{"id":1832,"date":"2020-12-02T17:17:07","date_gmt":"2020-12-02T17:17:07","guid":{"rendered":"https:\/\/sectigostore.com\/blog\/?p=1832"},"modified":"2021-01-04T15:16:16","modified_gmt":"2021-01-04T15:16:16","slug":"pci-merchant-compliance-levels","status":"publish","type":"post","link":"https:\/\/sectigostore.com\/blog\/pci-merchant-compliance-levels\/","title":{"rendered":"What Are the 4 PCI Merchant Compliance Levels?"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">What you need to know about PCI DSS merchant levels and how they affect your PCI compliance\u2026<\/h2>\n\n\n\n<p>Are you here to learn about the PCI compliance levels for merchants? We\u2019ve got you covered with this guide that breaks down the four merchant levels.<\/p>\n\n\n\n<p>Not many people have even heard of the Payment Card Industry Data Security Standards (PCI DSS), but these standards affect everyone with a credit card (or who processes credit card transactions) every day. In 2004, when credit card fraud was running rampant, credit card companies knew they needed some way to mitigate the issue or risk facing a never-ending line of unhappy customers. The problem was that if they tried to force merchants and service providers into meeting their desired security requirements, the merchants would just switch to another credit card company who wasn\u2019t enforcing such high standards.<\/p>\n\n\n\n<p>To combat this, five of the largest credit card companies joined together to create the <a href=\"https:\/\/www.pcisecuritystandards.org\/\">PCI Security Standards Council<\/a> and PCI DSS with it. This way, merchants and service providers were forced to play by the council\u2019s rules or face their wrath (in the form of fines from the individual card companies). Yes, I know that last line sounded very Game of Thrones-ish, but I assure you that PCI DSS are for the cardholder\u2019s benefit \u2014 they ensure merchants provide top-notch security for the cardholder\u2019s data.<\/p>\n\n\n\n<p>However, with the creation of PCI DSS, it became clear to the PCI Security Standards Council that not all merchants needed to meet the same standards. With this latest iteration of PCI DSS (<a href=\"https:\/\/www.pcisecuritystandards.org\/documents\/PCI_DSS-QRG-v3_2_1.pdf\">PCI DSS version 3.2.1<\/a>) which features hundreds of security controls, it\u2019s just not practical nor necessary for every business to meet every standard, and this is why the PCI DSS merchant compliance levels were created.<\/p>\n\n\n\n<p>In this article, we dive into the PCI DSS merchant compliance levels, what their differences are, and how each level affects companies differently.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">More on PCI DSS &amp; Why Merchant Compliance Levels Are Necessary<\/h2>\n\n\n\n<p>The point behind PCI DSS is to mitigate vulnerabilities and enforce security standards that helps merchants better protect cardholder data. Unfortunately, data is a very sough after and lucrative target of hackers. Since 2005, there have been <a href=\"https:\/\/privacyrights.org\/\">more than 11 billion<\/a> data records breached, according to privacyrights.org. This is why security is needed for the entire card-handling process as there are a number of areas that could be breached.<\/p>\n\n\n\n<p>From processing devices to servers to web applications to transmitting data, every step of the process needs some type of security. PCI DSS extends beyond merchants to ensure that even service providers meet the standards. Service providers are <a href=\"https:\/\/www.pcisecuritystandards.org\/pdfs\/pci_ssc_quick_guide.pdf\">defined<\/a> as \u201cfinancial institutions that initiate and maintain the relationships with merchants that accept payment cards.\u201d<\/p>\n\n\n\n<p>To avoid facing noncompliance fines, merchants and service providers must maintain PCI compliance. The PCI DSS compliance levels help merchants know what requirements they are expected to meet. To learn a bit more about PCI DSS, the requirements that merchants are expected to meet, what a self-assessment is and more, we have some related resources you will find valuable:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Related: <a href=\"https:\/\/sectigostore.com\/blog\/what-is-pci-dss-a-quick-guide-to-the-12-pci-dss-requirements\/\">What Is PCI DSS? A Quick Guide to the 12 PCI DSS Requirements<\/a><\/li><li>Related: <a href=\"https:\/\/sectigostore.com\/blog\/how-to-do-a-pci-self-assessment\/\">How to Do a PCI Self Assessment<\/a><\/li><\/ul>\n\n\n\n<p>For more on PCI DSS compliance levels, keep on reading.