Global Risk Management Services Group
Global Risk Management Services Group
  • Home
  • About
  • Services
    • Overview
    • PCI Risk Advisory
    • Non-PCI Risk Advisory
  • Schedule Your Engagement
  • Contact Us
  • PCI Applicability
  • PCI Pre-Compliance
  • PCI Levels & Requirements
  • Framework for Success-PCI
  • Business & Tech Risk
  • Specialized Assessments
  • Governance Evaluation
  • FAQs
  • Careers
  • More
    • Home
    • About
    • Services
      • Overview
      • PCI Risk Advisory
      • Non-PCI Risk Advisory
    • Schedule Your Engagement
    • Contact Us
    • PCI Applicability
    • PCI Pre-Compliance
    • PCI Levels & Requirements
    • Framework for Success-PCI
    • Business & Tech Risk
    • Specialized Assessments
    • Governance Evaluation
    • FAQs
    • Careers
  • Sign In
  • Create Account

  • Bookings
  • My Account
  • Signed in as:

  • filler@godaddy.com


  • Bookings
  • My Account
  • Sign out


Signed in as:

filler@godaddy.com

  • Home
  • About
  • Services
    • Overview
    • PCI Risk Advisory
    • Non-PCI Risk Advisory
  • Schedule Your Engagement
  • Contact Us
  • PCI Applicability
  • PCI Pre-Compliance
  • PCI Levels & Requirements
  • Framework for Success-PCI
  • Business & Tech Risk
  • Specialized Assessments
  • Governance Evaluation
  • FAQs
  • Careers

Account


  • Bookings
  • My Account
  • Sign out


  • Sign In
  • Bookings
  • My Account

PCI Applicability to Your Business

Compliance Requirements Overview

PCI Applicability Levels for Your Business

PCI Applicability Levels for Your Business

Person interacting with digital compliance checklist.

  • The Payment Card Industry Data Security Standard (PCI DSS) is a comprehensive global security baseline established by major card brands (Visa, Mastercard, Amex, Discover, and JCB) to protect cardholder data and prevent fraud. Organizations must comply with the standard if they store, process, or transmit credit card details.


  • The current standard (PCI DSS v4.0.1) is structured around six core security goals that encompass 12 detailed requirements

PCI Applicability Levels for Your Business

PCI Applicability Levels for Your Business

PCI Applicability Levels for Your Business

A salesperson assisting a customer in an electronics store.

Compliance Validation Levels ( For Merchants):  An organization's validation method depends on its annual transaction volume and merchant level:


  • Level 1 (Over 6 Million Transactions/Year): Requires an annual on-site audit by an external Qualified Security Assessor (QSA) and an Attestation of Compliance (AOC).


  • Level 2 (1 to 6 Million Transactions/Year): Requires an annual Self-Assessment Questionnaire (SAQ), an AOC, and quarterly network scans.


  • Level 3 (20,000 to 1 Million E-commerce Transactions/Year): Requires an annual SAQ, an AOC, and quarterly network scans.


  • Level 4 (Fewer than 20,000 E-commerce Transactions/Year): Requires an annual SAQ, an AOC, and quarterly network scans if applicable.

PCI Applicability Levels for Your Business

PCI Applicability Levels for Your Business

PCI Applicability Levels for Your Business

Data center server room with racks of servers.

Compliance Validation Levels ( For Service Providers):  An organization's validation method depends on its annual transaction volume and Service Providers:


Level 1: High Volume

  • Criteria: Process, store, or transmit more than 300,000 card transactions annually. (Also includes Third-Party Processors and Data Storage Entities).
  • Requirements:
    • Annual onsite assessment by a Qualified Security Assessor (QSA).
    • Annual Report on Compliance (RoC).
    • Quarterly network scans by an Approved Scanning Vendor (ASV).
    • Attestation of Compliance (AoC).


Level 2: Standard Volume

  • Criteria: Process, store, or transmit 300,000 or fewer card transactions annually.
  • Requirements:
    • Annual Self-Assessment Questionnaire (SAQ-D for Service Providers).
    • Quarterly network scans by an ASV.
    • Annual Attestation of Compliance (AoC)

Global Risk Management Services Group L.L.C

Copyright © 2023 - 2026  Global Risk Management Services Group L.L.C - All Rights Reserved. 

Powered by

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

Accept