Merchant levels

PCI merchant levels: Visa has three, Mastercard has four

There is no single PCI level taxonomy, and since April 2024 there is not even a shared number of tiers. Your level sets your assessment route, and the route is what costs money. Both brands' thresholds below are quoted from their own current rulebooks.

Brand rules checked 17 July 2026 · Updated July 2026

Visa: three levels

Thresholds as printed in Visa's What To Do If Compromised v10.0. Visa adds that the full criteria live in its AIS Program Guide, which it does not publish.

LevelThresholdValidation
Level 1More than 6,000,000 Visa transactions a yearAnnual on-site assessment producing a Report on Compliance
Level 21,000,001 to 6,000,000 Visa transactions a yearAnnual self-assessment questionnaire, unless the acquirer requires more
Level 31 to 1,000,000 Visa transactions a year. Since 25 April 2024 this tier also contains every merchant Visa used to call level 4Annual self-assessment questionnaire; validation set by the acquirer

Mastercard: four levels

Quoted from Mastercard Security Rules and Procedures, Merchant Edition, 3 February 2026, section 2.2.2. Mastercard publishes its criteria in full.

LevelThresholdValidation
Level 1More than six million total combined Mastercard and Maestro transactions annually, or any merchant meeting Visa's Level 1 criteria, or any merchant Mastercard designates (which may include any merchant with a confirmed compromise)Annual assessment producing a ROC Attestation of Compliance signed by a QSA, a certified ISA, or an executive officer of the merchant
Level 2More than one million but up to six million total combined Mastercard and Maestro transactions annually, or any merchant meeting Visa's Level 2 criteriaAnnual SAQ. Merchants completing SAQ A, SAQ A-EP or SAQ D must additionally engage a QSA or certified ISA for validation. A ROC may be done instead by choice
Level 3More than 20,000 but up to one million total combined Mastercard and Maestro e-commerce transactions annually, or any merchant meeting Visa's Level 3 criteriaAnnual SAQ required, but validation of compliance to Mastercard is not required. A ROC may be done instead by choice
Level 4Any merchant not deemed to be Level 1, Level 2 or Level 3Compliance with PCI DSS is required, but validation to Mastercard is not required except where law or regulation demands it. A merchant may validate by completing an annual SAQ

What each level means in practice

The assessment route is the part that matters, because it is what your money and your quarter go on.

LevelVolumeAssessment routeRealistic timeline
Level 1Over 6 million transactions per year (both brands)Report on Compliance (ROC), signed by a QSA, a certified ISA, or an executive officerMonths, not weeks. Scope drives everything
Level 21,000,001 to 6 million transactions per year (both brands)Annual SAQ. Under Mastercard, SAQ A, A-EP or D must also be validated by a QSA or certified ISAWeeks to months, depending on SAQ type
Level 3Visa: 1 to 1,000,000 a year, having absorbed the old level 4 on 25 April 2024. Mastercard: 20,000 to 1 million e-commerceSAQ + quarterly ASV scansWeeks, if your SAQ type is a simple one
Level 4 (Mastercard only)Any merchant Mastercard does not deem Level 1, 2 or 3. Retired by Visa on 25 April 2024SAQ (type depends on payment acceptance method)Days to weeks for the simplest SAQ types

No annual cost column, deliberately. No card brand, QSA, acquirer or pen test firm publishes a price list for PCI compliance work, and only one ASV publishes any price at all. So this site does not print cost bands for that work: a range for a price nobody discloses would be a guess, and labelling a guess an estimate does not make it true. What you get instead is what each line is priced against, so you can go and get a real number from the only people who have one, and a calculator that does the arithmetic using rates you supply from your own quotes. Where a real published price does exist, such as the compliance platform list prices on AWS Marketplace or SecurityMetrics' published small-business bundle, we quote it to the source and say when we checked it.

Level 4

Level 4 (Mastercard only)

Any merchant Mastercard does not deem Level 1, 2 or 3. Retired by Visa on 25 April 2024

Still a live Mastercard classification, and no longer a Visa one. Compliance with PCI DSS is required here even though validation to Mastercard is not, and that gap is invisible until a breach. Hosted payment solutions cut the work more than anything else you can do.

