Terminology Index

Glossary

2953 terms

Open concept maps
P
32

PCI Merchant Levels

The tiers that classify organizations by payment-card transaction volume, determining how rigorously they must validate PCI DSS compliance, from self-assessment for smaller merchants to full external assessment for the largest.

PCI DSS sorts merchants into levels based on annual card transaction volume (and risk history). The level dictates the validation method: the largest merchants undergo a full on-site assessment by a Qualified Security Assessor with quarterly scans, while smaller ones may use a self-assessment questionnaire. Understanding merchant levels clarifies what a given organization must actually do to demonstrate PCI compliance, scaling the assurance burden to transaction volume and risk.

Introduced in: Security Frameworks and Control Mapping

Examples

  • A high-volume merchant requiring a full QSA assessment.
  • A small merchant validating via a self-assessment questionnaire.
  • Determining validation obligations from the organization's merchant level.