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Are the PCI Compliance Levels for Merchants?<\/h2>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/12\/pci-compliance-levels-merchants.png\" alt=\"An illustration of a green clipboard to outlines the 4 PCI merchant compliance levels with gold check marks\" class=\"wp-image-1833\" width=\"243\" height=\"275\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/12\/pci-compliance-levels-merchants.png 433w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/12\/pci-compliance-levels-merchants-265x300.png 265w\" sizes=\"auto, (max-width: 243px) 100vw, 243px\" \/><\/figure><\/div>\n\n\n\n<p>Now it\u2019s time to dive into the PCI DSS compliance levels. These are focused on PCI merchant compliance levels (as opposed to service providers). The one thing that makes compliance levels a tad tricky is that each of the five major credit card brands all have their own criteria for the compliance levels.<\/p>\n\n\n\n<p>We broke each level down by the credit card brand, so you can easily tell which level you are. Also, we start with the least demanding PCI merchant compliance levels and work our way up to the most demanding one.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>Credit Card Brand<\/strong><\/td><td><strong>Their Criteria to Determine Level 1 Merchants<\/strong><\/td><\/tr><tr><td><a href=\"https:\/\/www.americanexpress.com\/us\/merchant\/us-data-security.html\">American Express<\/a><\/td><td>2.5M+ American Express card transactions annually<\/td><\/tr><tr><td><a href=\"https:\/\/www.discoverglobalnetwork.com\/en-us\/business-resources\/fraud-security\/pci-rules-regulations\/identify-your-merchant-level\">Discover Financial Services<\/a><\/td><td>6M+ Discover card transactions annually, or if another credit card brand deemed you a Level 1 Merchant<\/td><\/tr><tr><td><a href=\"https:\/\/www.global.jcb\/en\/products\/security\/data-security-program\/index.html\">JCB International<\/a><\/td><td>More than 1M JCB card transactions annually<\/td><\/tr><tr><td><a href=\"https:\/\/www.mastercard.us\/en-us\/business\/overview\/safety-and-security\/security-recommendations\/site-data-protection-PCI\/merchants-need-to-know.html\">Mastercard<\/a><\/td><td>6M+ combined Mastercard and Maestro card transactions annually or has suffered a cyber-attack that has resulted in compromised data<\/td><\/tr><tr><td><a href=\"https:\/\/usa.visa.com\/support\/small-business\/security-compliance.html?ep=v_sym_cisp\">Visa<\/a><\/td><td>6M+ Visa card transactions annually<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><em><strong>NOTE:<\/strong> All credit card brands reserve the right to deem a merchant Level 1 at their sole discretion.<\/em><\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>Credit Card Brand<\/strong><\/td><td><strong>Their Criteria to Determine Level 2 Merchants<\/strong><\/td><\/tr><tr><td>American Express<\/td><td>50,000-2.5M American Express card transactions annually<\/td><\/tr><tr><td>Discover Financial Services<\/td><td>1M-6M Discover card transactions annually via their network<\/td><\/tr><tr><td>JCB International<\/td><td>Less than 1M JCB card transactions annually<\/td><\/tr><tr><td>Mastercard<\/td><td>1M- 6M combined Mastercard and Maestro card transactions annually<\/td><\/tr><tr><td>Visa<\/td><td>1M-6M Visa card transactions annually<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>Credit Card Brand<\/strong><\/td><td><strong>Their Criteria to Determine Level 3 Merchants<\/strong><\/td><\/tr><tr><td>American Express<\/td><td>10,000-50,000 American Express card transactions annually<\/td><\/tr><tr><td>Discover Financial Services<\/td><td>All other merchants who process fewer than 1M Discover card transactions annually<\/td><\/tr><tr><td>JCB International<\/td><td>JCB does not have a Level 3 ranking<\/td><\/tr><tr><td>Mastercard<\/td><td>20,000-1M combined Mastercard and Maestro card transactions annually<\/td><\/tr><tr><td>Visa<\/td><td>20,000-1M Visa ecommerce transactions annually<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td><strong>Credit Card Brand<\/strong><\/td><td><strong>Their Criteria