Assessment
SAQ (type depends on payment acceptance method)
QSA required
Not by definition, though your acquirer may insist
Timeline
Days to weeks for the simplest SAQ types
Biggest lever
Keeping card data off your own servers

Level 3

Level 3

Visa: 1 to 1,000,000 a year, having absorbed the old level 4 on 25 April 2024. Mastercard: 20,000 to 1 million e-commerce

The tier that changed. Every merchant Visa used to call level 4 is a Visa level 3 merchant now, with no change to what PCI DSS asks of it, which Visa stated explicitly. Mastercard's level 3 still means something narrower. For e-commerce, requirement 6.4.3 on payment page scripts is the newest real cost.

Assessment
SAQ + quarterly ASV scans
QSA required
Not by definition, though your acquirer may insist
Timeline
Weeks, if your SAQ type is a simple one
Biggest lever
Keeping card data off your own servers

Level 2

Level 2

1,000,001 to 6 million transactions per year (both brands)

Mastercard's published rule is the one that surprises people: at this level, an SAQ A, A-EP or D must be validated by a QSA or a certified ISA. Self-assessment is not necessarily self-service. Your acquirer may separately require a full ROC.

Assessment
Annual SAQ. Under Mastercard, SAQ A, A-EP or D must also be validated by a QSA or certified ISA
QSA required
Not by definition, though your acquirer may insist
Timeline
Weeks to months, depending on SAQ type
Biggest lever
Your SAQ type, because of Mastercard's QSA rule

Level 1

Level 1

Over 6 million transactions per year (both brands)

The largest merchants, plus anyone Mastercard designates. Mastercard may deem any merchant a Level 1 merchant at its sole discretion, which expressly includes any merchant with a confirmed compromise, whatever its volume. A breach can promote a small merchant here overnight.

Assessment
Report on Compliance (ROC), signed by a QSA, a certified ISA, or an executive officer
QSA required
A ROC is required. Mastercard permits it to be signed by a QSA, a certified ISA, or an executive officer of the merchant
Timeline
Months, not weeks. Scope drives everything
Biggest lever
Scope. Every in-scope system is testable surface

What pushes a merchant up a level

You do not need to grow into a higher level for it to apply. Three of the four routes below have nothing to do with your transaction count.

TriggerConsequenceSource
Transaction growth across a thresholdMastercard requires the merchant to reach the new level's requirements as soon as practical and in any event within one year of the event that caused the transition.Mastercard SPME 2.2.2
A confirmed compromiseMastercard may deem the merchant Level 1 regardless of volume, which forces an annual ROC. Visa may separately require a forensic investigation on a five business day clock.Mastercard SPME 2.2.2; Visa WTDIC v10.0 section 5
Your SAQ type, under Mastercard's Level 2 ruleA Level 2 merchant completing SAQ A, SAQ A-EP or SAQ D must additionally engage a QSA or a certified ISA for validation. The questionnaire stays, the assessor arrives anyway.Mastercard SPME 2.2.2
Your acquirer's own risk decisionYour acquirer decides what evidence it accepts, under your merchant agreement. It can require a ROC where the brand rules would allow an SAQ. This is contract, not standard.Merchant agreement

Need an independent assessment?

Our partner network includes QSAs and ISAs across all merchant levels. Costs vary by scope and QSA fees are quoted independently. We do not endorse a specific firm.

Find a QSA in the PCI SSC directory

Frequently asked

It depends which brand you ask, and since April 2024 they no longer give the same answer. Visa runs three levels: over 6 million transactions a year is level 1, 1,000,001 to 6 million is level 2, and 1 to 1,000,000 is level 3. Mastercard runs four: over six million combined Mastercard and Maestro transactions is Level 1, over one million up to six million is Level 2, over 20,000 up to one million e-commerce transactions is Level 3, and anything else is Level 4. So a small merchant is a Visa level 3 merchant and a Mastercard Level 4 merchant at the same time. Your acquirer can also move you up, and Mastercard may designate any merchant Level 1 at its sole discretion.

Continue reading