Get Demo
Cyber Silo Assistant
Hello! I'm your Cyber Silo assistant. How can I help you today?

PCI DSS Compliance Levels — Which Level Applies to Your Business?

Learn PCI DSS compliance levels for Saudi merchants and service providers, including SAQ types, validation requirements, and how to align with SAMA CSF and NCA

📅 Published: June 2026 🔐 Compliance • PCI DSS ⏱️ 9–12 min read

PCI DSS compliance is determined by your organization's transaction volume, processing channel, and role as either a merchant or service provider. The Payment Card Industry Security Standards Council (PCI SSC) defines four merchant levels and a parallel set of service provider tiers, each with distinct validation requirements. For Saudi and GCC enterprises operating under Vision 2030 — where digital payment adoption, fintech growth, and e-commerce are expanding rapidly — knowing which PCI DSS compliance level applies to your business is the first step toward avoiding fines, reputational damage, and potential loss of card-processing privileges.

These merchant levels range from Level 1 (over 6 million Visa transactions annually) down to Level 4 (fewer than 20,000 e-commerce transactions). Each level determines which Self-Assessment Questionnaire (SAQ) type you may be eligible to use, whether you require an on-site assessment by a Qualified Security Assessor (QSA), and how frequently you must submit compliance reports. For Saudi organizations subject to SAMA CSF compliance services in Saudi Arabia, understanding how PCI DSS maps to local regulatory expectations is critical. CyberSilo's Compliance Standards Automation platform helps enterprises determine their exact PCI level and automate the evidence collection required for both SAQs and Reports on Compliance (ROCs).

Why PCI DSS Levels Matter for Saudi Enterprises

Card-not-present fraud, data breaches at payment gateways, and non-compliance penalties are rising across the GCC. Saudi Arabia's fintech sector is projected to grow at over 20% CAGR through 2028, and the Saudi Central Bank (SAMA) mandates that all financial institutions handling cardholder data comply with PCI DSS as part of the SAMA Cybersecurity Framework (CSF). Beyond SAMA, the National Cybersecurity Authority's Essential Cybersecurity Controls (NCA ECC) also overlap with PCI DSS requirements around access control, logging, and vulnerability management.

PCI DSS compliance levels directly impact:

For Saudi enterprises — particularly those processing payments for government services, e-government portals, or Saudi fintech platforms — misclassifying your PCI level can lead to regulatory friction with SAMA or CITC.

Merchant Levels 1–4 Explained

The PCI SSC defines merchant levels based primarily on Visa transaction volumes over a rolling 12-month period. Mastercard, American Express, Discover, and JCB have similar tiering, with minor variations. Below is the definitive breakdown for Visa, which is the most widely adopted standard globally and in the GCC.

Level 1 Merchants

Criteria: Over 6 million Visa transactions per year (all channels). Also includes any merchant that has suffered a data breach or that is deemed high-risk by Visa or the acquiring bank.

Validation requirements:

SAQ eligibility: None. Level 1 merchants are not permitted to use any SAQ — they must undergo a full ROC.

Saudi context: Large Saudi banks (e.g., SNB, Al Rajhi), major telecom operators (STC, Zain, Mobily), and large e-commerce platforms like Noon or Jarir Bookstore typically fall into Level 1. If you process over SAR 50 million in card transactions annually, you are likely Level 1.

Level 2 Merchants

Criteria: 1 million to 6 million Visa transactions per year (all channels).

Validation requirements:

SAQ eligibility: SAQ A, A-EP, B, B-IP, C, C-VT, D (Merchant or Service Provider) — depending on the cardholder data environment.

Saudi context: Mid-sized Saudi retailers, regional hotel chains, and growing fintech platforms (e.g., Tamam, Lean) often fall into Level 2. Many have complex hybrid environments (e-commerce + POS + call center) that require SAQ D.

Level 3 Merchants

Criteria: 20,000 to 1 million Visa e-commerce transactions per year.

Validation requirements:

SAQ eligibility: SAQ A or A-EP are most common, but if the merchant stores, processes, or transmits cardholder data on-premises, SAQ D may be required.

Saudi context: Small-to-medium Saudi e-commerce stores, cloud-based payment gateways, and subscription-based services that process between 20k and 1M transactions. Many use Shopify, WooCommerce, or local Saudi payment gateways (e.g., PayTabs, HyperPay).

Level 4 Merchants

Criteria: Fewer than 20,000 Visa e-commerce transactions per year, and up to 1 million total transactions (non e-commerce).

Validation requirements:

SAQ eligibility: SAQ A is most common — but only if the merchant has fully outsourced all cardholder data processing to a PCI-compliant third party and does not store, process, or transmit any card data electronically.

Saudi context: Small Saudi restaurants, local service providers, and individual entrepreneurs using CPay or similar Saudi POS terminals. Many incorrectly assume they are exempt — but PCI DSS applies to any entity that accepts card payments, regardless of size.

