Cost by level

Level 4 PCI compliance cost: a Mastercard tier, not a Visa one

Visa folded its own level 4 into level 3 on 25 April 2024 and said the change altered nothing about what PCI DSS requires. Mastercard kept all four levels, so Level 4 is a Mastercard classification now and the same small merchant holds both labels at once. For most merchants this size the entire obligation is a 24-control SAQ A, and the thing that decides it is the checkout, not the volume.

Updated July 2026

Mastercard Level 4

Live

Defined by exclusion: any merchant not deemed Level 1, 2 or 3

Visa level 4

Retired

Consolidated into level 3 on 25 April 2024. You are a Visa level 3 merchant

SAQ A

~24

Controls under v4.0.1, against ~251 for SAQ D

Validation

Not required to Mastercard. Compliance still is

The Level 4 definition, and the label you did not notice changing

Level 4 is now a Mastercard classification only, and Mastercard defines it by exclusion: any merchant it does not deem Level 1, Level 2 or Level 3. In practice that means sitting below the Level 3 floor of 20,000 combined Mastercard and Maestro e-commerce transactions a year. Visa retired its own level 4 on 25 April 2024, consolidating it into level 3 and stating that the change introduced no alteration to existing PCI DSS compliance requirements. Mastercard did not follow. So the same corner shop is a Mastercard Level 4 merchant and a Visa level 3 merchant at the same time, which sounds like a contradiction and is simply two networks keeping their own books.

That matters for one practical reason: it tells you which published figures apply to you. The Visa numbers that attach to a small merchant are the level 3 ones, because that is what Visa now calls you. And it is a fast test of whoever is advising you. Anyone still sorting you into a Visa level 4 is working from a chart that stopped being true in April 2024.

NetworkDoes it still have a Level 4What that means for a small merchant
MastercardYes. All four levels, SPME 3 February 2026, section 2.2.2You are Level 4 by exclusion. Compliance with PCI DSS is required; validation to Mastercard is not, except where law or regulation demands it
VisaNo. Consolidated into level 3 on 25 April 2024You are a Visa level 3 merchant, and the published Visa breach-response figures for level 3 are the ones that apply to you
American ExpressYes. Fewer than 10,000 Amex transactions a year, DSOP April 2026Validation documentation is submitted only if American Express asks for it, at its discretion. The obligation to comply applies regardless
DiscoverNo. Three levels, not fourYou sit in its lowest band, which is all merchants below its 1 million transaction Level 2 band
JCBNo merchant levels at allNo JCB row belongs in a merchant level table, however often you see one

What actually sets a Level 4 bill

The obligation tracks your payment setup, not your transaction count, and that is the whole reason this tier is cheap when it is cheap. There are only a handful of lines, and the first one dominates the rest.

LinePriced againstWhat you control
The SAQ itselfWhich questionnaire your payment method forces you into. The published control count is the honest measure: ~24 for SAQ A, 33 for SAQ P2PE, 41 for SAQ B, 79 for SAQ C-VT, 82 for SAQ B-IP, 160 for SAQ C, ~251 for SAQ D.How you take payments. This is the single biggest lever at this level and it is an architecture decision, not a purchasing one.
Quarterly ASV scanningThe count of external IPs, hostnames or domains in scope, where your SAQ type calls for scanning at all. Requirement 11.3.2 fixes the quantity at four passing scans a year.How many internet-facing targets sit in PCI scope. For many hosted-checkout merchants the honest answer is very few.
RemediationWhatever the questionnaire surfaces. The least predictable line, and the one most likely to be the largest at this level.How honestly you answer the SAQ the first time. A questionnaire that surfaces nothing has usually not been read properly.
Your processor's PCI feeYour merchant agreement. It is not a card brand fine, it is not set by PCI DSS, and no processor or acquirer publishes a schedule of it. Two merchants on the same processor routinely see different numbers.Whether it is a non-compliance fee, which completing the SAQ removes, or a programme fee, which is a contract term. Your statement says which.
Help completing itNothing published. No consultant or QSA firm publishes a rate for SAQ support.Whether you need it at all. At ~24 controls on a hosted setup, many owners do not.

The one published price at this level

Almost nothing in PCI has a list price. This tier has the exception, and it is worth quoting exactly rather than rounding into a range. SecurityMetrics, which is an Approved Scanning Vendor, publishes a list price of $399 per year for the product it calls "PCI for small businesses" (securitymetrics.com/pci-small-business-pricing, checked July 2026). Its published feature list for that price includes an external vulnerability scan for one IP, an online PCI Self Assessment Questionnaire, an online compliance reporting portal, compliance reporting to your merchant processor, PANscan card-discovery software for one machine, and one seat of security awareness training.

Read what that is before you treat it as a benchmark. It is one vendor's bundle for a single IP address, not an ASV scan rate and not a market price, and it does not tell you what anyone else charges. SecurityMetrics' own page carries an asterisk: "Price discounts available depending on merchant processor." Its general pricing page adds that SMB pricing varies based on packages from your acquiring bank. So the honest use of this figure is as a reference point for the smallest, simplest merchant, and as the question to put to your own acquirer: what does the equivalent cost through you, and is it already in what I pay?

The checkout decides everything else

A merchant whose customers enter card details on a page hosted by the processor never has cardholder data touch its own systems, and the questionnaire shrinks accordingly. Stripe states that it "is certified annually by an independent PCI Qualified Security Assessor (QSA) as a PCI Level 1 Service Provider meeting all PCI requirements", and that SAQ A applies to merchants using Checkout, Payment Links, or Stripe.js and Elements, because those host all card data collection inputs within an iframe served from Stripe's domain rather than yours, so customer card information never touches your servers (docs.stripe.com/security/guide and stripe.com/guides/pci-compliance, checked July 2026). That is a published statement from the platform about its own product, which is a different class of fact from a price, and it is the kind of thing worth confirming in writing with whoever processes your payments.

