PCI ASV Scan Cost by Merchant Level (1–4)

Published on

Updated on

Key Takeaways
  • ASV scan cost by merchant level depends less on your level number and more on how many IP addresses and domains sit inside your cardholder data environment (CDE).
  • All four merchant levels require quarterly external ASV scans; the schedule doesn't get stricter as your level goes up.
  • Level 1 and Level 2 merchants often carry a heavier total compliance bill because of QSA-led audits, not because their scans cost more per IP.
  • Typical PCI ASV scan pricing runs $150–$3,200/year based on scope; total PCI compliance cost by level ranges from $1,000/year (Level 4) to $250,000+/year (Level 1).
  • Vendor pricing model (flat-rate vs. per-IP), network segmentation, and rescan policy move your bill more than your merchant level classification does on its own.

ASV scan cost by merchant level is one of the most-searched budgeting questions among businesses preparing for PCI DSS compliance, and it’s also one of the most commonly misunderstood. Most guidance treats “what’s my merchant level” and “what will scanning cost me” as separate questions with separate answers. They aren’t. Your merchant level sets how you validate compliance; your scan scope and vendor pricing model set what you actually pay each quarter.

This guide puts both pieces together: the Level 1 through Level 4 thresholds, how each level changes your scan obligations, and the real cost ranges you should budget for, whether you’re a Level 4 small business running a single storefront or a Level 1 enterprise managing a sprawling, multi-domain environment.

Key Definitions

Merchant Level: A classification (1–4) assigned by card brands, primarily Visa and Mastercard, based on annual card transaction volume, which determines how rigorously a merchant must validate PCI DSS compliance.

Approved Scanning Vendor (ASV): A company approved by the PCI Security Standards Council (PCI SSC) to perform external vulnerability scans of a merchant's internet-facing infrastructure, as required under PCI DSS Requirement 11.3.2.

External Vulnerability Scan: An automated scan run from outside the network to detect publicly exposed vulnerabilities across IP addresses and domains inside the CDE.

Cardholder Data Environment (CDE): The systems, network segments, and processes that store, process, or transmit cardholder data, and the scope boundary for both ASV scans and broader PCI DSS assessments.

SAQ (Self-Assessment Questionnaire): A self-administered compliance checklist used by lower-tier merchants (typically Levels 2–4).

ROC (Report on Compliance): A formal, QSA-audited compliance report required of the highest-volume merchants (typically Level 1, and sometimes Level 2).

What Are PCI Merchant Levels 1–4?

Your merchant level is based purely on annual transaction count, not revenue, company size, or industry, and it determines your validation path more than your scan schedule.

Level
Annual Transaction Volume
Validation Method
Level 1
Over 6 million transactions (any channel)
Annual ROC via on-site QSA audit
Level 2
1 million–6 million transactions
Annual SAQ + AOC (QSA-assisted in some cases)
Level 3
20,000–1 million e-commerce transactions
Annual SAQ + AOC
Level 4
Under 20,000 e-commerce transactions, or up to 1 million total
Annual SAQ (acquirer requirements vary)

Thresholds are set by Visa and Mastercard and broadly mirrored by American Express, Discover, and JCB, though your acquiring bank has the final say on which level applies to you and may layer on its own requirements. One wrinkle worth flagging: any merchant, at any level, can be reclassified as Level 1 following a card data breach, regardless of transaction volume.

Not Sure What Your Scan Scope Actually Costs?

Get a straightforward, scope-based quote instead of guessing from generic pricing tables.

How Merchant Level Affects Your ASV Scan Requirements and Scope

Scan frequency stays flat across all four levels: quarterly, no exceptions, but scan scope and overall validation burden grow with level, and that's where the real PCI merchant-level cost differences show up.

  • Level 1 merchants face the highest overall compliance investment, not because their scans are priced differently, but because their environments are typically large and distributed; dozens or hundreds of IP addresses spread across data centres, cloud infrastructure, and third-party systems. On top of quarterly ASV scans, Level 1 merchants must complete an annual ROC through a QSA, layering formal audit costs on top of the scan fee itself.

 

  • Level 2 merchants sit just below Level 1 in complexity. They complete an annual SAQ rather than a full ROC, which meaningfully reduces the audit side of the bill, but the quarterly scan requirement is unchanged. Scan scope here still depends heavily on how well the network is segmented; a tightly scoped Level 2 environment can cost less to scan than a poorly segmented Level 3 one.

 

  • Level 3 merchants typically manage smaller, more contained environments, with fewer IP addresses and less infrastructure to assess. Most ASV vendors offer mid-tier pricing packages well-suited to this tier, and accurate scoping, making sure the scan covers only what’s actually in the CDE, is the main lever for keeping costs down.

 

  • Level 4 merchants, the largest segment of the merchant population by count, generally have the smallest scan footprint; often a single domain or a handful of IPs behind a hosted checkout. Requirements at this level are set by individual acquiring banks rather than uniformly mandated by card brands, but most banks do require quarterly scans as a condition of compliance. This is also the tier where vendor pricing transparency matters most, since Level 4 businesses are often managing compliance on the leanest budgets.

