Typical volume
~1M – 6M transactions/year
Merchant Tier Guidance
Powered by ValueMentor
PCI DSS Level 2 is a transaction-volume tier, not a validation method — depending on your card brand and payment flow, you may qualify to self-assess or you may need a formal QSA-led assessment. Answer a few questions below and we'll point you to the right program.
The definition
~1M – 6M transactions/year
SAQ or QSA-led, depends on card brand
Remote, delivered globally
ValueMentor
Your merchant level alone doesn't determine your program — your payment flow and your card brand's requirements do.
How it works
Review your last 12 months of card transactions across all channels — this is what determines your merchant level, not your revenue or industry.
Your acquirer (or the card brand directly) sets and confirms your merchant level and tells you whether QSA-led validation is required at that level.
If every cardholder-data touchpoint is fully outsourced to a validated third party (hosted checkout, redirect, or iframe), you're likely SAQ A eligible — the fastest, most affordable path.
Self-assessment eligible → PCI DSS SAQ A Compliance. QSA-led required, or cardholder data touches your own systems → PCI DSS Level 1 program.
Questions
Talk to us before you buy — we'll help you scope it correctly the first time.