Cost by level
Level 4 PCI compliance cost: a Mastercard tier, not a Visa one
Visa folded its own level 4 into level 3 on 25 April 2024 and said the change altered nothing about what PCI DSS requires. Mastercard kept all four levels, so Level 4 is a Mastercard classification now and the same small merchant holds both labels at once. For most merchants this size the entire obligation is a 24-control SAQ A, and the thing that decides it is the checkout, not the volume.
Updated July 2026
Mastercard Level 4
Live
Defined by exclusion: any merchant not deemed Level 1, 2 or 3
Visa level 4
Retired
Consolidated into level 3 on 25 April 2024. You are a Visa level 3 merchant
SAQ A
~24
Controls under v4.0.1, against ~251 for SAQ D
Validation
Not required to Mastercard. Compliance still is
The Level 4 definition, and the label you did not notice changing
Level 4 is now a Mastercard classification only, and Mastercard defines it by exclusion: any merchant it does not deem Level 1, Level 2 or Level 3. In practice that means sitting below the Level 3 floor of 20,000 combined Mastercard and Maestro e-commerce transactions a year. Visa retired its own level 4 on 25 April 2024, consolidating it into level 3 and stating that the change introduced no alteration to existing PCI DSS compliance requirements. Mastercard did not follow. So the same corner shop is a Mastercard Level 4 merchant and a Visa level 3 merchant at the same time, which sounds like a contradiction and is simply two networks keeping their own books.
That matters for one practical reason: it tells you which published figures apply to you. The Visa numbers that attach to a small merchant are the level 3 ones, because that is what Visa now calls you. And it is a fast test of whoever is advising you. Anyone still sorting you into a Visa level 4 is working from a chart that stopped being true in April 2024.
| Network | Does it still have a Level 4 | What that means for a small merchant |
|---|---|---|
| Mastercard | Yes. All four levels, SPME 3 February 2026, section 2.2.2 | You are Level 4 by exclusion. Compliance with PCI DSS is required; validation to Mastercard is not, except where law or regulation demands it |
| Visa | No. Consolidated into level 3 on 25 April 2024 | You are a Visa level 3 merchant, and the published Visa breach-response figures for level 3 are the ones that apply to you |
| American Express | Yes. Fewer than 10,000 Amex transactions a year, DSOP April 2026 | Validation documentation is submitted only if American Express asks for it, at its discretion. The obligation to comply applies regardless |
| Discover | No. Three levels, not four | You sit in its lowest band, which is all merchants below its 1 million transaction Level 2 band |
| JCB | No merchant levels at all | No JCB row belongs in a merchant level table, however often you see one |
What actually sets a Level 4 bill
The obligation tracks your payment setup, not your transaction count, and that is the whole reason this tier is cheap when it is cheap. There are only a handful of lines, and the first one dominates the rest.
| Line | Priced against | What you control |
|---|---|---|
| The SAQ itself | Which questionnaire your payment method forces you into. The published control count is the honest measure: ~24 for SAQ A, 33 for SAQ P2PE, 41 for SAQ B, 79 for SAQ C-VT, 82 for SAQ B-IP, 160 for SAQ C, ~251 for SAQ D. | How you take payments. This is the single biggest lever at this level and it is an architecture decision, not a purchasing one. |
| Quarterly ASV scanning | The count of external IPs, hostnames or domains in scope, where your SAQ type calls for scanning at all. Requirement 11.3.2 fixes the quantity at four passing scans a year. | How many internet-facing targets sit in PCI scope. For many hosted-checkout merchants the honest answer is very few. |
| Remediation | Whatever the questionnaire surfaces. The least predictable line, and the one most likely to be the largest at this level. | How honestly you answer the SAQ the first time. A questionnaire that surfaces nothing has usually not been read properly. |
| Your processor's PCI fee | Your merchant agreement. It is not a card brand fine, it is not set by PCI DSS, and no processor or acquirer publishes a schedule of it. Two merchants on the same processor routinely see different numbers. | Whether it is a non-compliance fee, which completing the SAQ removes, or a programme fee, which is a contract term. Your statement says which. |
| Help completing it | Nothing published. No consultant or QSA firm publishes a rate for SAQ support. | Whether you need it at all. At ~24 controls on a hosted setup, many owners do not. |
The one published price at this level
Almost nothing in PCI has a list price. This tier has the exception, and it is worth quoting exactly rather than rounding into a range. SecurityMetrics, which is an Approved Scanning Vendor, publishes a list price of $399 per year for the product it calls "PCI for small businesses" (securitymetrics.com/pci-small-business-pricing, checked July 2026). Its published feature list for that price includes an external vulnerability scan for one IP, an online PCI Self Assessment Questionnaire, an online compliance reporting portal, compliance reporting to your merchant processor, PANscan card-discovery software for one machine, and one seat of security awareness training.