to Determine Level 4 Merchants<\/strong><\/td><\/tr><tr><td>American Express<\/td><td>Less than 10,000 American Express card transactions annually<\/td><\/tr><tr><td>Discover Financial Services<\/td><td>Discover does not have a Level 4 ranking<\/td><\/tr><tr><td>JCB International<\/td><td>JCB does not have a Level 4 ranking<\/td><\/tr><tr><td>Mastercard<\/td><td>Fewer than 20,000 combined Mastercard and Maestro card transactions annually<\/td><\/tr><tr><td>Visa<\/td><td>All merchants processing up to 1M transactions annually or fewer than 20,000 Visa ecommerce transactions<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">How Do PCI DSS Compliance Levels Relate to Staying PCI Complaint?<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"640\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/11\/pci-self-assessment-1024x640.jpg\" alt=\"PCI merchant compliance levels graphic: A close-up photo of credit cards that showcases their logos\" class=\"wp-image-1754\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/11\/pci-self-assessment-1024x640.jpg 1024w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/11\/pci-self-assessment-300x188.jpg 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/11\/pci-self-assessment-560x350.jpg 560w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/11\/pci-self-assessment-1536x960.jpg 1536w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/11\/pci-self-assessment-940x588.jpg 940w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/11\/pci-self-assessment-480x300.jpg 480w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/11\/pci-self-assessment.jpg 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>If you handle cardholder data in anyway, you need to be PCI complaint. To prove you are PCI complaint, you must undergo an annual validation to prove that you meet the necessary requirements. The PCI DSS compliance levels help credit card companies know what type of annual validation you must go through to demonstrate that you meet their expected standards.<\/p>\n\n\n\n<p>Bellow, we lay out what you need to know about maintaining PCI compliance through your annual validation based on your PCI DSS compliance level.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Level 4-2 Merchants<\/h2>\n\n\n\n<p>If you\u2019re a merchant who falls within the PCI merchant levels 4, 3, or 2, you\u2019re expected to complete the same general annual validation requirements across all three levels and all five credit card companies. There are very slight differences in the expectations, which you can review at the links directed to your acquiring bank in the \u201cWhat Are the PCI DSS Compliance Levels?\u201d section above. But in general, here is what Level 4-2 Merchants need to do during their annual validations:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Download and Complete a PCI Self-Assessment Questionnaire<\/h3>\n\n\n\n<p>This part is simple. All you need to do is download the correct PCI self-assessment questionnaire and answer the questions listed on it. The operative word in the last sentence is \u201ccorrect\u201d as there are <a href=\"https:\/\/sectigostore.com\/blog\/how-to-do-a-pci-self-assessment\/\">eight PCI-DSS self-assessment questionnaires<\/a> to choose from and it\u2019s essential that you select the right one. They are sorted by how you accept payment cards.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Complete an Attestation of Compliance<\/h3>\n\n\n\n<p>Your attestation of compliance (AOC) will be included with your PCI self-assessment questionnaire when you download it. The AOC is nothing more than confirming you\u2019re validated and gaining signatures from the appropriate parties.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Conduct Vulnerability Scanning<\/h3>\n\n\n\n<p>To ensure you are, indeed, secure and meeting the expected security standards, you\u2019ll need to have a vulnerability scan assessment completed by an Approved Scanning Vendor (ASV). An ASV is a data security firm who has been vetted and approved by the PCI Security Standards Council and uses a scanning solution to help verify if your PCI complaint.