Compliance Warning for Saudi Merchants: The Saudi Central Bank (SAMA) requires all licensed financial institutions to ensure their merchant clients maintain PCI DSS compliance. If your acquiring bank detects non-compliance, they may impose surcharges, increase reserve requirements, or terminate your merchant agreement. Even if you qualify for SAQ A, you must still submit an annual Attestation of Compliance to your acquiring bank.

Service Provider Levels

Service providers — including payment gateways, hosting providers, acquirers, and fraud detection platforms — are classified separately by Visa and the PCI SSC. The most widely used classification is Visa's service provider tiers:

Service Provider Tier
Annual Visa Transaction Volume
Validation Requirement
Typical Saudi Examples
Tier 1
Over 300,000
Annual ROC + quarterly scans
Saudi payment gateways (e.g., PayTabs, HyperPay, STC Pay)
Tier 2
Under 300,000
Annual SAQ D + quarterly scans
Saudi hosting providers, small MSPs
Tier 3 – High Risk
Any volume, if flagged
Full ROC + forensic investigation
Any Saudi service provider post-breach

Saudi fintech companies and payment service providers registered with SAMA are automatically expected to meet Tier 1 service provider requirements. The NCA ECC compliance services in Saudi Arabia framework also applies parallel controls for logging, monitoring, and incident response that align with PCI DSS requirements 10 and 12.

Unsure Which PCI DSS Level Applies to Your Saudi Business?

A misclassification can lead to audit failures or regulatory penalties. CyberSilo's experts help you determine your exact merchant or service provider level and build the evidence pack for your SAQ or ROC. Even if you have complex multi-channel processing, we can map your environment to the correct validation pathway.

SAQ Types and Which Level Can Use Them

The Self-Assessment Questionnaire (SAQ) is a validation tool for merchants and service providers that are not required to undergo a full on-site ROC. However, not all SAQs are available to all levels. The table below shows which SAQ types align with which PCI merchant level and processing environment.

SAQ Type
Intended For
Eligible Merchant Levels
Key Restriction
SAQ A
Card-not-present merchants that fully outsource all cardholder data processing to a PCI-compliant third party. No electronic storage, processing, or transmission of card data.
Level 3, 4
Cannot be used if you store any cardholder data electronically — even encrypted.
SAQ A-EP
E-commerce merchants that outsource payment processing but have some control over the payment page (e.g., iFrame or URL redirect).
Level 2, 3, 4
Requires that the payment page is hosted by a PCI-compliant third party.
SAQ B
Merchants using only standalone, dial-out POS terminals (no electronic cardholder data storage).
Level 2, 3, 4
Imprinters and paper-only terminals only.
SAQ B-IP
Merchants using standalone IP-based POS terminals with no electronic storage.
Level 2, 3, 4
Terminal must be isolated from other systems.
SAQ C-VT
Merchants using only web-based virtual terminals on a single, isolated PC (no electronic storage).
Level 2, 3, 4
Must not store any cardholder data electronically.
SAQ C
Merchants with payment application systems connected to the internet, but no electronic storage.
Level 2, 3, 4
Payment application must be isolated from other systems.
SAQ D (Merchant)
All other merchants not eligible for SAQ A through C-VT. For merchants that store, process, or transmit cardholder data.
Level 2, 3, 4
Most rigorous SAQ — requires full 12-requirement validation.
SAQ D (Service Provider)
Eligible service providers under 300,000 transactions annually.
Tier 2
Only for service providers that do not need a ROC.

Saudi merchants often assume they qualify for the simpler SAQ A, but our assessments show that over 40% of Saudi small-to-medium enterprises inadvertently store cardholder data in logs, databases, or email records — which immediately invalidates SAQ A eligibility and requires at minimum SAQ C or D. CyberSilo's PCI DSS compliance services in Saudi Arabia include a thorough cardholder data discovery scan to determine your actual SAQ eligibility.

Validation and Reporting Timeline by Level

The frequency of validation varies by level. Below is the typical schedule for Saudi entities:

Saudi organizations registered with SAMA must also align their PCI DSS validation cycle with SAMA CSF reporting requirements — often resulting in a combined assessment. CyberSilo's Compliance Standards Automation platform can synchronize PCI DSS validation tasks with NCA ECC and SAMA CSF calendars to eliminate redundant effort.

Automate Your PCI DSS Evidence Collection for Any Level

Whether you need a full ROC or an SAQ D, CyberSilo's platform maps every PCI DSS requirement (including all 12 requirements of v4.0.1) to your existing security controls. We help you avoid the common pitfalls that cause SAQ Type misclassification and ROC failures in Saudi audits.

Frequently Asked Questions

How do I know if I am a Level 1 or Level 2 merchant in Saudi Arabia?

Your PCI level is determined by your total Visa transaction volume over the previous 12 months. If you exceed 6 million Visa transactions, you are Level 1. Between 1 million and 6 million, you are Level 2. Your acquiring bank (e.g., SNB, Al Rajhi, Alinma) maintains this volume data and can confirm your classification. For non-Visa card schemes (Mastercard, Amex), similar volume thresholds apply but may vary slightly.

