Skip to Content
Category Criteria Requirements Compliance date
Level 1
  • Any merchant that has suffered a hack or an attack that resulted in an account data compromise
  • Any merchant having more than six million total combined Mastercard and Maestro transactions annually
  • Any merchant meeting the Level 1 criteria of Visa
  • Any merchant that Mastercard, in its sole discretion, determines should meet the Level 1 merchant requirements to minimize risk to the system
  • Annual Onsite Assessment1
  • Quarterly Network Scan conducted by an ASV2

30 June 20123

Level 2
  • Any merchant with more than one million but less than or equal to six million total combined Mastercard and Maestro transactions annually
  • Any merchant meeting the Level 2 criteria of Visa
  • Annual Self-Assessment4
  • Onsite Assessment at Merchant Discretion4
  • Quarterly Network Scan conducted by an ASV2

30 June 20124

Level 3
  • Any merchant with more than 20,000 combined Mastercard and Maestro e-commerce transactions annually but less than or equal to one million total combined Mastercard and Maestro e-commerce transactions annually
  • Any merchant meeting the Level 3 criteria of Visa
  • Annual Self-Assessment
  • Quarterly Network Scan conducted by an ASV2

30 June 2005

Level 4
  • All other merchants5
  • Annual Self-Assessment
  • Quarterly Network Scan conducted by an ASV2

Consult Acquirer

Visit pcisecuritystandards.org for the most updated information

  1. Effective 30 June 2012, Level 1 merchants that choose to conduct an annual onsite assessment using an internal auditor must ensure that primary internal auditor staff engaged in validating PCI DSS compliance attend PCI SSC ISA Training and pass the associated accreditation program annually in order to continue to use internal auditors.
  2. Quarterly network scans must be conducted by a PCI SSC Approved Scanning Vendor (ASV).
  3. Initial compliance date of June 2005 for Level 1 merchants has now passed. The 30 June 2012 deadline is for PCI SSC ISA training and certification only and is for those merchants that choose to conduct an annual onsite assessment using an internal auditor.
  4. Effective 30 June 2012, Level 2 merchants that choose to complete an annual self-assessment questionnaire must ensure that staff engaged in the self-assessment attend PCI SSC ISA Training and pass the associated accreditation program annually in order to continue the option of self-assessment for compliance validation. Alternatively, Level 2 merchants may, at their own discretion, complete an annual onsite assessment conducted by a PCI SSC approved Qualified Security Assessor (QSA) rather than complete an annual self-assessment questionnaire.
  5. Level 4 merchants are required to comply with the PCI DSS. Level 4 merchants should consult their acquirer to determine if compliance validation is also required.