Level Up Your Business Today
Join the thousands of people like you already growing their businesses and knowledge with our team of experts. We deliver timely updates, interesting insights, and exclusive promos to your inbox.
Join For Free💳 Save money on credit card processing with one of our top 5 picks for 2024
Do you know your PCI compliance level? It's important that merchants understand their PCI level in order to satisfy PCI compliance requirements.
There are four separate levels of PCI compliance, called the PCI Merchant Risk Level System. These PCI levels are based on the total number of credit card transactions your business processes annually. Your risk for a data breach goes up as you process more transactions, requiring additional steps to maintain PCI compliance.
Knowing which PCI compliance level you fall under is critically important because your processor will require different documentation and procedures for each one. Fortunately, determining which risk level your business falls under is easy and straightforward.
For a rundown of some of our favorite providers, check out our list of the best credit card processors for small businesses.
Your business’s PCI compliance level depends on how many retail and eCommerce transactions you process per year. Most merchants fall into level 4. Note that your level depends on the number of transactions processed per year, not the dollar amount of your transactions.
PCI Level 4 | PCI Level 3 | PCI Level 2 | PCI Level 1 | |
---|---|---|---|---|
Annual Transaction Volume (eCommerce) | Less than 20,000 | 20,000-1,000,000 | N/A | N/A |
Annual Transaction Volume (All Sales Channels) | Up to 1,000,000 | N/A | 1,000,000-6,000,000 | More than 6,000,000 |
Once you find your merchant risk level, you must take certain actions, directly related to your particular level, in order to maintain PCI compliance. Not adhering to those guidelines can result in expensive PCI noncompliance fees or even a data breach.
If you slack on maintaining your PCI compliance level requirements and your small business experiences a security breach, not only will it put you and your customers at risk, but it may also result in your business being placed in a much more restrictive PCI level (Level 1).
Below, we’ll discuss the criteria and compliance requirements for all four merchant risk levels. We’ll start with merchant level 4 and work our way up, as level four has the least stringent requirements and applies to the smallest businesses.
For even more information on what businesses need to do to maintain PCI compliance, read our complete guide to PCI DSS compliance.
We can’t emphasize enough the importance of avoiding an actual data breach. For smaller merchants, the additional costs of suffering a breach and being placed in the Level 1 compliance category could be a serious threat to the health of your business.
We’d also like to remind you that some providers offer a more robust set of features designed to safeguard your account and keep you in compliance than others. Choosing a good provider is critically important, not just for PCI compliance but also for protecting your business from chargebacks and other problems.
Get in touch with a real human being on the Merchant Maverick team! Send us your questions, comments, reviews, or other feedback. We read every message and will respond if you'd like us to.
Reach OutGet in touch with a real human being on the Merchant Maverick team! Send us your questions, comments, reviews, or other feedback. We read every message and will respond if you'd like us to.
Reach OutLet us know how well the content on this page solved your problem today. All feedback, positive or negative, helps us to improve the way we help small businesses.
Give Feedback
Want to help shape the future of the Merchant Maverick website? Join our testing and survey community!
By providing feedback on how we can improve, you can earn gift cards and get early access to new features.
Help us to improve by providing some feedback on your experience today.
The vendors that appear on this list were chosen by subject matter experts on the basis of product quality, wide usage and availability, and positive reputation.
Merchant Maverick’s ratings are editorial in nature, and are not aggregated from user reviews. Each staff reviewer at Merchant Maverick is a subject matter expert with experience researching, testing, and evaluating small business software and services. The rating of this company or service is based on the author’s expert opinion and analysis of the product, and assessed and seconded by another subject matter expert on staff before publication. Merchant Maverick’s ratings are not influenced by affiliate partnerships.
Our unbiased reviews and content are supported in part by affiliate partnerships, and we adhere to strict guidelines to preserve editorial integrity. The editorial content on this page is not provided by any of the companies mentioned and has not been reviewed, approved or otherwise endorsed by any of these entities. Opinions expressed here are author’s alone.
"*" indicates required fields