Knowledge
·
June 23, 2024

Who need PCI DSS Compliance?

Anyone storing, processing or transmitting cardholder data must meet PCI DSS. Here are the merchant and service provider levels and what each level submits.

Article cover image

Service Provider

"Service Provider" as defined by PCI DSS is an organization providing services that involve transmitting, processing, or storing payment cardholder data on behalf of merchants or other service providers. This includes entities offering payment processing services, wallet providers, platforms integrating various payment channels, online marketplaces, and others impacting security of cardholder data.

Additionally, data centers providing virtual hosting services and cloud service providers are not directly involved in transaction services; they may impact cardholder data security to some extent and are also classified as service providers. Unlike merchants, service providers are categorized into two levels. Using VISA as an example, the classification and compliance requirements are detailed as follows:

Level 1

  • Processes over 300,000 transactions annually.
  • Annual on-site assessment by a QSA with submission of a Report on Compliance (ROC).
  • Submission of an Attestation of Compliance (AOC).
  • Conduct quarterly reports of External Vulnerability Scans by an Approved Scanning Vendor (ASV).

Level 2

  • Processes less than 300,000 transactions annually.
  • Annual submission of a Self-Assessment Questionnaire (SAQ).
  • Submission of an Attestation of Compliance (AOC).
  • Conduct quarterly reports of External Vulnerability Scans by an Approved Scanning Vendor (ASV).

Merchant

Level 1

  • Processes over 6 million transactions annually.
  • Annual on-site assessment by a QSA with submission of a Report on Compliance (ROC).
  • Submission of an Attestation of Compliance (AOC).
  • Conduct quarterly reports of External Vulnerability Scans by an ASV.

Level 2

  • Processes between 1 million and 6 million transactions annually.
  • Annual submission of a Self-Assessment Questionnaire (SAQ).
  • Submission of an Attestation of Compliance (AOC).
  • Conduct quarterly reports of External Vulnerability Scans by an ASV.

Level 3

  • Processes between 20,000 and 1 million transactions annually.
  • Annual submission of a Self-Assessment Questionnaire (SAQ).
  • Submission of an Attestation of Compliance (AOC).
  • Conduct quarterly reports of External Vulnerability Scans by an ASV.

Level 4

  • Processes up to 20,000 transactions annually.
  • Annual submission of a Self-Assessment Questionnaire (SAQ).
  • Submission of an Attestation of Compliance (AOC).
  • Conduct quarterly reports of External Vulnerability Scans by an ASV (optional).

For more details, refer to the VISA website: usa.visa.com/support/small-business/security-compliance.html and usa.visa.com/partner-with-us/pci-dss-compliance-information.html

Contact Us Today for Expert PCI Compliance Support

👉 Contact Us