<\/p>\n\n\n\n<p>You should note that the ASVs reserve the option to use either an approved open source security solution or their own software. The task and responsibility of <a href=\"https:\/\/www.pcisecuritystandards.org\/assessors_and_solutions\/approved_scanning_vendors\">finding an ASV<\/a> falls on you as the one seeking compliance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Level 1 Merchants<\/h2>\n\n\n\n<p>If you\u2019re a Level 1 Merchant, your road is a bit more involved. You\u2019ll also need to complete a PCI Annual Vulnerability Scan by an Approved Scanning Vendor and an Attestation of Completion. But rather than needing to do a PCI self-assessment questionnaire, you\u2019ll need to undergo an on-site security assessment by a Qualified Security Assessor (QSA) instead.<\/p>\n\n\n\n<p>The goal of this on-site assessment is to confirm that you meet the appropriate PCI DSS. The QSA will do this by reviewing all of your payment card procedures, systems and use their own \u201cindependent judgment\u201d to verify you met your standards.<\/p>\n\n\n\n<p>When you <a href=\"https:\/\/www.pcisecuritystandards.org\/assessors_and_solutions\/qualified_security_assessors\">search for a QSA<\/a>, it\u2019s best if you look for someone who has knowledge of your industry and gives you feel that they would mesh with your company culture. The QSA will not simply come in and give you a stamp saying that you\u2019re &nbsp;\u201capproved\u201d or \u201cnot approved\u201d \u2014 it\u2019s their job to be a resource as well and to help your company meet PCI DSS (hence the recommendation of finding the right fit). Furthermore, it\u2019s also recommended that you look for a QSA that is an ASV, too, so you can kill two birds with one stone.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">A Final Word on the PCI DSS Compliance Levels<\/h2>\n\n\n\n<p>From PCI DSS compliance levels to how the levels affect merchants and their PCI compliance process, we have come to the end of our road. If you handle cardholder data, it\u2019s vital you stay up on this information and know what PCI DSS merchant compliance level you are. Make sure you do whatever you can to stay PCI complaint.<\/p>\n\n\n\n<p>One way to streamline the process of attaining and maintaining PCI compliance is to use a PCI compliance scanner tool. An automated tool such as <a href=\"https:\/\/sectigostore.com\/website-security\/hacker-guardian-pci-scan-control-center\">HackerGuardian<\/a> will literally scan you entire network, compile issues, make recommendations on how to resolve them and then put together a final report ready for you to submit to your acquiring bank.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What you need to know about PCI DSS merchant levels and how they affect your PCI compliance\u2026 Are you here to learn about the PCI compliance levels for merchants? We\u2019ve&#8230;<\/p>\n","protected":false},"author":14,"featured_media":1834,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[79],"tags":[157,58],"class_list":["post-1832","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-other","tag-pci-compliance","tag-pci-dss","post-with-tags"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What Are the 4 PCI Merchant Compliance Levels? - InfoSec Insights<\/title>\n<meta name=\"description\" content=\"If you handle credit card payments, the PCI merchant compliance levels are vital for you to know. Familiarize yourself with the 4 levels here.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sectigostore.com\/blog\/pci-merchant-compliance-levels\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What Are the 4 PCI Merchant Compliance Levels? - InfoSec Insights\" \/>\n<meta property=\"og:description\" content=\"If you handle credit card payments, the PCI merchant compliance levels are vital for you to know. Familiarize yourself with the 4 levels here.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sectigostore.com\/blog\/pci-merchant-compliance-levels\/\" \/>\n<meta property=\"og:site_name\" content=\"InfoSec Insights\" \/>\n<meta property=\"article:published_time\" content=\"2020-12-02T17:17:07+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-01-04T15:16:16+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/12\/pci-merchant-compliance-levels.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Danny Lewis\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Danny Lewis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/pci-merchant-compliance-levels\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/pci-merchant-compliance-levels\\\/\"},\"author\":{\"name\":\"Danny Lewis\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/25502b599fb00be7291f8a162d0d7267\"},\"headline\":\"What Are the 4 PCI Merchant Compliance Levels?