Who determines the compliance validation level for a merchant?
- A.The payment brand (such as Visa, Mastercard) and/or the acquiring bank determine the validation level based on transaction volume
- B.The merchant decides its own level
- C.The merchant's QSA determines the level, a company qualified by the PCI Security Standards Council rather than by the individual card brands
- D.The PCI SSC assigns levels directly, which the v4.0 applicability notes single out as the one control area assessors may verify by inquiry alone
Why A is correct
Payment brands and acquiring banks determine a merchant's compliance validation level, typically based on annual transaction volume, with different requirements for each level.
Know someone studying for PCI DSS? Send them this one.