PCI DSS Level 1 is the most demanding tier of PCI compliance, reserved for the organisations that handle the largest volumes of card transactions. If you are approaching Level 1, the validation requirements step up considerably from the PCI DSS self-assessment that smaller merchants use. This guide explains what PCI DSS Level 1 is, what it requires, and how to approach it.
Understanding PCI compliance levels is essential for any organisation that processes payment card data. The levels of PCI compliance determine how you validate, who reviews your controls, and how much the process costs. Level 1 PCI compliance sits at the top of those PCI compliance levels. The PCI SSC and the card brands jointly set the thresholds; the PCI data security standard and the card industry data security standard set the requirements designed to protect cardholder data at every level. Organisations that achieve and maintain compliance with PCI DSS at Level 1 invest in it as a continuous programme rather than an annual event. The payment card industry security standards are maintained by the card industry security standards council (PCI SSC) in collaboration with the major card brands; the PCI data security standard that applies to Level 1 merchants is the same standard that applies at all levels, but the method of validation is fundamentally different.
What PCI DSS Level 1 is
PCI DSS sorts merchants into compliance levels based on annual card transaction volume, and Level 1 is the highest. The PCI Security Standards Council and card brands set the thresholds, but generally Level 1 merchants are those processing over six million transactions annually across all channels. Service providers also have levels, with the larger Level 1 service provider tier treated at the equivalent rigour. Understanding the PCI DSS compliance level that applies to your organisation is the starting point for scoping your validation obligations.
Below Level 1 are Level 2 merchants, Level 3 merchants, and Level 4 merchants, each with progressively lighter validation requirements. The PCI compliance levels framework reflects different risk profiles: more payment data means more risk means more rigorous validation. PCI DSS Level 1 sits at the top because of the sheer volume of payment card data processed.
Being Level 1 means your PCI DSS compliance validation is more rigorous because the scale of cardholder data you handle makes you a higher-value target. A data breach at this scale can expose millions of card records and result in significant fines from card brands, in addition to forensic investigation costs and reputational damage. Demonstrate PCI DSS compliance at Level 1 by meeting every applicable PCI DSS control requirement and having that compliance verified by an independent QSA through the formal Report on Compliance process.
Merchant levels compared
The four PCI DSS compliance levels apply generally across Visa, Mastercard, and other card brands, though exact thresholds can vary by card brand. Understanding the 4 PCI compliance levels as a whole helps you see where Level 1 sits in context. The framework below reflects the general standard:
| Merchant level | Annual transaction volume | Validation method |
|---|---|---|
| Level 1 | Over 6 million transactions, or any merchant that has experienced a data breach, or any merchant designated Level 1 by a card brand | Annual QSA assessment + Report on Compliance + Attestation of Compliance |
| Level 2 | 1 million to 6 million transactions | Annual SAQ + quarterly ASV scans; card brand may require QSA assessment |
| Level 3 | 20,000 to 1 million e-commerce transactions | Annual SAQ + quarterly ASV scans |
| Level 4 | Fewer than 20,000 e-commerce transactions or up to 1 million other transactions | Annual SAQ + quarterly ASV scans (requirements set by acquiring bank) |
Note that card brands can designate any merchant as Level 1 following a confirmed data breach, regardless of transaction volume. This is not widely publicised, but it means that any merchant that has suffered a breach may face Level 1 validation requirements even if their volume is below the six million threshold. For Visa specifically, merchants processing over 1 million Visa transactions annually across all channels are typically Level 2; only those above 6 million Visa transactions reach Level 1. Other card brands follow similar thresholds but may have brand-specific rules.
Service providers have their own two-tier structure. Level 1 service providers store, process, or transmit over 300,000 card transactions annually. Level 2 service providers fall below that threshold. Service provider compliance requirements differ from merchant requirements and typically include a QSA-led Report on Compliance for Level 1 service providers. Meeting the PCI standard at this tier requires the same rigour as Level 1 merchants.