Can a Saudi e-commerce merchant use SAQ A if they use PayTabs or HyperPay?

Only if the merchant has entirely outsourced all cardholder data processing to the payment gateway and does not store, process, or transmit any cardholder data electronically. This means no customer database with stored PANs, no email containing full card numbers, and no log files with card data. Most Saudi e-commerce merchants who manage their own customer accounts or order history will require at minimum SAQ A-EP or SAQ D.

What happens if a Saudi merchant misclassifies their PCI DSS level?

Misclassification can result in submitting the wrong SAQ type, which may be rejected by your acquiring bank. In serious cases, the bank may flag you as non-compliant, impose higher transaction fees, increase reserve requirements, or terminate your merchant agreement. For SAMA-regulated entities, misclassification could also trigger regulatory scrutiny under SAMA CSF and NCA ECC frameworks.

Do I need a QSA for Level 2 in Saudi Arabia?

Level 2 merchants can typically use a SAQ, but many Saudi acquiring banks now require a ROC by a QSA if your environment involves complex or multiple processing channels. Additionally, if you are a Level 2 merchant that also serves as a service provider (e.g., you process payments for other businesses), you may be reclassified as a Tier 1 service provider and need a ROC.

How does PCI DSS Level 1 intersect with SAMA CSF in Saudi Arabia?

Both frameworks require robust access controls, logging and monitoring, vulnerability management, and incident response. SAMA CSF’s control domains (e.g., Cybersecurity Operations, Identity and Access Management) directly map to PCI DSS requirements 7, 8, 10, and 11. A combined assessment approach using a unified automation platform can reduce duplication and audit fatigue. CyberSilo's SAMA CSF compliance services in Saudi Arabia are designed to align both frameworks efficiently.

Our Conclusion & Recommendation

Determining your correct PCI DSS compliance level is not optional — it is the foundation of cardholder data security for Saudi enterprises. Misclassification, whether due to transaction volume miscalculation, incorrect SAQ selection, or oversight of service provider status, exposes your organization to compliance failures, financial penalties, and reputational risk. With the rapid expansion of Saudi fintech, e-government payment services, and digital banking under Vision 2030, the regulatory landscape is only tightening. SAMA and NCA now expect seamless alignment between PCI DSS and local frameworks.

CyberSilo recommends that every Saudi merchant and service provider conduct a level validation exercise at least annually, especially if your transaction volume is growing or you have recently added new payment channels. Our Compliance Standards Automation platform automates the evidence mapping for PCI DSS, NCA ECC, SAMA CSF, and CITC CRF simultaneously — so you never have to manage compliance in silos again.

Get Your PCI Level Confirmed in One Business Day

CyberSilo's team of PCI QSAs and compliance engineers will review your transaction volume, processing environment, and existing controls to confirm your exact level and SAQ eligibility — at no cost for the initial assessment.

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

What Are the Best Alternatives to Traditional Siem Platforms for Cloud Environments
SIEM
Mar 3, 2026 ⏱ 19 min

What Are the Best Alternatives to Traditional Siem Platforms for Cloud Environments

Explore cloud-native SIEM alternatives, SOAR platforms, and CSPM tools for scalable and automated cloud security solutions tailored to modern enterprises.

Read Article
What Are the Best Siem Tools That Integrate With Edr and Xdr
SIEM
Mar 3, 2026 ⏱ 15 min

What Are the Best Siem Tools That Integrate With Edr and Xdr

Explore the integration of SIEM tools with EDR and XDR platforms for enhanced cybersecurity, visibility, and incident response efficiency.

Read Article
What Platforms Combine Generative Ai With Siem or Soar Tools
SIEM
Mar 3, 2026 ⏱ 18 min

What Platforms Combine Generative Ai With Siem or Soar Tools

Explore how generative AI enhances SIEM and SOAR platforms, improving threat detection, automation, and security operations efficiency.

Read Article
Which Platform Integrates Cloud Security Monitoring With Siem
SIEM
Mar 3, 2026 ⏱ 14 min

Which Platform Integrates Cloud Security Monitoring With Siem

Explore effective integration of cloud security monitoring with SIEM for enhanced threat detection, compliance, and real-time visibility across environments.

Read Article
Which Siem Software Brands Are Known for Ensuring Strong Compliance
SIEM
Mar 3, 2026 ⏱ 16 min

Which Siem Software Brands Are Known for Ensuring Strong Compliance

Explore leading SIEM software brands enhancing compliance through automated reporting, real-time monitoring, and integration with key regulatory frameworks.

Read Article
Who Offers Siem Software With Built-in Compliance Reporting
SIEM
Mar 3, 2026 ⏱ 17 min

Who Offers Siem Software With Built-in Compliance Reporting

Explore how SIEM solutions with built-in compliance reporting enhance regulatory adherence, automate checks, and improve security governance for enterprises.

Read Article
✅ Link copied!