Merchant and service provider levels: who assigns yours
Levels come from the payment brands’ rulebooks and are applied by your acquirer — PCI DSS v4.0.1 never mentions them. The Mastercard and Amex thresholds, and what a level changes.
Your acquirer applies your level. The payment brands define what the levels are. Nobody else has a vote — not a Qualified Security Assessor, not a scanning vendor, not a testing firm, and not a consultant who emails to tell you that you are “Level 1”.
The clearest evidence is what the standard does not say. Search PCI DSS v4.0.1 (June 2024) for merchant level, Level 1 merchant or service provider level and you get nothing — zero occurrences. Levels are not a PCI SSC construct; they live in the payment brands’ own rulebooks, and the standard says where authority sits: “Whether any entity is required to comply with or validate their compliance to PCI DSS is at the discretion of those organizations that manage compliance programs (such as payment brands and acquirers).”
| Party | Its role in your level |
|---|---|
| The payment brand | Publishes the criteria and thresholds in its own rules, and keeps discretion to assign a level regardless of volume |
| Your acquirer — in India, your acquiring bank or sponsoring payment aggregator | Holds the counts, determines your level, tells you, and reports your validation status to the brand |
| A QSA, ISA, ASV or testing firm | None. An assessor records the instrument your level requires; it does not choose it |
Mastercard: the thresholds, and the cross-brand catch
From the Mastercard Security Rules and Procedures — Merchant Edition, 6 August 2024, §2.2.2:
| Level | Criteria | Validation |
|---|---|---|
| 1 | Over six million combined Mastercard and Maestro transactions annually; or meeting Visa’s Level 1 criteria; or Mastercard’s sole discretion | ROC, by a QSA or ISA |
| 2 | Over one million and up to six million combined Mastercard and Maestro transactions; or meeting Visa’s Level 2 criteria | Annual SAQ — but SAQ A, A-EP or D must additionally engage a QSA or ISA |
| 3 | Over 20,000 and up to one million combined Mastercard and Maestro e-commerce transactions; or meeting Visa’s Level 3 criteria | Annual SAQ; validation to Mastercard not required |
| 4 | Everything else | Compliance required; validation not, unless law requires it |
Two things there get missed. The first is that Mastercard imports Visa’s criteria by reference: a merchant meeting Visa’s Level 1 test is a Mastercard Level 1 merchant whatever its Mastercard volume. Counting one brand and stopping gives the wrong answer for a lopsided card mix, which in India is most of them.
The second is that Mastercard Level 2 self-assessment is not entirely self-assessment: if your SAQ is A, A-EP or D, a QSA or ISA must be engaged for the validation — and those are the three SAQs e-commerce merchants file.
American Express counts differently, and lower
American Express runs its own programme under its Data Security Operating Policy (April 2026), on a different denominator: American Express card transactions only.
| Level | Annual American Express card transactions |
|---|---|
| 1 | 2.5 million or more, or assigned at Amex’s discretion |
| 2 | 50,000 to fewer than 2.5 million |
| 3 | 10,000 to fewer than 50,000 |
| 4 | Fewer than 10,000 |
Level 1 files a ROC AOC, Level 2 an SAQ AOC with a scan where the SAQ type requires one. Levels 3 and 4 need not submit anything unless Amex asks, but remain fully bound by the policy. Volume rolls up to the highest American Express merchant account, so a group cannot split it downward, and franchisors mandating a POS system or service provider must validate for the affected franchisees.
The consequence is that you do not have “a PCI level”. You have one per brand. A merchant with modest American Express acceptance and heavy Visa and Mastercard volume can sit at Mastercard Level 2 and American Express Level 4 in the same year.
Service provider levels are not merchant levels
Merchant levels are volume bands. Service provider levels frequently are not. Under the Mastercard SDP Program a Level 1 service provider is any Third Party Processor, Merchant Payment Gateway, Staged Digital Wallet Operator, Digital Activity Service Provider, Token Service Provider, 3-D Secure Service Provider or Installment Service Provider — regardless of volume — plus any AML/Sanctions service provider, Data Storage Entity or Payment Facilitator over 300,000 combined Mastercard and Maestro transactions a year. Level 1 validates annually by ROC, conducted by a QSA. Mastercard, not the provider, decides the classification.
