Skip to content
English - United States
  • There are no suggestions because the search field is empty.

What Are the PCI Compliance Levels and SAQs?

Merchant level is set by transaction volume. The SAQ you file depends on how you take payments.

PCI merchant levels are set by how many card transactions you process per year and determine how you must validate compliance. The Self-Assessment Questionnaire (SAQ) type is set by how you accept payments and determines which requirements you must answer to. Most small and mid-sized businesses are Level 4 and file one SAQ annually.

Merchant levels

  • Level 1: more than 6 million card transactions per year (any channel). Requires an annual on-site assessment by a Qualified Security Assessor and quarterly network scans.
  • Level 2: 1 million to 6 million transactions per year. Annual SAQ and quarterly scans.
  • Level 3: 20,000 to 1 million e-commerce transactions per year. Annual SAQ and quarterly scans.
  • Level 4: fewer than 20,000 e-commerce transactions, or up to 1 million transactions in total, per year. Annual SAQ; scans as required by the SAQ type and your processor.

Levels are defined per card brand and can be raised after a breach. Your card processor tells you your level.

The common SAQ types

  • SAQ A: card-not-present merchants who fully outsource payment processing (for example, a hosted payment page) and store no card data. The shortest questionnaire.
  • SAQ A-EP: e-commerce merchants whose website affects the security of the payment page even though a third party processes it.
  • SAQ B: imprint machines or standalone dial-out terminals, no electronic storage.
  • SAQ B-IP: standalone IP-connected payment terminals.
  • SAQ C-VT: merchants keying transactions into a web-based virtual terminal.
  • SAQ C: payment applications connected to the internet, no electronic card storage.
  • SAQ P2PE: merchants using a validated point-to-point encryption solution.
  • SAQ D: everyone else, including merchants who store card data. The longest questionnaire.

Why scope is everything

The SAQ you qualify for depends on how much of your environment touches card data. Moving from a payment application on your office network (SAQ C or D) to validated terminals or a hosted page (SAQ B-IP or A) can cut the requirements dramatically. Network segmentation does the same for the systems that remain.

Mentis Group's PCI compliance services in Dallas-Fort Worth start with scoping for exactly this reason. See what is PCI compliance for the standard and how much PCI compliance costs for the money side. Level and SAQ definitions are published by the PCI Security Standards Council and the card brands.

Have a question about your own environment? Schedule a consultation with Mentis Group or call (866) 901-7808.