchants into four levels by annual transaction volume: Level 1 (over 6 million), Level 2 (1 to 6 million), Level 3 (20,000 to 1 million e-commerce), and Level 4 (under 20,000 e-commerce or up to 1 million total).
  • PCI DSS is not a government law. It is a contractual obligation enforced through your merchant agreement, and non-compliance brings monthly fees plus, after a breach, a mandatory forensic investigation and possible loss of card-processing privileges.
  • Which SAQ you complete depends entirely on how you accept payments, ranging from SAQ A for fully outsourced card-not-present transactions to SAQ D for everyone else.
  • LeadingIT operates the technical half of PCI compliance (network segmentation, MFA, logging, patching) for Chicagoland businesses, though we are not a QSA or ASV and do not certify compliance.

What Are the 4 PCI Compliance Levels?

The major card brands tier merchants by annual transaction volume. While each brand maintains slightly different definitions and thresholds, they generally align on a standard four-level system. The commonly used Visa and Mastercard tiering provides the clearest picture of the merchant levels for PCI compliance.

LevelAnnual Transaction VolumeValidation MethodAudit / Scan Requirement
Level 1Over 6 million card transactions per yearOn-site assessment by a Qualified Security Assessor (QSA), producing a Report on Compliance (ROC)Quarterly ASV scans, plus a signed Attestation of Compliance (AOC)
Level 21 to 6 million card transactions per yearSelf-Assessment Questionnaire (often SAQ D)Quarterly ASV scans, plus a signed AOC
Level 320,000 to 1 million e-commerce transactions per yearSelf-Assessment Questionnaire matched to how the site handles paymentsQuarterly ASV scans, plus a signed AOC
Level 4Fewer than 20,000 e-commerce transactions, or up to 1 million total transactions per yearSelf-Assessment QuestionnaireASV scans only if payment systems connect to the internet or the acquirer requires them

How to Identify Your Merchant Level

The table shows the thresholds, but how do you figure out which level applies to your business? The process is straightforward:

  1. Check your annual transaction count. Log into your payment processor portal or your acquirer’s reporting dashboard. Look for total transaction volume over the last 12 months. Most processors display this prominently on the account summary screen.
  2. Compare against the thresholds above. Count all card transactions across every channel: in-person, online, and over the phone. If your e-commerce transactions are under 20,000 and your total card volume is under 1 million, you are Level 4.
  3. Confirm with your acquirer’s annual notice. Your acquiring bank sends a yearly notification stating your assigned level and which SAQ to complete. This notice is the authoritative word. If the bank says Level 3 but your count says Level 4, the bank’s determination controls.

Your acquiring bank is the financial institution that provides your merchant account. They are the ultimate authority on which level applies to your business and what specific documentation they require you to submit each year.

PCI Level 1 Merchant

This is the highest tier with the most stringent validation requirements. A pci level 1 merchant is typically a global retailer, a major airline, or a massive e-commerce marketplace. The card brands can also escalate a merchant of any size to a higher validation level if that business suffers a data breach that compromises cardholder data.

Level 1 merchants cannot simply fill out a self-assessment. They must hire a Qualified Security Assessor (QSA). A QSA is an independent auditor certified by the PCI Security Standards Council. The QSA conducts a thorough on-site assessment of the merchant’s security controls and produces a formal Report on Compliance (ROC).

In addition to the annual ROC, Level 1 merchants must have an Approved Scanning Vendor (ASV) perform external vulnerability scans of their network every quarter. They must also submit an Attestation of Compliance (AOC) signed by an executive officer and the QSA to their acquiring bank.

PCI Level 2 Merchant

The second tier covers mid-sized companies that handle a significant volume of card payments.

The pci compliance level requirements for Level 2 offer a break from the mandatory on-site QSA audit, but the security expectations remain high. Level 2 merchants validate their compliance by completing an annual Self-Assessment Questionnaire (SAQ). Because of their size and complexity, many Level 2 merchants must complete SAQ D, which is the longest and most comprehensive version of the questionnaire.

Like Level 1, these merchants must also engage an Approved Scanning Vendor to perform quarterly external network scans. They complete their validation by submitting an AOC signed by a company officer to their acquirer.

PCI Level 3 Merchant

Level 3 is a specific tier aimed primarily at mid-sized e-commerce businesses. The validation requirements for Level 3 are virtually identical to Level 2. The distinction exists mostly for the card brands to track risk specifically within the e-commerce sector. Level 3 merchants must complete the appropriate annual SAQ based on how their website handles payments. They must also pass quarterly ASV scans and submit a signed AOC.

PCI Level 4 Merchant

If you run a small or mid-sized business in Illinois, you are almost certainly a pci level 4 merchant. Most local restaurants, retail shops, contractors, and professional services firms fit comfortably into this category.

