Important Notice from AspDotNetStorefront
It is with dismay that we report that we have been forced, through the action of hackers, to shut off write-access to this forum. We are keen to leave the wealth of material available to you for research. We have opened a new forum from which our community of users can seek help, support and advice from us and from each other. To post a new question to our community, please visit: http://forums.vortx.com
Results 1 to 2 of 2

Thread: PCI - What Level are you?

  1. #1
    ssgumby is offline Senior Member
    Join Date
    Feb 2009
    Posts
    683

    Default PCI - What Level are you?

    Just curious what level other people are and what provider they use.

    I just got a notice from First Data that since I am using authorize.net I am Level 5 (highest level)

    seems CRAZY and im looking more into it but what level are other people at?

    Thanks

  2. #2
    DanV's Avatar
    DanV is offline Ursus arctos horribilis
    Join Date
    Apr 2006
    Posts
    1,568

    Default

    Visa defines their merchant levels as follows:

    Level / Tier 1 Merchant Criteria Validation Requirements
    1 Merchants processing over 6 million Visa transactions annually (all channels) or Global merchants identified as Level 1 by any Visa region 2
    Annual Report on Compliance (“ROC”) by Qualified Security Assessor (“QSA”)
    Quarterly network scan by Approved Scan Vendor (“ASV”)
    Attestation of Compliance Form

    2 Merchants processing 1 million to 6 million Visa transactions annually (all channels)
    Annual Self-Assessment Questionnaire (“SAQ”)
    Quarterly network scan by ASV
    Attestation of Compliance Form

    3 Merchants processing 20,000 to 1 million Visa e-commerce transactions annually
    Annual SAQ
    Quarterly network scan by ASV
    Attestation of Compliance Form

    4 Merchants processing less than 20,000 Visa e-commerce transactions annually and all other merchants processing up to 1 million Visa transactions annually
    Annual SAQ recommended
    Quarterly network scan by ASV if applicable
    Compliance validation requirements set by acquirer


    I don't see any definition for a Level 5 merchant.