What Is PCI DSS & What Are The 4 Levels Of PCI Compliance

TL;DR

  • PCI DSS compliance is the security standard every business handling credit card data must meet, and the four PCI compliance levels are defined by annual transaction volume, which determines how each business validates.

  • Any business that stores, processes, or transmits cardholder data must comply, with no exemption for small or low-volume merchants whose transaction count changes their level rather than whether the rules apply.

  • Levels 2 through 4 usually self-validate with the Self-Assessment Questionnaire that matches how they take payments, while Level 1 merchants need a Qualified Security Assessor to complete a Report on Compliance.

  • Compliance cost scales with your level and how much card data you handle, ranging from roughly $1,000 to $5,000 a year for the smallest merchants to $50,000 or more for a Level 1 enterprise.


 

If your organization handles credit card payments, complying with PCI DSS is non-negotiable. Yet according to Verizon’s 2024 Payment Security Report, only 14% of organizations maintain full PCI compliance.1 Many business leaders still struggle to understand what PCI means, how it applies to their operations, and what’s required to stay compliant.

At TailWind, we help distributed enterprises meet compliance efforts across every location with managed IT services, cybersecurity solutions, and expert field support. Check out this guide to start navigating PCI compliance with confidence.

What Is PCI DSS? Payment Card Industry Definition

PCI stands for Payment Card Industry – specifically, it refers to the Payment Card Industry Data Security Standard, or PCI DSS. These standards protect cardholder data during and after a transaction, and any organization that handles credit card information is required to adhere to them.

PCI Meaning For Your Business

Complying with PCI DSS can help your business reduce the risk of threats like data breaches, fraud, and regulatory fines. Unfortunately, meeting the requirements isn’t always straightforward – especially for multi-location enterprises. That’s why TailWind helps clients align with compliance frameworks like PCI DSS by building security best practices into the networks we manage.

Who Needs To Be PCI Compliant & Who Is Exempt?

Any business that stores, processes, or transmits cardholder data has to comply with PCI DSS. That covers far more organizations than most people assume, and there is no size threshold that lets a business opt out.

Two broad groups fall under the standard:

  • Merchants: any business that accepts credit or debit card payments, whether online, in a store, over the phone, or by mail. A single-location restaurant and a 200-site retail chain are both merchants under PCI DSS.

  • Service Providers: businesses that store, process, or transmit cardholder data on behalf of others, or that can affect the security of a client's card data. Payment gateways, hosting providers, and managed IT firms often fall here.

The most common misconception is that small or low-volume businesses are exempt. They are not. Transaction volume changes your compliance level and how you validate, not whether the rules apply. A business processing a few thousand card payments a year still has to meet the standard, usually through a Self-Assessment Questionnaire rather than a full audit.

The rare cases that sit outside PCI DSS are organizations that never touch cardholder data at all, for example a company that has fully outsourced payments to a compliant provider and whose own systems never see card details. Even then, you are responsible for confirming that your provider is compliant and keeping their Attestation of Compliance on file.

The 12 PCI DSS Requirements

PCI DSS defines how organizations must secure their networks, devices, and data when handling payment card information.

Which Are The PCI Security Standards?

PCI DSS covers 12 core security requirements organized into six control objectives:

  1. Build and Maintain a Secure Network
  2. Protect Cardholder Data
  3. Maintain a Vulnerability Management Program
  4. Implement Strong Access Control Measures
  5. Regularly Monitor and Test Networks
  6. Maintain an Information Security Policy

If your business processes credit card payments – online or in-store – you’re responsible for ensuring that your environment complies with these requirements.

PCI Compliance Checklist

Those six objectives break down into 12 specific requirements, and this is the checklist most assessors and Self-Assessment Questionnaires work through line by line:

  1. Install and maintain network security controls, such as firewalls.

  2. Apply secure configurations to all system components, with no vendor-default passwords.

  3. Protect stored cardholder data.

  4. Encrypt cardholder data when it travels across open or public networks.

  5. Protect all systems and networks against malware.

  6. Develop and maintain secure systems and software.

  7. Restrict access to cardholder data to a business need-to-know.

  8. Identify users and authenticate access to system components.

  9. Restrict physical access to cardholder data.

  10. Log and monitor all access to network resources and cardholder data.

  11. Test the security of systems and networks regularly.

  12. Support information security with organizational policies and programs.

Requirements 1 and 2 map to building a secure network, 3 and 4 to protecting cardholder data, 5 and 6 to vulnerability management, 7 through 9 to access control, 10 and 11 to monitoring and testing, and 12 to your security policy. Knowing which requirement covers what makes it far easier to scope an assessment and spot the gaps in your own environment.

What Is PCI DSS 4.0?

The latest version, PCI DSS 4.0, introduced important updates that reflect the changing security landscape. These updates provide more flexibility while raising the bar on what security measures organizations should implement, including robust authentication and encryption standards and continuous security monitoring rather than point-in-time checks.

At TailWind, we stay current with PCI DSS 4.0 and other evolving standards, so we’re always ready to help our clients align with new requirements and avoid compliance gaps.