This is the most manageable of the PCI DSS compliance levels. Level 4 merchants validate their compliance annually using a Self-Assessment Questionnaire. Depending on how you accept payments, you might qualify for one of the shorter SAQ versions, which drastically reduces your compliance paperwork. Quarterly ASV scans are only required if your payment systems connect to the internet or if your acquirer specifically mandates them.

Merchant Levels vs. Service Provider Levels

It is important to understand the difference between merchant levels and the separate pci compliance levels for service providers.

AttributeMerchantService Provider
Who they areA business that accepts card payments directly from customers for goods or servicesA third-party company that stores, processes, or transmits cardholder data on behalf of another business
ExamplesRetailers, restaurants, e-commerce stores, contractorsPayment gateways, managed security providers, web hosting companies
Who sets the tierAcquiring bank or payment processorCard brands and the PCI Security Standards Council
How they validateSAQ or QSA audit, depending on volume levelSAQ D for Service Providers or full QSA audit, depending on volume
Your responsibilityYou only need to worry about your own merchant levelYou are responsible for ensuring that any service provider you use is fully PCI DSS compliant

Service providers operate under their own distinct tier system based on transaction volume. The highest-volume service providers must undergo a full on-site QSA audit and produce a Report on Compliance, just like Level 1 merchants. Lower-volume service providers can typically validate their compliance using a specific self-assessment known as SAQ D for Service Providers.

The Level 4 Reality for Chicagoland SMBs

Knowing the PCI compliance levels is just the beginning. The real work is understanding what Level 4 actually requires of your business. Here is the full Level 4 compliance journey, end to end:

  1. Determine your merchant level. Confirm with your acquirer that you fall under Level 4 based on your annual transaction count.
  2. Define your CDE scope. Map every system, person, and process that touches cardholder data, then shrink that boundary through network segmentation.
  3. Choose the correct SAQ. Match your payment acceptance method to the right Self-Assessment Questionnaire type.
  4. Implement the 12 requirements. Build and maintain the security controls the standard demands across all in-scope systems.
  5. Submit to your acquirer. Upload your completed SAQ, AOC, and any required ASV scan results through your acquirer’s compliance portal.

The current version of the standard is PCI DSS 4.0.1 (which superseded 4.0, while the older version 3.2.1 was retired on March 31, 2024). The future-dated requirements introduced with version 4.0 became mandatory on March 31, 2025.

Here is what Level 4 compliance looks like in practice for your business.

Your Acquirer Sets the Rules

PCI compliance is not a government law in the US. It is a strict contractual obligation. Your acquiring bank or payment processor enforces the rules. They will notify you of your level, tell you which documents to submit, and provide the portal for you to upload your SAQ.

If you ignore these requirements, the consequences flow directly through your processor. This usually starts with non-compliance fees added to your merchant account statement, with the amount and schedule set by your processor’s contract. If you suffer a data breach while non-compliant, the penalties escalate rapidly:

  • Mandatory forensic investigation
  • Card-brand assessments passed through your acquirer
  • Card reissuance costs
  • Higher processing rates
  • Potential total loss of your ability to accept credit cards

Defining Your Cardholder Data Environment (CDE)

Before you can secure your data, you have to know where it lives. The cardholder data environment (CDE) is the complete set of systems, people, and processes that store, process, or transmit cardholder data, plus any system connected to them.

Cardholder data includes the primary account number (PAN), the cardholder name, the expiration date, and the service code. There is also sensitive authentication data, which includes the CVV or CVC security code, the full magnetic-stripe data, and PINs.

You may NEVER store sensitive authentication data after authorization is complete, even if it is encrypted.

The size of your CDE dictates the scope of your compliance effort. Proper network segmentation (isolating your payment terminals from your main guest Wi-Fi and back-office computers) can drastically shrink your CDE. A smaller CDE means fewer systems have to meet the strict PCI DSS requirements.

Choosing the Right SAQ

Most Level 4 merchants validate their compliance using a Self-Assessment Questionnaire. The PCI Security Standards Council offers several different SAQ types. The one you must use depends entirely on how you take payments.

How You Take PaymentsSAQ Type
Card-not-present, fully outsourced all payment processing to a validated third partySAQ A
E-commerce, outsources payment processing but has a website that could affect the security of the payment pageSAQ A-EP
Only imprint machines or standalone dial-out terminals with no electronic data storageSAQ B
Standalone IP-connected terminalsSAQ B-IP
Payment application systems connected to the internetSAQ C
Manually enters single transactions via a virtual terminal on a computerSAQ C-VT
Validated point-to-point encryption hardware solutionsSAQ P2PE
Everyone else, who does not meet the strict criteria of the other formsSAQ D

Meeting the 12 Core Requirements

Filling out the SAQ is just the reporting phase. The actual compliance work involves implementing the security controls that the questionnaire asks about. PCI DSS is organized into 12 distinct requirements grouped under 6 broader goals.