So a newly launched Indian payment gateway is a Mastercard Level 1 service provider on its first transaction, and registration is not complete until compliance is validated. American Express uses two service provider levels on the same 2.5 million threshold. Visa puts Level 1 at VisaNet processors and any third party agent over 300,000 Visa transactions a year, in a document dated 15 July 2015; confirm it with your sponsor.
What your level changes — and what it does not
It changes the reporting instrument — ROC or SAQ, whether a QSA or ISA must be involved, whether you report to the brand at all, and your exposure to non-compliance assessments. That is the whole of it.
It does not change which requirements apply. Mastercard puts it without qualification: “All Merchants must maintain ongoing compliance with the PCI DSS regardless of whether annual compliance validation is a requirement.” A Level 4 merchant is held to the same standard with lighter reporting, not to a lighter standard.
It does not choose your SAQ either. Eligibility follows how the payment channel is built — redirect, embedded iframe, direct post, terminal — not how many transactions run through it. Your level decides whether an SAQ is permitted at all; the architecture decides which one. See which SAQ applies to you.
And it does not move the testing clock. Requirements 11.4.2 and 11.4.3 require internal and external penetration testing “at least once every 12 months” and after any significant infrastructure or application upgrade or change. Neither carries a level qualifier. Requirement 11.4.6 sets segmentation testing at least once every six months for service providers that use segmentation to isolate the CDE — a consequence of being a service provider, not of being Level 1. A small merchant filing SAQ D owes the same Requirement 11.4 testing as a Level 1 merchant on a ROC, and is likelier to be surprised by it.
Levels move on events, not anniversaries
Mastercard obliges the acquirer to ensure a merchant transitioning between levels meets the new level’s requirements “not later than one year after the date of the event that results in or causes the Merchant to transition”. One good quarter starts a twelve-month clock nobody is watching.
Compromise moves it faster. A merchant with a confirmed Account Data Compromise event may be reclassified to Level 1 automatically; a service provider with a confirmed ADC event, an adverse inference, or a failure to cooperate with a forensic investigation will be, and is delisted from Mastercard’s compliant registered service provider list at the same time.
Finding out yours
- Ask your acquirer, in writing, separately for each brand you accept. Ask for the level, the count used, and the period it covers. One answer covering “PCI” is not an answer.
- If you are a service provider, ask what you are classified as, not only what volume you did. The classification sets the level, and it is the brand’s call.
- Do not take a level from a vendor. A firm quoting for the assessment has no standing to assign one, and being wrong either way is expensive.
Once settled, the level tells you which document you file and who signs it — covered in what “PCI DSS certification” actually means — and leaves the Requirement 11.4 obligations where they were. Those follow your scope and entity type, and are the part discovered late. Penetration testing scoped to Requirement 11.4 is work an independent qualified third party performs.
About the author
Chintan J
CISO & Director — Security Advisory
Oversees Security Brigade's cybersecurity advisory practice, helping regulated enterprises meet RBI, SEBI, CERT-In, and IRDAI compliance mandates. Previously held senior security leadership roles across BFSI.
Continue reading
All articles →What is and is not PCI DSS: SSF, P2PE, 3DS, PIN — and where PA-DSS went
PCI DSS assesses your organisation. SSF, P2PE, PTS, 3DS and PIN Security assess products and other parties. Where PA-DSS went, and what a listing changes.
Which PCI SSC document says what, and which PCI DSS version it is written against
PCI DSS v4.0.1 is the only active version: v4.0 retired 31 December 2024, v3.2.1 on 31 March 2024. Which PCI SSC document answers which question, and what version each carries.
PCI DSS renewal is a re-scope, not a repeat
Nothing renews on the anniversary. Requirement 12.5.2 asks the entity to re-confirm scope every twelve months, and a test scoped to last year's CDE is the first mismatch an assessor sees.