Approaching Level 1 and not sure where to start?
Run the free security self-assessment to get an instant baseline before your first scoping conversation.
What Level 1 validation requires
The defining difference at Level 1 is how you validate compliance. Rather than completing a PCI DSS self-assessment questionnaire, a Level 1 merchant must undergo a PCI DSS assessment performed annually by a PCI Qualified Security Assessor (QSA), resulting in a Report on Compliance. Level 1 compliance validation includes:
- An annual QSA-led assessment producing a Report on Compliance, signed by the PCI Qualified Security Assessor.
- An Attestation of Compliance summarising the result and signed by both the merchant and the QSA.
- Quarterly external vulnerability scans by an Approved Scanning Vendor to meet PCI DSS scanning requirements.
- Penetration testing at least annually and after significant changes, as required by PCI DSS.
- Full implementation of the applicable PCI DSS requirements across your cardholder data environment, including network segmentation, access controls, encryption, logging and monitoring, and secure development practices.
Some Level 1 merchants may use an Internal Security Assessor (ISA) if the payment brands accept this for their specific situation, but the external QSA-led report is the standard path. To comply with the PCI DSS standard at this level, organisations must transmit cardholder data only through documented channels, document all payment data flows, and accurately declare their merchant level to payment brands and acquiring banks. PCI DSS validation at Level 1 is the most rigorous form of PCI DSS compliance and sets the bar for what it means to be PCI compliant at scale. Achieving PCI compliance at Level 1 requires sustained effort across all 12 requirement domains and ongoing investment to maintain it year-round. PCI data security at this level means demonstrating that every applicable control is genuinely operating, not just documented.
The role of the QSA and Report on Compliance
A Qualified Security Assessor is an individual certified by the PCI SSC who is qualified to conduct PCI DSS assessments. QSAs work for companies that are themselves validated as QSA companies by the PCI SSC. The assessment can be conducted remotely, on-site, or as a hybrid of the two, depending on the cardholder data environment and what is agreed with the QSA. On-site work is not mandatory; whichever format is used, the QSA must verify that controls are genuinely operating, not just documented.
The Report on Compliance is the formal output of the QSA-led assessment. It documents the assessed scope, the controls reviewed, the findings, and the QSA's attestation of whether each PCI DSS requirement was met. The ROC is a detailed technical and procedural document; preparing for it requires your controls to be not just in place but evidenced and auditable.
The Attestation of Compliance is a shorter summary document that accompanies the ROC. Both are submitted to your acquiring bank and payment brands as evidence of your Level 1 compliance status.
What makes Level 1 harder
Level 1 is more demanding for three reasons: the compliance validation is external and independent rather than self-administered, the scope is usually larger because high-volume environments are complex, and the evidence bar is higher because a PCI Qualified Security Assessor has to attest to it.
The work is less about new PCI requirements and more about proving, rigorously, that the security controls and security requirements are genuinely in place and operating. Level 2 merchants may self-certify via SAQ in many cases; Level 1 merchants cannot. An internal security assessor is only an option where the card brand explicitly permits it for your situation.
The full breadth of PCI DSS requirements applies at every level. What changes at Level 1 is not the requirements themselves, but who verifies them and what evidence is required. A QSA will examine every requirement within the assessed scope and will test, not just accept documentation of, the controls you claim are in place.
The 12 PCI DSS requirements in context
PCI DSS is built around 12 requirement domains that apply at every merchant level. At Level 1, a QSA must verify compliance across all applicable requirements:
- Install and maintain network security controls
- Apply secure configurations to all system components
- Protect stored account data
- Protect cardholder data during transmission over open public networks
- Protect all systems from malicious software
- Develop and maintain secure systems and software
- Restrict access to cardholder data by business need to know
- Identify users and authenticate access
- Restrict physical access to cardholder data
- Log and monitor all access to system components and cardholder data
- Test security of systems and networks regularly (includes quarterly ASV scans and annual penetration testing)
- Support information security with organisational policies and programs
At Level 1, the QSA will test the operating effectiveness of these controls, not just confirm that documentation exists. This means systems must be genuinely configured and managed to the standard, not just described in policy documents.
