PCI DSS Level 1

PCI DSS Level 1 Certification (QSA Partner)

A QSA-signed Report on Compliance for Level 1 merchants and service providers, delivered through our QSA partner. We run readiness, documentation, remediation guidance, and project management so you arrive at the assessment prepared.

Overview

Level 1 merchants and Level 1 service providers are required to obtain a QSA-signed Report on Compliance (RoC) and Attestation of Compliance (AoC). The assessment is conducted and signed by a Qualified Security Assessor. Onyx Security Labs does not sign the RoC. We deliver the engagement through our QSA partner, who conducts and signs. The RoC is the annual report on compliance that your acquirer or payment brand requires under PCI DSS Level 1 requirements.

PCI DSS (the Payment Card Industry Data Security Standard) is maintained by the PCI Security Standards Council (PCI SSC). The card industry data security standard applies to any organisation that stores, processes, or transmits payment cards data at scale. Level 1 thresholds are determined by individual payment brands and are typically triggered by processing credit card transactions above a set annual volume, or by a mandate from your acquirer regardless of volume. Merchants or service providers who process above those thresholds must comply with pci dss Level 1 requirements, which include an annual QSA-signed RoC rather than a self-assessment.

Our role is the work that determines whether you pass. We run the readiness and gap assessment against the full PCI DSS v4.0.1 requirement set, author the policy and procedure suite, advise on scope reduction and segmentation, prepare the evidence repository, and manage the QSA engagement from start to signed attestation. You arrive at the assessment ready, not scrambling.

What’s included

  • Readiness and gap assessment against the full PCI DSS v4.0.1 data security standards requirement set
  • Cardholder data flow mapping and scope reduction guidance, including credit card data and account data inventories
  • Customised policy and procedure documentation suite and security controls documentation
  • Evidence preparation and organised audit repository
  • Remediation guidance (technical implementation remains with your team)
  • Coordination and project management with our QSA partner
  • QSA-conducted Report on Compliance and signed Attestation of Compliance (delivered by the QSA partner)

How we work

  1. 01
    Readiness assessment

    We assess your environment against the full PCI DSS v4.0.1 control set and identify exactly what stands between you and a signed RoC. Findings are documented with ownership and priority. This readiness phase is what allows you to achieve pci compliance at the assessment rather than discover gaps during it.

  2. 02
    Scope and remediation guidance

    We map cardholder data flows, advise on segmentation and scope reduction, and prioritise the remediation work. Network segmentation, tokenisation, and reducing unnecessary credit card data storage all affect your pci level and the assessment effort. Technical implementation, including firewall changes, server hardening, and code-level fixes, remains with your team.

  3. 03
    Documentation and evidence

    We author the customised policy and procedure suite, document your security controls, and assemble the evidence the QSA will review. An organised repository means the assessment runs on schedule. We note where an internal security assessor at your organisation should be trained and engaged to support maintaining pci compliance year-on-year.

  4. 04
    QSA assessment

    Our QSA partner conducts and signs the Report on Compliance and Attestation of Compliance. We coordinate the engagement throughout and manage any findings that arise during the assessment. The signed RoC and AoC are issued by the QSA partner and delivered to you as the formal pci dss level 1 compliance evidence your payment brand requires.

What you get

  • Readiness and gap assessment report against pci dss requirements
  • Customised policy and procedure documentation suite covering the full data security standards control set
  • Scope and segmentation documentation, including payment cards data flow maps
  • Organised evidence repository
  • QSA-signed Report on Compliance and Attestation of Compliance (issued by our QSA partner)

The signature comes from the QSA

The Report on Compliance is conducted and signed by our Qualified Security Assessor partner. Onyx Security Labs prepares you for the assessment, manages the engagement, and authors the documentation. We do not sign the RoC ourselves. This is stated plainly because it matters: your acquirer or payment brand will check. A pci qsa from our accredited partner is the only person who can sign the annual report on compliance.

Who needs Level 1 versus an SAQ?

The pci level thresholds that trigger a Level 1 requirement vary by payment brand. Visa and Mastercard typically place merchants processing above a defined transaction volume into Level 1. American Express has its own thresholds. Service providers are classified separately, with pci level 1 service provider status often triggered at lower volumes than merchant Level 1. If your acquirer has placed you at Level 1 directly, that instruction overrides any volume calculation. Level 2 and below generally qualify for the SAQ route.

Frequently asked questions

When do we need a Level 1 assessment instead of an SAQ?

Level 1 thresholds are set by the payment brands and are typically based on annual transaction volume, or they can be required directly by your acquirer regardless of volume. Level 1 merchants and service providers need a QSA-signed Report on Compliance. An SAQ is not sufficient. The pci dss level 1 compliance path requires an annual report on compliance signed by a QSA, not a self-assessment.

Who signs the Report on Compliance?

A Qualified Security Assessor from our QSA partner conducts and signs the RoC and AoC. We handle readiness, documentation, remediation guidance, and project management throughout the engagement. Onyx Security Labs does not sign the RoC.

Can you reduce the scope of the assessment?

Often, yes. Network segmentation, tokenisation, and removing unnecessary cardholder data storage can shrink the cardholder data environment and reduce the assessment effort. We advise on scope reduction during the readiness phase, before the QSA engages. Reducing your pci dss scope is one of the most effective ways to control the cost and complexity of Level 1 compliance.

What is the difference between a RoC and an AoC?

The Report on Compliance is the full assessment document, completed and signed by the QSA. The Attestation of Compliance is the summary attestation document. Both are required for Level 1 validation and are delivered by our QSA partner as part of this engagement.

What are the pci dss compliance levels?

The pci dss compliance levels are set by each payment brand. For merchants, Level 1 is the highest tier and typically applies to organisations processing the largest volume of credit card transactions annually. Level 2 and below have lower thresholds and may qualify for the SAQ validation route. Service providers have their own separate compliance levels. We confirm which level applies to you during the initial scoping call.

Credentials held by our team

ISO/IEC 27001 Lead Auditor
CISM
CISA
COBIT 2019
CEH
CRTP
eCPPT
CSA
CCNA
ITIL
Free tool · about 3 minutes · instant score

How ready is your security and compliance?

Answer 15 quick questions across the controls auditors actually check, and get an instant readiness score with tailored next steps. No call required.

Start the free assessment

Ready to simplify security and compliance?

Pick a service, book a scope call, or ask a question. Whatever order works.