forumNew topic

Does PCI DSS Level 1 apply to us — which level fits our transaction volume?

NNazlı Ş***New member
Job title
Product Manager
Sector
Healthcare services
Organization type
20-person company
Joined
Jun 2026
Message
351

Doki · Infrastructure migration · 2023

#1

We run two brick-and-mortar apparel stores and a WordPress-based e-commerce site. Annually, we process about 40,000 card payments through our in-store POS terminals and about 110,000 online via our contracted payment gateway. That puts our total volume across all channels at 150,000 transactions per year. We never store card details on our server; when a customer clicks pay, they're redirected to the payment provider's hosted checkout page or the transaction completes inside an iframe.

Last week, our acquiring bank sent over an information security questionnaire asking about our PCI DSS compliance status. While trying to figure out what was needed, we talked to a cybersecurity consulting firm that claimed we fall squarely under PCI DSS Level 1, requiring an on-site assessment (QSA) and detailed penetration testing. Their quote came out to around 180,000 TL.

Does a business like ours with under 200k transactions a year actually have to meet Level 1 requirements? How are the tiers determined based on transaction volume, and what exactly do we need to do?

YYağmur Y***Member
Job title
Administrative manager
Sector
Furniture manufacturing
Organization type
medium-sized business
Joined
Dec 2024
Message
2

Doki · Log management setup · 2025

Most Helpful#2

Short answer: No, with an annual volume of 150,000 transactions you are nowhere near PCI DSS Level 1, and you are not required to undergo an on-site external audit. Under major card brand rules, Level 1 applies strictly to merchants processing over 6 million transactions annually or those that have suffered a serious card data breach; your business falls under Level 4.

Payment card security levels are determined by annual transaction count. In e-commerce, merchants doing between 20,000 and 1 million transactions per year generally fall into Level 3, while those under 20,000 are Level 4. Even combining your in-store and online volume, you don't come anywhere close to the Level 1 threshold. Neither tier requires an independent auditor to spend weeks on-site at your office.

In your situation, compliance means completing a Self-Assessment Questionnaire (SAQ) based on how your systems interact with card data. Because you use an iframe or a hosted payment page, card numbers never touch your servers. Under this setup, the document you need is usually SAQ A (which has very few requirements) or potentially SAQ A-EP, depending on your exact page implementation.

The first thing you should do is disregard that firm's expensive audit quote and contact merchant services at your acquiring bank or payment gateway. Clarify that you don't store card data and that you use the provider's redirect/hosted checkout solution, then ask them in writing which SAQ form they require from you.

SSultan Ö***Expert
Job title
Data entry clerk
Sector
Sports and fitness
Organization type
early-stage startup
Joined
Feb 2023
Message
10
#3

It really hinges on whether your site uses an iframe or a direct JavaScript library. If it's a redirect or a standard iframe, you just fill out SAQ A, which is basically checking yes/no on 22-25 items. But if the payment form renders on your own domain, that's SAQ A-EP, which requires quarterly external ASV scans.

AAli R***Expert
Job title
Angel Investor
Organization type
two-branch business
Joined
Jun 2023
Message
192
#4

That consulting firm is just using textbook fear marketing. I’ve been managing e-commerce infrastructure for 15 years, and I’ve never seen an SME that doesn't clear the 6 million threshold get classified as Level 1. The form the bank sent you is most likely just a boilerplate template they send out for routine annual checks. Ask your bank rep which SAQ type applies to you, don't waste money on an unnecessary audit.

DDoruk T***Veteran
Job title
Human Resources Specialist
Sector
Furniture manufacturing
Organization type
8-person team
Joined
Sep 2025
Message
2
#5

Notifications sent by banks are generally required under BDDK regulations and the annual inventory updates mandated by international card schemes. It should suffice to provide your bank with an official letter stating your transaction volume, confirming that you do not store card data, and clarifying that cardholder data is routed directly through a licensed payment institution's infrastructure.