How to approach Level 1
Treat Level 1 as a programme, not a project. Validate compliance against a clearly defined cardholder data environment. Reduce scope through segmentation so the assessment covers as little of your infrastructure as defensibly possible.
Get your security controls genuinely operating and evidenced before the assessment begins, ideally through a gap assessment or readiness review, so the assessment confirms your work rather than discovering gaps. Keep your quarterly scans and annual penetration test on schedule throughout the year, because Level 1 is a continuous obligation, not a one-time project. Comply with PCI DSS requirements year-round and the annual assessment becomes confirmation rather than crisis management.
Segmentation is particularly valuable at Level 1. Large organisations typically have extensive infrastructure. Without proper network segmentation that isolates your cardholder data environment from the rest of the business, the QSA assessment scope can expand to encompass systems that genuinely have no contact with payment card data. Verified segmentation, tested through the annual penetration test, is one of the most cost-effective ways to keep Level 1 manageable.
Involve your QSA early. Unlike the self-assessment process, where you complete the SAQ and submit it, Level 1 benefits from engaging a QSA ahead of the formal assessment. A pre-assessment or readiness review, even informally, surfaces gaps before they become assessment findings. It also ensures that your scoping is aligned with what the QSA will accept.
Service provider organisations at Level 1 must also meet the PCI SSC requirements specific to service providers, which are more extensive than merchant requirements. Maintaining PCI DSS compliance at Level 1 requires ongoing investment in data security, staff training, and regular assessment readiness.
Common mistakes at Level 1
Under-scoping the cardholder data environment. Excluding systems that are genuinely connected to, or can affect the security of, cardholder data systems is the most serious mistake. A QSA performing penetration testing or reviewing network diagrams will identify connected systems that belong in scope. Discovering this during the assessment is far more expensive than finding it in a pre-assessment review. PCI DSS controls that apply to your cardholder data environment must apply to all systems in that environment; a QSA will test whether those controls are operating across the full defined scope.
Treating compliance as an annual event. Controls must operate throughout the year, not just be activated before the assessment window. Quarterly ASV scans, log monitoring, access reviews, and vulnerability management need to be ongoing processes. PCI DSS compliance validation confirms that controls were operating; it does not retroactively cover periods of non-compliance during the year.
Inadequate penetration testing scope. PCI DSS requires penetration testing that covers both external and internal components of the cardholder data environment, tests network segmentation controls, and uses a methodology aligned with PCI DSS requirements (such as those based on NIST SP800-115 or PTES). A superficial penetration test that does not meet these criteria will not satisfy the requirement. A PCI qualified professional conducting penetration testing must understand what PCI requirements are designed to protect against and test accordingly.
Failing to demonstrate PCI DSS compliance continuously. Achieve PCI compliance at Level 1 requires that you can demonstrate PCI DSS compliance across all 12 PCI requirements at the time of assessment, based on evidence of year-round operation. The 12 PCI requirements are not a point-in-time checklist; they are ongoing obligations. PCI level 1 merchants must comply with PCI DSS across the full cardholder data environment and maintain the evidence to demonstrate it. PCI compliance requirements at Level 1 include not just the technical controls but the organisational policies, training, and incident response procedures across the compliance program. Service provider levels carry similar obligations; Level 1 service providers face PCI DSS compliance requirements that, in some respects, exceed merchant requirements because of the breadth of their processing responsibilities.
Level 1 service providers: additional considerations
Level 1 service providers must comply with PCI DSS requirements that, in several respects, go beyond merchant requirements. Service providers must maintain a list of all entities they provide services to, demonstrate that their customers can achieve and maintain PCI compliance through their services, and meet additional requirements around third-party management and service monitoring.
