Reference
Payment Certification Levels
A practical guide to EMVCo L1 / L2 / L3 terminal certifications, PCI DSS merchant compliance tiers, and the standards that govern every card-present transaction.
PCI DSS Merchant Compliance Levels
The Payment Card Industry Data Security Standard (PCI DSS) defines four merchant tiers based on annual transaction volume. The level determines the validation method required — from a simple SAQ to a full on-site audit by a Qualified Security Assessor.
Level 1More than 6 million transactions/year
Also applies to any merchant that has experienced a data breach, regardless of volume.
- Annual on-site audit by a QSA (Qualified Security Assessor)
- Report on Compliance (ROC) submitted to acquirer
- Quarterly network scan by an ASV (Approved Scanning Vendor)
- Annual penetration test
- Attestation of Compliance (AOC) form
Level 21 million – 6 million transactions/year
- Annual SAQ (Self-Assessment Questionnaire)
- Quarterly ASV network scan
- QSA audit may be required by some networks
- AOC form
Level 320,000 – 1 million e-commerce transactions/year
- Annual SAQ
- Quarterly ASV network scan
- AOC form
Level 4Fewer than 20,000 e-commerce OR fewer than 1 million all other transactions/year
- Annual SAQ (required by most acquirers)
- Quarterly ASV scan (recommended)
- AOC form (acquirer-dependent)
SAQ Types at a Glance
| SAQ | Who it applies to | Questions |
|---|---|---|
A | Card-not-present, fully outsourced payment page (iFrame / redirect) | ~22 |
A-EP | E-commerce site that partially controls the payment flow | ~191 |
B | Card-present, imprint-only or standalone dial-out terminals | ~41 |
B-IP | Standalone IP-connected terminals (no electronic cardholder data) | ~83 |
C | POS with payment app connected to internet; no storage of CHD | ~160 |
C-VT | Virtual terminal on a dedicated computer; no electronic CHD storage | ~73 |
D | All other merchants; service providers use D-SP | ~329 |
P2PE | Merchants using a PCI-validated P2PE solution | ~35 |
Visa vs. Mastercard levels differ slightly. Visa and Mastercard publish independent level definitions. The thresholds above reflect Visa's programme; Mastercard levels use the same tier names but apply different volume criteria for some tiers. Always confirm requirements with your acquiring bank.
Related Tools
Use these tools to work with the cryptographic primitives that underpin terminal and card security.