If your organization processes a very high volume of card transactions a year across all channels, you're a PCI DSS Level 1 merchant, and the rules change substantially. Validation requires an annual on-site assessment by a Qualified Security Assessor producing a signed Report on Compliance, quarterly external vulnerability scans, and an annual penetration test. A breach or a card brand's decision can also force Level 1 status regardless of your actual transaction count.
TL;DR:
- High-volume merchants must undergo annual on-site assessments, quarterly vulnerability scans, and annual penetration tests, regardless of their transaction count.
- Proper scoping of the cardholder data environment, including thorough documentation and segmentation, significantly reduces audit delays and scope expansion risks.
- Evidence organization, such as consistent naming and current network diagrams, is critical to a smooth assessment process and avoiding major schedule setbacks.
- Service providers focusing on multi-tenant security and API controls face additional sampling scrutiny and often pursue Level 1 validation to enhance trust signals.
- Ongoing compliance efforts, including regular scans, logging, and change management, are essential to maintain readiness between assessments and avoid costly surprises.
Table of Contents
- What Triggers PCI DSS Level 1 Status?
- What Auditors Actually Want to See During Validation
- How to Scope the Cardholder Data Environment Before the Audit
- Merchant vs. Service Provider: Different Scope, Different Scrutiny
- What a Level 1 Assessment Actually Costs, and How Long It Takes
- Staying Audit-Ready Between Assessments
- How PaySec Supports Level 1 Readiness
- The Part of Level 1 Compliance Most Guides Skip
- Get a Level 1 Readiness Review From PaySec
- Authoritative PCI Resources to Read Next
- Sources
- FAQ
What Triggers PCI DSS Level 1 Status?
The high-volume transaction threshold applies to Visa, Mastercard, and Discover, but it isn't universal. American Express and JCB set their own lower Level 1 cutoffs, so a merchant that clears Visa's bar comfortably might already owe Level 1 validation under a different card brand's rules. Service providers face a separate threshold that also pushes them into Level 1 territory.
Volume isn't the only path in. A confirmed data breach can bump any merchant to Level 1 overnight, no matter how small their processing volume was the day before. Card brands also retain discretion to designate specific merchants as Level 1 based on risk profile.
To confirm your actual level:
- Count transactions separately for each card brand you accept, not just your total volume.
- Include every channel: card-present, e-commerce, mail order, and telephone order.
- Ask your acquiring bank to confirm your designation. They track this and will notify you if your status changes.
- Recheck annually. Growth, an acquisition, or a new sales channel can quietly cross a threshold.
What Auditors Actually Want to See During Validation
A Level 1 assessment runs on four pillars, and each one has its own rhythm and evidence trail.
The Report on Compliance (ROC) is the core deliverable. A QSA conducts an on-site (or remote, where permitted) assessment covering all 12 PCI DSS requirements, and that means sampling systems, interviewing staff, and testing controls directly rather than taking your word for it. Expect the assessor to pull firewall configs, review access logs, and walk through your incident response plan with whoever owns it.
The Attestation of Compliance (AOC) is the signed summary that follows the ROC. It requires signatures from a company officer and the QSA, and it's the document your acquirer and the card brands actually want to see. Distribution matters: your acquiring bank needs a copy, and if you're a service provider, your merchant clients will often ask for one too.
Quarterly ASV scans cover your externally facing systems and must be run by an Approved Scanning Vendor. A failing scan isn't the end of the story, but it does start a remediation clock, and you'll need a clean passing scan before the quarter closes.
Annual penetration testing covers both internal and external attack surfaces, and it needs to happen again after any significant change to the cardholder data environment, not just once a year on a fixed date.
Here's the typical order of operations a QSA expects to follow:
- Confirm scope and review your network diagrams.
- Sample systems and locations across the environment.
- Interview control owners for each of the 12 requirements.
- Review evidence: logs, configs, and policy documents.
- Test controls directly rather than accepting documentation alone.
- Draft findings and issue the ROC.
Pro Tip: Build a standing evidence folder year round, not two weeks before the assessment. Firewall rule reviews, access control logs, and change tickets all age fast, and a QSA can usually tell when evidence was assembled retroactively.
