PCI DSS • Decision Guide

Which PCI compliance path applies to you?

Answer a few questions. The guide determines the applicable level and explains exactly which fact triggered the result.

01 / 05

What kind of entity are you?

This is a general PCI DSS orientation. Your acquirer, payment brand, or compliance-accepting entity may impose additional validation requirements.

02 / 05

How many card transactions do you process?

Use the annual total. For the merchant path, the thresholds below follow the payment provider guide and can differ by card brand.

transactions / year
03 / 05

How many are online?

This helps distinguish transaction-volume categories used by payment brands. If all your transactions are online, enter the same number as above.

online / year
04 / 05

Have you had a data breach in the past?

A confirmed payment-data breach can affect your PCI DSS validation requirements regardless of transaction volume.

05 / 05

How does card data enter your system?

Choose the closest payment provider integration model. This helps identify the likely SAQ family when an SAQ is available. You still need to satisfy every eligibility criterion.

Relevant PCI DSS resources
Assessment result
Level 2

Why you got this result

Based on payment provider's A guide to PCI compliance. This is an educational decision aid, not a PCI DSS determination or legal/compliance advice. Card brands, acquirers, payment providers and regulators can impose additional requirements.