Read what that is before you treat it as a benchmark. It is one vendor's bundle for a single IP address, not an ASV scan rate and not a market price, and it does not tell you what anyone else charges. SecurityMetrics' own page carries an asterisk: "Price discounts available depending on merchant processor." Its general pricing page adds that SMB pricing varies based on packages from your acquiring bank. So the honest use of this figure is as a reference point for the smallest, simplest merchant, and as the question to put to your own acquirer: what does the equivalent cost through you, and is it already in what I pay?
The checkout decides everything else
A merchant whose customers enter card details on a page hosted by the processor never has cardholder data touch its own systems, and the questionnaire shrinks accordingly. Stripe states that it "is certified annually by an independent PCI Qualified Security Assessor (QSA) as a PCI Level 1 Service Provider meeting all PCI requirements", and that SAQ A applies to merchants using Checkout, Payment Links, or Stripe.js and Elements, because those host all card data collection inputs within an iframe served from Stripe's domain rather than yours, so customer card information never touches your servers (docs.stripe.com/security/guide and stripe.com/guides/pci-compliance, checked July 2026). That is a published statement from the platform about its own product, which is a different class of fact from a price, and it is the kind of thing worth confirming in writing with whoever processes your payments.
For card-present merchants the equivalent lever is a PCI-validated point-to-point encryption terminal, which puts you on SAQ P2PE at 33 controls rather than SAQ B-IP at 82 or SAQ D at roughly 251. The distinction that matters is validated: the solution must be on the PCI SSC's P2PE list, not merely a terminal described as encrypted. That difference is the entire benefit and it is easy to get wrong on a sales call.
The third lever is the one that costs nothing: right-size the questionnaire. Small merchants routinely complete SAQ C or SAQ D, at roughly 160 and roughly 251 controls, when their payment flow qualifies for something far shorter, and they pay for that in time and in scope they do not have. Confirming the right SAQ is a conversation with your acquirer or processor and changes nothing about your architecture. If your processor disagrees with your reading, PCI SSC FAQ #1158 covers the route: confirm the payment flow in writing, share architecture diagrams, escalate via your acquirer. Start from the SAQ types guide and read the eligibility criteria in the front of the questionnaire itself.
What the rules actually expose you to
Card brand assessments are levied on your acquirer, not on you. Visa's rule is explicit that the assessment lands on the Member, and Mastercard's Table 2.2 assesses the Customer. Neither brand has a contract with you. What reaches you is set by the indemnity clause of your own merchant agreement, which is a private contract and the only document where your number exists. If you read one thing after this page, read that clause.
| Mastercard SDP assessment, lowest published merchant band | 1st violation | 2nd | 3rd | 4th |
|---|---|---|---|---|
| Level 3 merchants, ceiling per violation per calendar year | Up to USD 10,000 | Up to USD 20,000 | Up to USD 40,000 | Up to USD 80,000 |
Source: Mastercard Security Rules and Procedures, Merchant Edition, 3 February 2026, section 2.2.5, Table 2.2. Mastercard prints no separate Level 4 merchant row; the lowest merchant band it publishes is the Level 3 one above. Read the column heading carefully: these are ceilings, per violation, per calendar year, and Mastercard's own wording is "up to". They are not monthly and they are not ranges. Mastercard also states that noncompliance may result in merchant termination, which is the tail risk that appears on no fee schedule.