The payment card industry data security standard includes requirements specifically aimed at service providers to ensure that the organisations handling the most payment card data on behalf of others are held to an appropriately high standard. A Level 1 service provider that stores, processes, or transmits cardholder data for merchants carries significant responsibility for the security of that data across all client environments.
Service provider levels carry their own validation requirements. Level 1 service providers typically undergo a QSA-led Report on Compliance alongside the merchant validation process described above, confirming full compliance with the PCI DSS standard as it applies to service providers. For merchants choosing a service provider, confirming that the provider is at the appropriate PCI DSS compliance level is a key part of due diligence.
The bottom line
PCI DSS Level 1 applies to the highest-volume merchants and service providers, and it is validated through an annual QSA-led assessment and Report on Compliance rather than a self-assessment, alongside quarterly ASV scans and annual penetration testing. It is harder because of the rigour and scope, not new requirements. Reduce scope through segmentation, get security controls genuinely operating and evidenced, and engage your QSA early so the formal assessment confirms your work rather than finding gaps.
How Onyx helps
Onyx supports Level 1 merchants and service providers at every stage of the compliance cycle, from gap assessment and remediation planning through to the quarterly ASV scanning and annual penetration testing required under PCI DSS. For organisations preparing for a QSA-led Report on Compliance, we run readiness reviews that map your controls against all 12 requirement domains and surface gaps before they become findings. For the penetration testing requirement, we scope the test to the PCI DSS methodology, covering external and internal components of the cardholder data environment and testing segmentation controls so you can rely on the result. We coordinate the scanning and testing obligations in one programme so the two deliverables align with your assessment calendar. Engagements start with a short scoping call: no pressure, no obligation, just a clear plan.
See also: PCI compliance cost, what is an Approved Scanning Vendor, PCI DSS SAQ types explained, and our PCI DSS Level 1 compliance service.
Preparing for a Level 1 QSA assessment?
We run a readiness review and scope your PCI obligations on a 30-minute call. No pressure, no obligation.
FAQ
What is PCI DSS Level 1?
PCI DSS Level 1 is the highest merchant compliance level, applying to organisations that process the largest volumes of card transactions (generally over six million annually) or that a card brand has designated as Level 1 (for example after a data breach or for other risk-based reasons). It carries the most rigorous compliance validation requirements because of the scale of cardholder data involved.
How do you validate PCI DSS Level 1?
Through an annual assessment by a PCI Qualified Security Assessor (QSA) that produces a Report on Compliance, plus an Attestation of Compliance, quarterly external scans by an Approved Scanning Vendor, penetration testing at least annually and after significant changes, and full implementation of all applicable PCI DSS requirements. Compliance validation is external and independent, not self-assessed.
What is the difference between Level 1 and a Self-Assessment Questionnaire?
Smaller merchants can validate compliance by completing a Self-Assessment Questionnaire. Level 1 merchants cannot; they require an external, independent assessment by a QSA resulting in a Report on Compliance. The compliance validation is independent and more rigorous.
Does PCI DSS Level 1 require penetration testing?
Yes. Like all PCI DSS compliance programmes, Level 1 requires penetration testing at least annually and after significant changes, alongside quarterly external vulnerability scans by an Approved Scanning Vendor. These are separate, recurring obligations and both must be met to comply with PCI DSS requirements.
How do I prepare for a PCI DSS Level 1 assessment?
Reduce and define your cardholder data environment through segmentation, get your security controls genuinely operating and evidenced, and conduct a readiness review before the assessment begins. Keep quarterly scans and penetration testing on schedule throughout the year. Engage your QSA early rather than waiting for the formal assessment.
Can a Level 1 merchant use an Internal Security Assessor?
In some cases, yes, but only where the relevant card brand explicitly permits it. The default path for Level 1 is a QSA-led external assessment and Report on Compliance. An Internal Security Assessor is a qualified individual who can perform some assessment activities internally, but this is not universally accepted as a substitute for a QSA-led ROC at Level 1.