What Is A PCI DSS Assessment?

A PCI assessment is a formal evaluation that determines whether your business meets PCI DSS requirements. It typically includes:

  • Network and system analysis to understand your complete environment.
  • Security control verification to confirm controls are properly implemented and effective.
  • Review of your policies, processes, and documentation to ensure they align with PCI requirements.
  • Vulnerability scanning and pen testing to identify weaknesses before attackers can exploit them.

The format and scope of your PCI assessment depend on which PCI compliance level you fall into – which we’ll explain next.

What Is A PCI SAQ & Which One Applies To You?

A Self-Assessment Questionnaire, or SAQ, is the validation tool that lets eligible merchants confirm their own PCI DSS compliance without a full on-site audit. Which SAQ you complete depends entirely on how your business accepts and handles card payments, not on how big you are.

There are several SAQ types, each built for a specific payment setup:

  • SAQ A: for merchants who fully outsource card handling to a compliant third party, such as a hosted checkout page. This is the shortest questionnaire.

  • SAQ A-EP: for e-commerce merchants whose website affects how card data is collected but does not store it directly.

  • SAQ B and B-IP: for merchants using standalone terminals or imprint machines, with no electronic cardholder data storage.

  • SAQ C and C-VT: for merchants with a connected payment application system (C) or a web-based virtual terminal (C-VT).

  • SAQ P2PE: for merchants using a validated point-to-point encryption solution.

  • SAQ D: the most detailed questionnaire, for merchants and service providers that store, process, or transmit cardholder data directly and do not fit the lighter categories.

Levels 2 through 4 generally validate with the SAQ that matches their setup. Level 1 merchants cannot self-assess, and instead need a Qualified Security Assessor (QSA) to complete a Report on Compliance. If you are unsure which SAQ fits, your acquiring bank or payment processor can confirm the right one before you start.

The 4 PCI Compliance Levels Explained

PCI compliance is not one-size-fits-all. The PCI DSS sorts businesses into four levels based on how many card transactions they process each year, and your level determines how you have to validate compliance.

Level Who It Applies To Validation Requirements
Level 1 More than 6 million transactions per year; any merchant that has had a data breach; global merchants a card brand designates as Level 1. Annual on-site assessment by a Qualified Security Assessor (QSA); quarterly network vulnerability scans; Attestation of Compliance.
Level 2 1 to 6 million card transactions per year. Annual Self-Assessment Questionnaire; quarterly network scans by an Approved Scanning Vendor (ASV); Attestation of Compliance.
Level 3 20,000 to 1 million e-commerce transactions per year. Self-Assessment Questionnaire; quarterly ASV scans; Attestation of Compliance.
Level 4 Fewer than 20,000 e-commerce transactions per year, or up to 1 million total transactions across all channels. Self-Assessment Questionnaire, with the type set by your acquiring bank; vulnerability scans as required for your situation.

Two things are easy to miss: a data breach can push any merchant up to Level 1 regardless of volume, and Level 3 focuses on e-commerce because online transaction environments face the most exposure. Even Level 4 businesses, the smallest tier, carry real risk and still have to validate.

How To Become PCI Compliant: A Step-By-Step Guide

Becoming PCI compliant follows the same core path whether you are a single-location shop or a multi-site enterprise. The work scales with your level and your environment, but the sequence stays the same.

  • Step 1: Determine your level. Add up your annual card transactions to find which of the four levels you fall into. Your level sets whether you self-assess or need a QSA.

  • Step 2: Scope your cardholder data environment (CDE). Map every system, device, and process that stores, processes, or transmits card data. Anything that touches it is in scope, and everything else can often be segmented out to shrink the work.

  • Step 3: Complete the right validation document. Level 1 merchants complete a Report on Compliance (ROC) signed by a QSA. Levels 2 through 4 complete the Self-Assessment Questionnaire (SAQ) that matches how they accept payments.

  • Step 4: Run your scans and testing. Book quarterly external vulnerability scans with an Approved Scanning Vendor, and add penetration testing where your level or SAQ type requires it.

  • Step 5: Remediate the gaps. Fix whatever the scans, testing, and gap analysis surface, from unpatched systems to weak access controls, then rescan to confirm a clean result.

  • Step 6: Attest and submit. Complete your Attestation of Compliance and submit your documentation to your acquiring bank or payment processor.

  • Step 7: Monitor and maintain. Keep logging, patching, and reviewing controls year-round, and revalidate annually, since compliance lapses the moment your environment drifts.

Most businesses stumble on scoping and remediation rather than the paperwork, so the earlier you tighten your environment, the smoother every later step becomes.

PCI Compliance Cost: What Businesses Should Budget

The cost of becoming PCI compliant depends far more on how you handle card data than on your size alone. A business that routes every payment through a hosted checkout keeps most of its systems out of scope and validates cheaply. A business that stores or touches card data directly takes on the full weight of the standard.

Most compliance budgets are built from a few recurring line items:

  • Self-Assessment Questionnaire (SAQ) or Report On Compliance (ROC): self-assessment is the light path, and a QSA-led ROC is the heavy one. Independent 2026 estimates put SAQ support at roughly $5,000 to $20,000 for smaller merchants and a full QSA ROC at $30,000 to $100,000 or more.