For card-present merchants the equivalent lever is a PCI-validated point-to-point encryption terminal, which puts you on SAQ P2PE at 33 controls rather than SAQ B-IP at 82 or SAQ D at roughly 251. The distinction that matters is validated: the solution must be on the PCI SSC's P2PE list, not merely a terminal described as encrypted. That difference is the entire benefit and it is easy to get wrong on a sales call.

The third lever is the one that costs nothing: right-size the questionnaire. Small merchants routinely complete SAQ C or SAQ D, at roughly 160 and roughly 251 controls, when their payment flow qualifies for something far shorter, and they pay for that in time and in scope they do not have. Confirming the right SAQ is a conversation with your acquirer or processor and changes nothing about your architecture. If your processor disagrees with your reading, PCI SSC FAQ #1158 covers the route: confirm the payment flow in writing, share architecture diagrams, escalate via your acquirer. Start from the SAQ types guide and read the eligibility criteria in the front of the questionnaire itself.

What the rules actually expose you to

Card brand assessments are levied on your acquirer, not on you. Visa's rule is explicit that the assessment lands on the Member, and Mastercard's Table 2.2 assesses the Customer. Neither brand has a contract with you. What reaches you is set by the indemnity clause of your own merchant agreement, which is a private contract and the only document where your number exists. If you read one thing after this page, read that clause.

Mastercard SDP assessment, lowest published merchant band1st violation2nd3rd4th
Level 3 merchants, ceiling per violation per calendar yearUp to USD 10,000Up to USD 20,000Up to USD 40,000Up to USD 80,000

Source: Mastercard Security Rules and Procedures, Merchant Edition, 3 February 2026, section 2.2.5, Table 2.2. Mastercard prints no separate Level 4 merchant row; the lowest merchant band it publishes is the Level 3 one above. Read the column heading carefully: these are ceilings, per violation, per calendar year, and Mastercard's own wording is "up to". They are not monthly and they are not ranges. Mastercard also states that noncompliance may result in merchant termination, which is the tail risk that appears on no fee schedule.

Visa publishes no routine schedule for PCI DSS non-compliance: Rule 12.5.1.1 routes it to the Account Information Security Program Guide, which Visa does not publish. What Visa does publish is its breach-response assessments, and because you are a Visa level 3 merchant, these are yours:

Visa classificationTransaction bandAssessment
Level 3 merchants500,000 - 1,000,000USD $25K
Level 3 merchants100,000 - 500,000USD $10K
Level 3 merchants1 - 100,000USD $5K

Source: Visa, What To Do If Compromised, Visa Supplemental Requirements v10.0, effective 25 June 2026, section 9. These attach to the WTDIC breach-response requirements rather than to PCI DSS non-compliance generally. Section 8 adds that where Visa requires a PCI forensic investigation and it remains open past a four full calendar month grace period, a level 3 merchant pays a USD $3,000 one-time flat fee, against USD $10,000 per month for level 1 and level 2 merchants. And Rule 12.5.1.3 provides for an assessment of up to USD 100,000 per incident for failing to report a suspected or confirmed compromise within three calendar days. Every one of these is levied on the Member. Figures last verified 17 July 2026; full detail on the penalties page.

That PCI line on your statement

It is the most-asked question at this level and it has a short answer: no processor publishes the amount, so nobody can tell you what yours is except your own statement. It is a term of the merchant agreement you signed, not a card brand fine and not something PCI DSS sets, which is exactly why two merchants on the same processor see different numbers. Open the last monthly statement and read the fee schedule rather than the summary total. The wording usually tells you which of two charges it is.

A PCI programme or compliance fee is charged whether or not you are compliant, and usually bundles a portal, an SAQ tool and sometimes scanning. Completing your questionnaire does not remove it, because it is a contract term, so that one is a renewal conversation. A PCI non-compliance fee is charged because you have not completed your SAQ, and that one you can remove: complete the questionnaire through whichever portal your processor names, then check the next one or two statements to confirm it has dropped off. Either way, paying it does not make you compliant, which is the misunderstanding the name invites. More on the processor fees page.

Get the PCI SSC SAQ documents

The PCI SSC publishes every SAQ type in its official document library, each with its eligibility criteria printed in the front. For a merchant this size, confirming which questionnaire you actually qualify for, before scoping anything else, is the single biggest cost saver and it is free.

PCI SSC document library

Frequently asked

Nobody publishes a general answer, and any specific total you find is somebody's estimate rather than a quoted rate: no acquirer publishes its PCI fee schedule, no consultant publishes a rate card, and only one ASV publishes any price at all. What can be said is what your bill is made of at this level, and it is short. The SAQ your payment setup forces you into is the whole game: SAQ A carries roughly 24 controls under v4.0.1 against roughly 251 for SAQ D, and a fully hosted checkout is what puts you on the right side of that line. Quarterly ASV scanning applies where your SAQ type calls for it, at four passing scans a year under Requirement 11.3.2. Remediation costs whatever the questionnaire surfaces. And there is one real published price worth knowing: SecurityMetrics lists $399 a year for its "PCI for small businesses" product (securitymetrics.com/pci-small-business-pricing, checked July 2026), which bundles an external vulnerability scan for a single IP, an online SAQ, a compliance portal, PANscan for one machine and one training seat. That is one vendor's list price for a single-IP bundle, not a market rate, and SecurityMetrics' own page notes that discounts vary by merchant processor.

Continue reading