  1. Install and maintain network security controls. You must have properly configured firewalls to protect your cardholder data environment from unauthorized network traffic.
  2. Apply secure configurations. You must change all default passwords and security parameters provided by vendors before installing any system on your network.
  3. Protect stored account data. If you must store the primary account number, it must be rendered unreadable through strong encryption or tokenization.
  4. Protect cardholder data with strong cryptography in transit. Card data must be encrypted when it travels over open, public networks like the internet.
  5. Protect systems against malware. You must deploy and regularly update anti-virus software on all systems commonly affected by malicious software.
  6. Develop and maintain secure systems and software. You must protect your systems from known vulnerabilities by installing security patches provided by vendors in a timely manner.
  7. Restrict access by business need-to-know. Only employees who absolutely need access to cardholder data to do their jobs should have it.
  8. Identify users and authenticate access. Every user must have a unique ID. You must also enforce multi-factor authentication (MFA) for all access into the cardholder data environment.
  9. Restrict physical access to cardholder data. You must control physical access to servers, paper records, and payment terminals to prevent tampering or theft.
  10. Log and monitor all access. Track and monitor all access to network resources and cardholder data. This lets you detect anomalies and investigate incidents when something looks off.
  11. Test security regularly. You must regularly test your security systems and processes. This includes quarterly external vulnerability scans by an Approved Scanning Vendor if applicable, as well as penetration testing.
  12. Maintain an information security policy. You must establish, publish, maintain, and disseminate a security policy that addresses information security for all personnel.

How LeadingIT Helps

Managing firewalls, enforcing MFA, patching systems, and remediating failed ASV scans takes significant technical expertise. LeadingIT is a Chicagoland managed it and cybersecurity provider that has helped Illinois businesses since 2010. We serve roughly 200 organizations and over 2,500 users from our offices in Woodstock and Manteno.

We operate the technical half of PCI compliance as part of our managed IT services. We handle the network segmentation, the logging, and the security controls required by the 12 requirements. We also help you answer the technical questions on your SAQ correctly.

While LeadingIT is NOT a QSA or ASV and does not certify PCI compliance, we help you become and stay compliant so you can confidently submit your paperwork to your acquirer.

See Where You Stand

Free 2-minute PCI self-check: 8 plain-English questions, your risk level and the exact gaps to fix. No sign-up to see your result. free PCI compliance checklist

Frequently Asked Questions

Do small companies really need the Payment Card Industry Data Security Standard, or is PCI DSS only for big businesses?

PCI DSS applies to any business that accepts, processes, stores, or transmits payment card data, regardless of size or transaction volume. It is not a government law, but a contractual obligation enforced through the merchant agreement with your payment processor. If you take credit cards, you must comply with the standard.

What is PCI Compliance? A Simple Guide for Businesses

PCI compliance is a set of security standards created by the major card brands to protect cardholder data from theft and fraud. Businesses achieve compliance by implementing 12 core security requirements, such as using firewalls, encrypting data, and restricting access. Most small businesses prove they are following these rules by submitting an annual Self-Assessment Questionnaire to their bank.

Explain to me like I’m 5 PCI compliance

PCI compliance is a set of safety rules created by credit card companies. If you want to accept credit cards at your store, you have to promise to keep your customers’ card numbers locked up and safe from hackers. You prove you are following the rules by filling out a checklist every year and showing it to your bank.

How many companies lie on their compliance paperwork?

While exact numbers are impossible to track, many businesses unintentionally provide inaccurate answers on their Self-Assessment Questionnaires due to a lack of technical understanding. Falsifying compliance documents is dangerous because if a breach occurs, a mandatory forensic investigation will quickly reveal the missing security controls. This leads to severe financial penalties and the potential loss of card processing privileges.

For those of you dealing with PCI compliance, did SAQ A change under the new PCI DSS rules?

The transition to PCI DSS version 4.0.1 introduced significant changes across all SAQ types, including SAQ A. The future-dated requirements from version 4.0 officially became mandatory on March 31, 2025. Businesses must ensure they are using the most current version of the questionnaire and meeting the updated security controls.

Secure Your Business and Simplify Compliance

Navigating the PCI-DSS levels of compliance does not have to drain your time or resources. Once you know your level, the path forward is simply about putting the right it controls in place and maintaining them year-round. LeadingIT handles the technical heavy lifting of PCI compliance services so you can focus on running your business.

If you are tired of guessing on your SAQ or struggling to pass vulnerability scans, we can help. Book a call to speak with our team or contact us to get started.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.