- Job title
- Product Manager
- Sector
- Healthcare services
- Organization type
- 20-person company
- Joined
- Jun 2026
- Message
- 351
Doki · Infrastructure migration · 2023
We run two brick-and-mortar apparel stores and a WordPress-based e-commerce site. Annually, we process about 40,000 card payments through our in-store POS terminals and about 110,000 online via our contracted payment gateway. That puts our total volume across all channels at 150,000 transactions per year. We never store card details on our server; when a customer clicks pay, they're redirected to the payment provider's hosted checkout page or the transaction completes inside an iframe.
Last week, our acquiring bank sent over an information security questionnaire asking about our PCI DSS compliance status. While trying to figure out what was needed, we talked to a cybersecurity consulting firm that claimed we fall squarely under PCI DSS Level 1, requiring an on-site assessment (QSA) and detailed penetration testing. Their quote came out to around 180,000 TL.
Does a business like ours with under 200k transactions a year actually have to meet Level 1 requirements? How are the tiers determined based on transaction volume, and what exactly do we need to do?