  • ASV Scans: quarterly external vulnerability scans from an Approved Scanning Vendor, commonly $100 to $500 per quarter depending on how many IP addresses are in scope.

  • Penetration Testing: internal and external testing, often $3,000 to $30,000 based on the size of your environment.

  • Remediation: fixing whatever the scans and gap analysis surface, usually the least predictable line item because it reflects existing security debt.

  • Ongoing Monitoring & Maintenance: logging, alerting, and annual revalidation, since compliance is not a one-time project.

As a rough planning guide, independent cost models group annual spend by merchant level: around $1,000 to $5,000 for a small Level 4 merchant on a hosted checkout, $5,000 to $20,000 at Level 3, $10,000 to $50,000 at Level 2, and $50,000 to $500,000 for a Level 1 enterprise running a full QSA assessment. The single biggest lever in every band is scope: the fewer systems that touch cardholder data, the lower the bill.

What’s The Cost Of Failing To Comply With PCI DSS 4.0?

The penalties for PCI DSS non-compliance vary from payment processor to payment processor, so it can be difficult to pin down exact fines. However, fines compound for each month a business fails to comply, and the per-month charge increases for longer periods.

For example, a business might pay $5,000 per month if it’s out of compliance for three months. But if they’re still non-compliant after seven months, they could pay $50,000 per month. In some cases, some processors have imposed fines ranging from $50 to $90 for each customer affected by a data breach.2

These aren’t “fines” in the same sense that you’d pay for violating a government regulation; they’re penalties built into the contract between merchants, payment processors, and credit card brands. So if your business is found to be non-compliant, the card brands could fine your payment processors, who then fine you as the merchant.

PCI DSS Compliance FAQs

Is PCI Compliance A Legal Or Contractual Requirement?

PCI compliance is a contractual requirement, not a federal law in the US. You agree to it through your contracts with acquiring banks, payment processors, and the card brands (Visa, Mastercard, American Express, Discover, and JCB). Those parties can fine you, raise your fees, or revoke your ability to accept cards if you fall out of compliance. Some state laws also reference PCI DSS, so the practical effect is the same as a legal obligation: if you accept card payments, you have to comply.

Who Enforces PCI Compliance And Issues Fines?

The PCI Security Standards Council writes and maintains the standard, but it does not enforce it. Enforcement runs through the card brands and your acquiring bank. If you are found non-compliant, the card brands can fine your acquirer, who then passes those penalties on to you as the merchant. Fines are set by contract rather than statute, which is why they vary from one processor to the next and can escalate the longer non-compliance continues.

How Do I Know If My Business Is PCI Compliant?

You are PCI compliant once you have completed the validation your level requires and can prove it. For most businesses that means finishing the correct Self-Assessment Questionnaire, passing quarterly ASV scans, and filing an Attestation of Compliance. Level 1 merchants confirm compliance through a Qualified Security Assessor and a Report on Compliance instead. If you have never completed any of these steps, you are almost certainly not compliant yet, even if you have never had a breach. Your acquiring bank can confirm your current status.

How Often Are PCI Compliance Scans And Audits Required?

PCI DSS is an ongoing obligation, not a one-time check. External vulnerability scans by an Approved Scanning Vendor are required quarterly, so four times a year, for any business with internet-facing systems in scope. Self-Assessment Questionnaires and, for Level 1 merchants, the QSA-led Report on Compliance are completed annually. Penetration testing is typically required at least once a year and after any significant change to your network. You also need continuous logging and monitoring in between these checkpoints.

Can I Handle PCI Compliance Myself Without A QSA?

In many cases, yes. Merchants at Levels 2 through 4 can usually validate on their own by completing the Self-Assessment Questionnaire that matches how they accept payments, running the required scans, and filing an Attestation of Compliance. You only need a Qualified Security Assessor if you are a Level 1 merchant, or in specific cases where your SAQ type calls for one. That said, many smaller businesses still bring in outside help for scoping and remediation, since those steps are where most compliance efforts stall.

Get Expert PCI DSS Compliance Support From TailWind

No matter which of the PCI compliance levels you fall into, maintaining security isn’t a one-time event. Ongoing efforts should include:

  • Monitoring and logging system activity
  • Keeping software and firmware up to date
  • Compliance audits from a trusted provider
  • Securing remote access
  • Training employees on security best practices
  • Regularly reviewing your compliance posture

TailWind helps multi-site businesses simplify these compliance needs with centralized security frameworks, proactive monitoring, and IT services built to scale. Whether you're navigating your first PCI assessment or aligning with new PCI DSS 4.0 requirements, our managed network and field services teams are here to keep your infrastructure secure and compliant.

Book a meeting with our team today to learn more about how we can support your PCI compliance goals with scalable network solutions and expert guidance.

Sources:

  1. https://www.verizon.com/business/resources/T797/reports/2024-payment-security-report.pdf
  2. https://www.csoonline.com/article/569591/pci-dss-explained-requirements-fines-and-steps-to-compliance.html