How to Scope the Cardholder Data Environment Before the Audit
Scoping mistakes cause more audit delays than actual security gaps. Start by mapping every place cardholder data flows, is stored, or is transmitted, including systems you might assume are out of scope, like a backup server or a support ticketing tool that occasionally captures card numbers in a screenshot.
Segmentation is the primary lever for shrinking that scope. Network segmentation isolates the cardholder data environment from the rest of your infrastructure, tokenization replaces raw card data with non-sensitive tokens, and point-to-point encryption (P2PE) protects data from the moment of capture. Each comes with a trade-off: segmentation demands rigorous firewall rule maintenance, tokenization requires vendor integration work, and P2PE often means new hardware.
Documentation is where most teams underinvest:
- Maintain a current network diagram showing every system that touches card data.
- Assign clear ownership for each system and interface.
- Document data retention points and when data is purged.
- Keep an accurate inventory of third-party connections into the CDE.
Pro Tip: Name your evidence files consistently (system, date, control number) before the QSA arrives. It sounds minor, but disorganized evidence is one of the most common reasons assessments run long.
If your environment spans multiple business units or your last scoping exercise predates a major infrastructure change, bring in a QSA for a dedicated scoping workshop before the formal assessment starts. It's far cheaper to fix scope on paper than to discover mid-audit that three systems you assumed were segmented actually aren't.
Merchant vs. Service Provider: Different Scope, Different Scrutiny
A Level 1 merchant and a Level 1 service provider get audited against the same 12 requirements, but QSAs focus their sampling differently depending on which one you are.
For merchants, the sampling emphasis falls on:
- Physical retail locations and point-of-sale hardware
- E-commerce checkout flows and payment page integrity
- Store-level access controls and employee handling of card data
For service providers, the emphasis shifts toward:
- Multi-tenant isolation, since a control failure here can expose multiple clients at once
- API and gateway security at every integration point
- The mechanics of sharing ROC and AOC evidence with merchant clients who need it for their own compliance
Service providers that validate at Level 1 can also appear on Visa's Global Registry of Approved Service Providers, which functions as a commercial trust signal. Enterprise merchants often screen vendors against that registry before signing a contract, so some providers pursue Level 1 validation voluntarily, even when their transaction volume would technically qualify them for Level 2.
Your acquiring bank and the relevant card brands are the required recipients of your ROC and AOC. Service providers should expect merchant clients to request copies directly as part of their own due diligence.
What a Level 1 Assessment Actually Costs, and How Long It Takes
Budget more time than you expect. A Level 1 ROC assessment for a large, multi-environment organization commonly runs from several weeks to several months, depending on how many locations, systems, and business units fall inside scope. Poor scoping is the single biggest variable that stretches a timeline from weeks into months.
Cost drivers stack up quickly:
- QSA professional fees, which scale with the number of systems sampled and locations visited
- Remediation engineering time to close gaps found during scoping or pre-assessment testing
- ASV scanning and penetration testing fees, billed separately from the QSA engagement
- Internal staff hours spent gathering evidence, escorting assessors, and coordinating interviews
The findings that repeat most often across Level 1 audits: incomplete network segmentation, missing or incomplete access logs, weak multi-factor authentication coverage, and change control processes that exist on paper but aren't consistently followed in practice.
When you hit a finding that threatens your timeline, triage by risk to evidence collection first. A missing log retention policy that blocks a QSA from sampling six months of access history is a bigger schedule risk than a lower-severity finding you can remediate after the fact with a corrective action plan.
Staying Audit-Ready Between Assessments
Level 1 compliance isn't a once-a-year event. It's a standing operational program, and the gap between organizations that sail through their next ROC and those that scramble usually comes down to what happens in the eleven months between assessments.
