Contents
What are the levels of PCI compliance?
Level 1: Merchants that process over 6 million card transactions annually. Level 2: Merchants that process 1 to 6 million transactions annually. Level 3: Merchants that process 20,000 to 1 million transactions annually. Level 4: Merchants that process fewer than 20,000 transactions annually.
How many levels are there for merchants?
The PCI DSS (Payment Card Industry Data Security Standard) merchant levels are rankings of merchant transactions per year broken down into four levels. The payment card industry (PCI) uses merchant levels to determine risk from fraud and to ascertain the appropriate level of security for their businesses.
What is a Level 2 merchant?
Payment Card Industry Data Security Standard (PCI DSS) Level 2 merchants are those that process between 1 and 6 million Visa, Mastercard, and Discover transactions per year; 50,000 to 2 million sales using American Express, and fewer than 1 million JCB International credit card transactions.
Who defines merchant and service provider levels?
Compli- ance levels for merchants and service providers are defined based on annual transaction volume and corresponding risk exposure: The PCI Data Security Standard requirements apply to all payment card network members, merchants and service providers that store, process or transmit cardholder data.
Who determines merchant transaction volume?
Transaction volumes: Each acquirer determines merchant transaction volumes, and they are generally based on the aggregate number of transactions for a merchant. However, the Card Brand policy varies according to each individual brand and/or their acquirers.
What are the merchant levels for PCI compliance?
Merchant Level. 1. Any merchant that processes over 6 million Visa transactions per year as well as the merchants Visa determines should meet Level 1 requirements to minimize risk. 2. Any merchant that processes 1 to 6 million Visa transactions per year.
When does PCI Level 4 need to be applied?
PCI Level 4 applies to merchants that handle less than 20,000 e-commerce transactions per year, or merchants that process up to one million transactions through all channels (card present, card not present, e-commerce).
How to know if your merchant has PCI DSS?
All other merchants4 Annual Self-Assessment Questionnaire (SAQ)3 Level 1 merchants must undergo an annual PCI DSS assessment resulting in the completion of a ROC conducted by a PCI SSC-approved Qualified Security Assessor (QSA) or PCI SSC-certified Internal Security Assessor (ISA).
What does it mean to be compliant with PCI?
The PCI compliance level defines what an organization must do to stay compliant and what requirements it must meet. Four PCI compliance levels classify merchants over 12 months based on the total volume of credit, debit card, and prepaid card transactions.