SPIguard
       

Merchant Levels

The PCI DSS program will involve merchants of all business models. The PCI DSS is mandatory for level 1, 2, and 3 merchants. Level 4 a, b, are optional unless your Acquiring Institution has made it a mandatory requirement for processing credit card transactions.

Merchant levels defined

As of July 18, 2006, merchant level definitions have changed. Acquirers are responsible for determining the compliance validation levels of their merchants. Acquirers are also responsible for identifying the new compliance validation levels of their merchants according to the updated level definitions as of July 18, 2006.

All merchants will fall into one of the four merchant levels based on Visa transaction volume over a 12-month period. Transaction volume is based on the aggregate number of Visa transactions (inclusive of credit, debit and prepaid) from a merchant Doing Business As ("DBA"). In cases where a merchant corporation has more than one DBA, members must consider the aggregate volume of transactions stored, processed or transmitted by the corporate entity to determine the validation level. If data is not aggregated, such that the corporate entity does not store, process or transmit cardholder data on behalf of multiple DBAs, members will continue to consider the DBA's individual transaction volume to determine the validation level. Merchant levels are defined as:

Merchant Level Description
1 Any merchant-regardless of acceptance channel-processing over 6,000,000 Visa transactions per year. Any merchant that has suffered a hack or an attack that resulted in an account data compromise.Any merchant that Visa, at its sole discretion, determines should meet the Level 1 merchant requirements to minimize risk to the Visa system.Any merchant identified by any other payment card brand as Level 1.
2 Any merchant-regardless of acceptance channel-processing 1,000,000 to 6,000,000 Visa transactions per year.
3 Any merchant processing 20,000 to 1,000,000 Visa e-commerce transactions per year.
4 Any merchant processing fewer than 20,000 Visa e-commerce transactions per year, and all other merchants-regardless of acceptance channel-processing up to 1,000,000 Visa transactions per year.

Back to top

Compliance validation basics

In addition to adhering to the PCI Data Security Standard, compliance validation is required for Level 1, Level 2, and Level 3 merchants, and may be required for Level 4 merchants.

Level Validation Action Validated By Due Date
1
  • Annual On-site PCI Data Security Assessment
  • Quarterly Network Scan
  • Qualified Data Security Company or Internal Audit if signed by Officer of the company
  • Qualified Independent Scan Vendor

9/30/04

New level 1 merchants have up to one year from identification to validate.

2
  • Annual PCI Self-Assessment Questionnaire
  • Quarterly Network Scan
  • Merchant
  • Qualified Independent Scan Vendor

New level 2 merchants:
9/30/2007

3
  • Annual PCI Self-Assessment Questionnaire
  • Quarterly Network Scan
  • Merchant
  • Qualified Independent Scan Vendor
6/30/05
4*
  • Annual PCI Self-Assessment Questionnaire
  • Quarterly Network Scan
  • Merchant
  • Qualified Independent Scan Vendor

Validation requirements and dates are determined by the merchant's acquirer

*The PCI DDS requires that all merchants perform external network scanning to achieve compliance. Acquirers may require submission of scan reports and/or questionnaires by level 4 merchants.

Back to top

Validation procedures and documentation

Acquirers must obtain the required compliance validation requirements from their merchants. Documentation must be available to Visa upon request. Acquirers and merchants should also verify the compliance reporting requirements of other payment card brands that may require proof of compliance validation.

Compliance validation takes place at the merchant's expense, as follows:

  • The Annual On-Site PCI Data Security Assessment must be completed for Level 1 merchants according to the PCI Security Audit Procedures document. This document is also to be used as the template for the Report on Compliance.

Level 1 merchants should engage a Visa-approved, Qualified Data Security Company to complete the Report on Compliance and provide the report to their acquirer. Alternatively, acquirers may elect to accept the Report on Compliance from a level 1 merchant, provided that a letter signed by a merchant officer accompanies the report.

Download the PCI Security Audit Procedures (DOC, 627k).

  • The Annual PCI Self-Assessment Questionnaire must be completed by Level 2 and 3 merchants. Level 4 merchants may be required to complete the PCI Self-Assessment Questionnaire as specified by their acquirer.

Download the PCI Self-Assessment Questionnaire (DOC, 293k).

  • The Quarterly Network Security Scan is an automated tool that checks systems for vulnerabilities. It conducts a non-intrusive scan to remotely review networks and Web applications based in the externally-facing Internet Protocol (IP) address provided by the merchant. Acquirers are responsible for ensuring that the quarterly network security scans required of their levels 1, 2, and 3 merchants are performed by a qualified independent scan vendor. The Quarterly Network Security Scan may be required of level 4 merchants as specified by their acquirer.

Download the PCI Security Scanning Procedures (PDF, 105k).

PCI DSS Benefits ->

       
PCI DSS Compliant
Auditor Dyntek Canada
Certificate available here
QISA List
Copyright © 1994 - 2008 SPIguard Security Solutions Inc.
1-800-811-7811
info@spiguard.com
Community Storefronts PayPaq CN Wylie Strategic Profits Help for Charities

All rights reserved. Large sections of this site may not be copied without the consent of SPIguard. All text that is intellectual property is copyrighted. Theft will result in consequences. Any information from this site may NOT be used or displayed in any form without prior permission from SPIguard. and such information requires that appropriate credit be given to this site.