Merchant Tier Guidance

Powered by ValueMentor

Which PCI DSS path fits a Level 2 merchant like you?

PCI DSS Level 2 is a transaction-volume tier, not a validation method — depending on your card brand and payment flow, you may qualify to self-assess or you may need a formal QSA-led assessment. Answer a few questions below and we'll point you to the right program.

Typical volume~1M – 6M transactions/year
Validation pathSAQ or QSA-led, depends on card brand
DeliveryRemote, delivered globally
Delivered byValueMentor

The definition

What is PCI DSS Level 2?

PCI DSS Level 2 is a merchant tier defined by the payment card brands, generally covering merchants processing between roughly 1 million and 6 million card transactions per year — exact thresholds vary by card brand and transaction channel, so confirm your tier with your acquiring bank. Level 2 merchants are usually eligible to validate compliance using a Self-Assessment Questionnaire (SAQ), but some card brands still require an assessment led by a Qualified Security Assessor (QSA) at this volume. Which one applies to you determines which Secusy program you need — this page helps you figure out which.
  • Typical volume

    ~1M – 6M transactions/year

  • Validation path

    SAQ or QSA-led, depends on card brand

  • Delivery

    Remote, delivered globally

  • Delivered by

    ValueMentor

Two paths, one decision

Your merchant level alone doesn't determine your program — your payment flow and your card brand's requirements do.

You likely need a QSA-led assessment

  • Your card brand (some require this for Level 2 merchants, e.g. certain Mastercard programs) mandates a QSA-led assessment regardless of self-assessment eligibility
  • You store, process or transmit cardholder data directly, or operate a partially outsourced payment flow
  • You accept card-present payments through your own terminals or point-of-sale systems
  • Your acquiring bank has told you a Report on Compliance (ROC) is required

How it works

How to confirm which path applies to you

  1. Step 1

    Check your transaction volume

    Review your last 12 months of card transactions across all channels — this is what determines your merchant level, not your revenue or industry.

  2. Step 2

    Ask your acquiring bank

    Your acquirer (or the card brand directly) sets and confirms your merchant level and tells you whether QSA-led validation is required at that level.

  3. Step 3

    Review your payment flow

    If every cardholder-data touchpoint is fully outsourced to a validated third party (hosted checkout, redirect, or iframe), you're likely SAQ A eligible — the fastest, most affordable path.

  4. Step 4

    Choose your program

    Self-assessment eligible → PCI DSS SAQ A Compliance. QSA-led required, or cardholder data touches your own systems → PCI DSS Level 1 program.

Questions

Frequently asked questions

Still not sure which path fits?

Talk to us before you buy — we'll help you scope it correctly the first time.