NNazlı T***Member
Job title
Social media manager
Sector
Packaging
Organization type
medium-sized business
Joined
Nov 2023
Message
58
#6

Has there ever been any suspected card breach on your system in the past, or an unusual wave of chargebacks flagged by the banks? Because even with low transaction volumes, card brands can unilaterally bump a company to Level 1 if a security incident was identified. If nothing like that happened, the quote is completely unjustified.

SSinan T***MemberCommunity member
Joined
Sep 2025
Message
12
#7

we use a virtual POS too but where do we doownload this SAQ form and where do we submit it? does an external specialist have to sign off on it, or is a company representative's signature enough?

CCaner G***MemberCommunity member
Joined
Aug 2023
Message
218
#8

Before spending a single cent, log into your payment gateway's portal. Most payment providers provide their own PCI DSS certificate and a pre-filled SAQ attestation for you under the compliance tab for free. Downloading that and forwarding it to the bank usually sorts it right out.

BBurak G***Member
Job title
Logistics planning
Sector
Livestock
Organization type
early-stage startup
Joined
Oct 2024
Message
29
#9

We went through the exact same thing last year with similar volume. We filled out the SAQ A form, stamped it, sent it to the bank, and that was it. We just had external vulnerability scans run twice a year on our site, which cost us around 6.000 TL in total. 180.000 TL is straight-up highway robbery.

FFatma B***Member
Job title
Project manager
Sector
Media and publishing
Organization type
8-person team
Joined
May 2024
Message
164
#10

The cheap-looking path usually ends up costing more later. Having backups accessible on the same network and with the same identity makes them part of the target.

That's all, sorry if I went on too long.

İİlknur Y***VeteranCommunity member
Joined
Jul 2022
Message
3
#11

Correct. If you scold false alarms, nobody will report again.

Correct me if I'm wrong.

EEmre A***Member
Job title
Warehouse Manager
Sector
Automotive aftermarket
Organization type
sole proprietorship
Joined
Mar 2023
Message
370
#12

The cheap-looking path usually ends up costing more later. Most incidents start with a leaked password, not a vulnerability.

Hope this helps.

PPolat Y***ExpertCommunity member
Joined
May 2023
Message
54
#13

This thread is archived.

SSerkan Ç***VeteranCommunity member
Joined
May 2023
Message
294
#14

I think differently. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Hope this helps.

HHasan G***MemberCommunity member
Joined
Jan 2025
Message
144
#15

don't miss this: If you don't write this down from the start it leads to arguments later.

LLemanNew member
Job title
Healthcare worker
Joined
Oct 2024
Message
30

Doki · Incident response support · 2024

#16

there's also a measurement aspecct to this... if you scold false alarms nobody will report again.

taking measures without an inventory leaves doors you haven't seen open.

TTuğçe M***Member
Job title
Operations manager
Sector
Logistics
Organization type
two-branch business
Joined
Jan 2023
Message
362
#17

This is exactly what we experienced. Security isn't absolute; it's about making attacks not worth the effort.

I'm also curious if anyone does it differently.

AAyşe A***Member
Job title
Customer service representative
Sector
Automotive aftermarket
Organization type
chain store
Joined
Feb 2023
Message
29
#18

I agree. When making decisions, write down the worst-case scenario too not just the best.

Payment information changes are never verified through the channel they came from. Correct me if I'm wrong.

PPolat S***MemberCommunity member
Joined
Mar 2024
Message
110
#19

This approach has a cost which isn't discussed. Processes without records never improve because you don't know what to fix.

If you have questions, write them; I'll answer as best I can.

EEsra T***Member
Job title
Data Analyst
Sector
Livestock
Organization type
workshop
Joined
Feb 2024
Message
66
#20

quik summary for newcomers: Everything goes well for the first three months; problems arise in the fourth.

proven by experience.

Reply