Keep these running year round:
- Quarterly external ASV scans, plus internal scans on your own schedule, and a fresh scan after any significant CDE change
- Centralized logging and alerting with retention long enough to satisfy sampling requests during your next audit
- Change management tied directly to CDE components, with release gating that flags anything touching cardholder data systems
- Vendor management that collects subcontractor evidence proactively, since shared responsibility doesn't excuse you from proving a partner's controls
Physical security controls deserve attention here too, particularly in cash-handling or card-present retail environments where camera systems and access logs form part of your evidence base. Guides on securing commercial camera systems cover practical steps worth reviewing if surveillance infrastructure touches your CDE boundary.
How PaySec Supports Level 1 Readiness
Evidence hygiene is the difference between a smooth ROC and a painful one, and reporting infrastructure does a lot of that work quietly in the background. PaySec's real-time reporting and analytics give compliance teams a running record of transaction activity and system behavior, which shortens the scramble to reconstruct evidence when a QSA asks for six months of history.
Whether you build remediation capability internally or bring in outside compliance assistance often depends on how many gaps your scoping exercise uncovers. Smaller gap lists favor an internal fix; a longer list, especially one touching segmentation or logging infrastructure, usually moves faster with dedicated support. PaySec's PCI compliance assistance page and its PCI compliance guide for larger merchants are useful starting points for either path.
The Part of Level 1 Compliance Most Guides Skip
Most PCI DSS content treats Level 1 as a checklist: hit the transaction threshold, hire a QSA, pass the ROC, move on. That framing undersells how much of the actual difficulty sits in scoping, not in the twelve requirements themselves. A QSA can test controls efficiently once scope is clean. What actually blows timelines is disorganized evidence and a CDE boundary nobody mapped carefully the first time.

The conventional advice to "start preparing three months out" is reasonable for a Level 2 reassessment. For a Level 1 organization spanning multiple business units, that's often too late to fix a segmentation gap discovered mid-audit. Treat scoping and evidence hygiene as continuous operational work, not an annual sprint. Organizations that do this consistently spend less on remediation engineering and less on QSA time, because the assessor is testing a clean environment instead of untangling one.
If you take one thing from this: prioritize evidence retention and access logging before you prioritize anything else. Every other finding is fixable in isolation. A logging gap can block sampling across half your requirements at once.
— PaySec Marketing Team
Get a Level 1 Readiness Review From PaySec
Preparing for a Level 1 assessment gets easier when your payment infrastructure is already built for transparency, with real-time transaction reporting, secure processing built on PCI DSS Level 1 and SOC 2 compliance, and no long-term contracts locking you into a setup that doesn't fit your evidence needs.
If your business runs card-present transactions, PaySec's mobile payment processing and payment terminal options are built with the same compliance foundation, so your point-of-sale environment doesn't become the weak link in your scoping exercise. Request a readiness review with PaySec's team to see where your current setup stands before your next QSA engagement.
Authoritative PCI Resources to Read Next
- PCI Data Security Standard (PCI DSS) for the official standard and program documents
- PCI SSC program resources for ROC templates and reporting forms
- Qualified Security Assessors directory to find an accredited QSA
- Service provider level explainer for a practical breakdown of Level 1 through Level 4
Sources
- PCI Data Security Standard (PCI DSS)
- What are Service Provider Levels and How Do They Affect PCI Compliance - SecurityMetrics
- Qualified Security Assessors - PCI SSC
FAQ
What is a PCI DSS Level 1 provider?
A Level 1 provider is a merchant or service provider that meets the highest transaction volume threshold under PCI DSS and must validate compliance through an annual QSA-led Report on Compliance rather than a self-assessment questionnaire.
What are the differences between PCI Level 1 and Level 2 compliance?
Level 1 requires an on-site assessment by a Qualified Security Assessor producing a formal ROC, while Level 2 typically allows a self-assessment questionnaire, though both levels still require quarterly ASV scans.
What does it mean to be PCI Level 1 certified?
There's no single "certification" in PCI DSS. Level 1 status means an organization has completed an annual QSA-led ROC, submitted a signed AOC, and maintained quarterly scans and annual penetration testing.
How do I get PCI DSS certified?
Start by confirming your transaction volume with your acquirer, then engage an accredited QSA from the official directory to scope your cardholder data environment and schedule your Report on Compliance assessment.