Visa publishes no routine schedule for PCI DSS non-compliance: Rule 12.5.1.1 routes it to the Account Information Security Program Guide, which Visa does not publish. What Visa does publish is its breach-response assessments, and because you are a Visa level 3 merchant, these are yours:
| Visa classification | Transaction band | Assessment |
|---|---|---|
| Level 3 merchants | 500,000 - 1,000,000 | USD $25K |
| Level 3 merchants | 100,000 - 500,000 | USD $10K |
| Level 3 merchants | 1 - 100,000 | USD $5K |
Source: Visa, What To Do If Compromised, Visa Supplemental Requirements v10.0, effective 25 June 2026, section 9. These attach to the WTDIC breach-response requirements rather than to PCI DSS non-compliance generally. Section 8 adds that where Visa requires a PCI forensic investigation and it remains open past a four full calendar month grace period, a level 3 merchant pays a USD $3,000 one-time flat fee, against USD $10,000 per month for level 1 and level 2 merchants. And Rule 12.5.1.3 provides for an assessment of up to USD 100,000 per incident for failing to report a suspected or confirmed compromise within three calendar days. Every one of these is levied on the Member. Figures last verified 17 July 2026; full detail on the penalties page.
That PCI line on your statement
It is the most-asked question at this level and it has a short answer: no processor publishes the amount, so nobody can tell you what yours is except your own statement. It is a term of the merchant agreement you signed, not a card brand fine and not something PCI DSS sets, which is exactly why two merchants on the same processor see different numbers. Open the last monthly statement and read the fee schedule rather than the summary total. The wording usually tells you which of two charges it is.
A PCI programme or compliance fee is charged whether or not you are compliant, and usually bundles a portal, an SAQ tool and sometimes scanning. Completing your questionnaire does not remove it, because it is a contract term, so that one is a renewal conversation. A PCI non-compliance fee is charged because you have not completed your SAQ, and that one you can remove: complete the questionnaire through whichever portal your processor names, then check the next one or two statements to confirm it has dropped off. Either way, paying it does not make you compliant, which is the misunderstanding the name invites. More on the processor fees page.
Get the PCI SSC SAQ documents
The PCI SSC publishes every SAQ type in its official document library, each with its eligibility criteria printed in the front. For a merchant this size, confirming which questionnaire you actually qualify for, before scoping anything else, is the single biggest cost saver and it is free.
Frequently asked
Nobody publishes a general answer, and any specific total you find is somebody's estimate rather than a quoted rate: no acquirer publishes its PCI fee schedule, no consultant publishes a rate card, and only one ASV publishes any price at all. What can be said is what your bill is made of at this level, and it is short. The SAQ your payment setup forces you into is the whole game: SAQ A carries roughly 24 controls under v4.0.1 against roughly 251 for SAQ D, and a fully hosted checkout is what puts you on the right side of that line. Quarterly ASV scanning applies where your SAQ type calls for it, at four passing scans a year under Requirement 11.3.2. Remediation costs whatever the questionnaire surfaces. And there is one real published price worth knowing: SecurityMetrics lists $399 a year for its "PCI for small businesses" product (securitymetrics.com/pci-small-business-pricing, checked July 2026), which bundles an external vulnerability scan for a single IP, an online SAQ, a compliance portal, PANscan for one machine and one training seat. That is one vendor's list price for a single-IP bundle, not a market rate, and SecurityMetrics' own page notes that discounts vary by merchant processor.
Continue reading
Level 3 PCI cost
The tier Visa folded its level 4 into, and where Requirement 6.4.3 bites.
SAQ A
The 24-control questionnaire most hosted-checkout merchants want.
Processor PCI fees
That charge on your statement, and which of the two kinds it is.
SAQ types guide
Match your payment flow to the right questionnaire, sized in controls.
Reduce PCI costs
Scope reduction, measured in controls rather than guesses.
Non-compliance penalties
What Visa and Mastercard actually publish, and what they do not.