\",\"datePublished\":\"2020-12-02T17:17:07+00:00\",\"dateModified\":\"2021-01-04T15:16:16+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/pci-merchant-compliance-levels\\\/\"},\"wordCount\":1637,\"image\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/pci-merchant-compliance-levels\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/pci-merchant-compliance-levels.jpg\",\"keywords\":[\"PCI Compliance\",\"PCI DSS\"],\"articleSection\":[\"Other\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/pci-merchant-compliance-levels\\\/\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/pci-merchant-compliance-levels\\\/\",\"name\":\"What Are the 4 PCI Merchant Compliance Levels? - InfoSec Insights\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/pci-merchant-compliance-levels\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/pci-merchant-compliance-levels\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/pci-merchant-compliance-levels.jpg\",\"datePublished\":\"2020-12-02T17:17:07+00:00\",\"dateModified\":\"2021-01-04T15:16:16+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/25502b599fb00be7291f8a162d0d7267\"},\"description\":\"If you handle credit card payments, the PCI merchant compliance levels are vital for you to know. Familiarize yourself with the 4 levels here.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/pci-merchant-compliance-levels\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/sectigostore.com\\\/blog\\\/pci-merchant-compliance-levels\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/pci-merchant-compliance-levels\\\/#primaryimage\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/pci-merchant-compliance-levels.jpg\",\"contentUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/12\\\/pci-merchant-compliance-levels.jpg\",\"width\":1600,\"height\":1000,\"caption\":\"PCI compliance levels feature graphic: A photo of a credit card that's secured by a lock & chains\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/pci-merchant-compliance-levels\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What Are the 4 PCI Merchant Compliance Levels?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/\",\"name\":\"InfoSec Insights\",\"description\":\"SectigoStore.com Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/25502b599fb00be7291f8a162d0d7267\",\"name\":\"Danny Lewis\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f25ef0f7508958c9e3fc8f585b4182b78f50bee96670874ce71dd6940b588fef?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f25ef0f7508958c9e3fc8f585b4182b78f50bee96670874ce71dd6940b588fef?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f25ef0f7508958c9e3fc8f585b4182b78f50bee96670874ce71dd6940b588fef?s=96&d=mm&r=g\",\"caption\":\"Danny Lewis\"},\"description\":\"Danny is a writer and editor with a background in journalism, marketing and communications. He is a tech enthusiast and writes about technology, website security and cyber security.\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What Are the 4 PCI Merchant Compliance Levels? - InfoSec Insights","description":"If you handle credit card payments, the PCI merchant compliance levels are vital for you to know. Familiarize yourself with the 4 levels here.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sectigostore.com\/blog\/pci-merchant-compliance-levels\/","og_locale":"en_US","og_type":"article","og_title":"What Are the 4 PCI Merchant Compliance Levels? - InfoSec Insights","og_description":"If you handle credit card payments, the PCI merchant compliance levels are vital for you to know. Familiarize yourself with the 4 levels here.","og_url":"https:\/\/sectigostore.com\/blog\/pci-merchant-compliance-levels\/","og_site_name":"InfoSec Insights","article_published_time":"2020-12-02T17:17:07+00:00","article_modified_time":"2021-01-04T15:16:16+00:00","og_image":[{"width":1600,"height":1000,"url":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/12\/pci-merchant-compliance-levels.jpg","type":"image\/jpeg"}],"author":"Danny Lewis","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Danny