6 million or more transactions per year
Level 1 compliance is required for any merchant processing six million or more transactions per year, regardless of channel. All transactions performed by the merchant are aggregated, whether they occurred over the phone, in person or online. All transactions performed by the merchant are aggregated if the data is stored, processed or transmitted together, even if the transactions are performed under multiple Doing Business As (DBA) organisations. Visa also reserves the right to require Level 1 compliance by any merchant they determine needs to be in order to protect the Visa system.
In order to obtain and maintain Level 1 compliance, merchants need to produce an annual report on compliance by a Qualified Security Assesor.
Between 1 and 6 million transactions per year
Level 2 compliance is required for any merchant processing between 1 million and six million transactions per year, regardless of channel. All transactions performed by the merchant are aggregated, whether they occurred over the phone, in person or online.
In order to obtain and maintain Level 2 compliance, merchants need to complete an annual Self-Assessment Questionnaire (SAQ).
Between 20,000 and 1 million transactions online per year
Level 3 compliance is required for any merchant processing between 20,000 and 1 million e-commerce transactions per year. All transactions performed by the merchant are aggregated if the data is stored, processed or transmitted together, even if the transactions are performed under multiple Doing Business As (DBA) organisations.
In order to obtain and maintain Level 3 compliance, merchants need to complete an annual Self-Assessment Questionnaire (SAQ), perform quarterly network scans by an Approved Scan Vendor, and complete an Attestation of Compliance Form.
Less than 20,000 e-commerce transactions, or less than 1 million transactions offline per year
Level 4 compliance is required for any merchant processing less than 20,000 e-commerce transactions per year. It is also required of any merchant processing less than 1 million transactions via any other channel (telephone, in person, or otherwise non-ecommerce channel). All transactions performed by the merchant are aggregated if the data is stored, processed or transmitted together, even if the transactions are performed under multiple Doing Business As (DBA) organisations.
In order to obtain and maintain Level 4 compliance, it is recommended merchants complete an annual Self-Assessment Questionnaire (SAQ), perform quarterly network scans if applicable by an Approved Scan Vendor, and complete any additional requirements set forth by their merchant bank.