PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Glossary · PCI DSS v4.0.1

Merchant levels — Validation levels

Merchant levels are set by the payment brands, not by PCI SSC, and determine how compliance must be validated. Level 1 merchants require a Report on Compliance; lower levels may be eligible to self-assess.

What it means in practice

Visa and Mastercard place merchants above roughly six million transactions a year at Level 1; thresholds and definitions differ per brand and per region.
Any merchant can be designated Level 1 by a payment brand, and a compromise can trigger reassignment.
Service providers have their own levels; Level 1 service providers require a Report on Compliance and SAQ D for Service Providers is limited to Level 2.

Not sure how this affects your assessment?

The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Definitions paraphrased from the PCI DSS v4.0.1 standard and the PCI SSC Glossary of Terms, Abbreviations and Acronyms. Independent summary; not endorsed by PCI SSC.