Lewis","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sectigostore.com\/blog\/pci-merchant-compliance-levels\/#article","isPartOf":{"@id":"https:\/\/sectigostore.com\/blog\/pci-merchant-compliance-levels\/"},"author":{"name":"Danny Lewis","@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/25502b599fb00be7291f8a162d0d7267"},"headline":"What Are the 4 PCI Merchant Compliance Levels?","datePublished":"2020-12-02T17:17:07+00:00","dateModified":"2021-01-04T15:16:16+00:00","mainEntityOfPage":{"@id":"https:\/\/sectigostore.com\/blog\/pci-merchant-compliance-levels\/"},"wordCount":1637,"image":{"@id":"https:\/\/sectigostore.com\/blog\/pci-merchant-compliance-levels\/#primaryimage"},"thumbnailUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/12\/pci-merchant-compliance-levels.jpg","keywords":["PCI Compliance","PCI DSS"],"articleSection":["Other"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/sectigostore.com\/blog\/pci-merchant-compliance-levels\/","url":"https:\/\/sectigostore.com\/blog\/pci-merchant-compliance-levels\/","name":"What Are the 4 PCI Merchant Compliance Levels? - InfoSec Insights","isPartOf":{"@id":"https:\/\/sectigostore.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/sectigostore.com\/blog\/pci-merchant-compliance-levels\/#primaryimage"},"image":{"@id":"https:\/\/sectigostore.com\/blog\/pci-merchant-compliance-levels\/#primaryimage"},"thumbnailUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/12\/pci-merchant-compliance-levels.jpg","datePublished":"2020-12-02T17:17:07+00:00","dateModified":"2021-01-04T15:16:16+00:00","author":{"@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/25502b599fb00be7291f8a162d0d7267"},"description":"If you handle credit card payments, the PCI merchant compliance levels are vital for you to know. Familiarize yourself with the 4 levels here.","breadcrumb":{"@id":"https:\/\/sectigostore.com\/blog\/pci-merchant-compliance-levels\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sectigostore.com\/blog\/pci-merchant-compliance-levels\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sectigostore.com\/blog\/pci-merchant-compliance-levels\/#primaryimage","url":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/12\/pci-merchant-compliance-levels.jpg","contentUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/12\/pci-merchant-compliance-levels.jpg","width":1600,"height":1000,"caption":"PCI compliance levels feature graphic: A photo of a credit card that's secured by a lock & chains"},{"@type":"BreadcrumbList","@id":"https:\/\/sectigostore.com\/blog\/pci-merchant-compliance-levels\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sectigostore.com\/blog\/"},{"@type":"ListItem","position":2,"name":"What Are the 4 PCI Merchant Compliance Levels?"}]},{"@type":"WebSite","@id":"https:\/\/sectigostore.com\/blog\/#website","url":"https:\/\/sectigostore.com\/blog\/","name":"InfoSec Insights","description":"SectigoStore.com Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sectigostore.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/25502b599fb00be7291f8a162d0d7267","name":"Danny Lewis","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f25ef0f7508958c9e3fc8f585b4182b78f50bee96670874ce71dd6940b588fef?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f25ef0f7508958c9e3fc8f585b4182b78f50bee96670874ce71dd6940b588fef?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f25ef0f7508958c9e3fc8f585b4182b78f50bee96670874ce71dd6940b588fef?s=96&d=mm&r=g","caption":"Danny Lewis"},"description":"Danny is a writer and editor with a background in journalism, marketing and communications. He is a tech enthusiast and writes about technology, website security and cyber security."}]}},"_links":{"self":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/1832","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/comments?post=1832"}],"version-history":[{"count":2,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/1832\/revisions"}],"predecessor-version":[{"id":1837,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/1832\/revisions\/1837"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/media\/1834"}],"wp:attachment":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/media?parent=1832"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/categories?post=1832"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/tags?post=1832"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}