What Drives PCI ASV Scan Pricing

The number of IP addresses and domains in scope is the single biggest driver of PCI ASV scan pricing, more so than the merchant level itself.

Number of IPs and domains in scope. Vendors that charge a price per IP, incrementally for every address included in the scan. A poorly segmented network, even at a lower merchant level, can end up with a larger, more expensive scan scope than a well-segmented Level 1 environment. Proper network segmentation, isolating the CDE from the rest of the network, is one of the few compliance best practices that also directly reduces cost.

Vendor pricing model. Some ASVs charge per IP, per domain, or per scan, which creates unpredictable bills as infrastructure grows. Others offer flat-rate or bundled pricing covering a defined number of IPs or an unlimited scope within a subscription tier. Flat-rate pricing tends to give growing businesses more budget predictability.

Network complexity and remediation. Merchants with distributed environments, multiple locations, cloud-hosted systems, and third-party integrations are more likely to trigger scan findings that need remediation before a passing result is achieved. Some vendors charge separately for rescans after remediation; others bundle unlimited rescans into the annual fee. That clause is worth reading closely, since a single failing scan and rescan cycle can add hundreds of dollars per quarter.

PCI ASV Scan Cost by Merchant Level: Typical Ranges

Separate the ASV scan fee from the total PCI compliance cost; conflating the two is where most budgeting goes wrong.

ASV scan cost alone (scales with scope, not level directly)

Environment Size
IPs/Domains in Scope
Typical Annual Scan Cost
Small
1–10
$150 – $1,200
Mid-market
10–50
$1,200 – $3,200
Enterprise
50–200+
$5,000 – $15,000+

A Level 4 merchant with a large, multi-domain footprint can pay more for scanning than a Level 2 merchant running a single hosted storefront. Scope, not level, is the driver.

Total PCI compliance cost by level (scan + validation + audit where applicable)

Level
Typical Annual Range
Why
Level 4
$1,000 – $10,000
SAQ + scans; light validation burden
Level 3
$5,000 – $20,000
SAQ + scans; more scope review
Level 2
$10,000 – $50,000
SAQ/AOC, possible QSA involvement
Level 1
$50,000 – $250,000+
Full QSA-led ROC, on-site audit, extensive documentation

The real cost jump isn’t between scan fees; it’s between Level 2/3 (self-assessed) and Level 1 (formally audited). That’s where budgets should concentrate planning time.

Confused About Which Merchant Level Applies to You?

: Answer a few quick questions about your payment flow and infrastructure to find out in seconds.

How to Choose an ASV Vendor and Control Compliance Costs

A PCI SSC-approved vendor with transparent, scope-based pricing and included rescans will control your PCI compliance cost by level far more reliably than chasing the lowest headline price.

Every vendor you consider must hold current PCI SSC approval; scan results from a non-approved vendor simply aren’t valid for PCI DSS purposes, no matter how thorough the scan is technically. Verify approval status directly against the PCI SSC’s published ASV list before signing up. Beyond approval status, look past the sticker price. Compare what’s included at each tier: how many IPs or domains the plan covers, whether remediation guidance is included, how fast results come back, and, critically, what happens if a scan fails.

A vendor that bundles unlimited rescans and remediation support into the annual fee is often better value than one with a lower list price but per-incident rescan charges. For SMBs and Level 3–4 merchants especially, pricing transparency matters more than feature depth. Secusy ASV, for example, is built around PCI-approved scanning with straightforward, scope-based pricing rather than opaque per-incident billing the kind of predictability that smaller compliance teams need most.

Conclusion

Your merchant level tells you which PCI compliance SAQ or ROC you’ll use, but your scan scope, your vendor’s pricing model, and how well your network is segmented actually set your bill. Quarterly ASV scans apply equally at every level; what changes is everything around them. Know your level, scope your CDE accurately, and choose a PCI SSC-approved vendor with transparent, predictable pricing; that combination does more for your compliance budget than trying to game your merchant level classification ever could.

Manage Compliance for Multiple Clients?

Partner with a PCI-approved ASV and offer scanning as part of your own service stack.

Frequently Asked Questions

No. All merchant levels require quarterly external ASV scans under PCI DSS Requirement 11.3.2. Level changes how you validate compliance overall, not how often you scan.

Scan cost tracks IP/domain scope more than the level itself; typically $150–$1,200/year for small environments up to $5,000–$15,000+/year for large, enterprise-scale scopes.

Yes. A significant jump in transaction volume, or a card data breach, can move you to a higher level, sometimes straight to Level 1 in the case of a breach, regardless of prior volume.

No. Pricing models vary widely; some vendors charge per IP address, others offer flat-rate or bundled plans. Rescan policy after a failed scan is another major cost variable to compare.

Reduce scope. Segmenting your network to isolate the cardholder data environment, or moving to a fully hosted checkout, shrinks both your scan footprint and your validation burden.
No. QSA involvement is mandatory for Level 1 (ROC) and sometimes required or recommended by acquirers for Level 2. Levels 3 and 4 typically self-certify via SAQ.
In most cases, yes. While Level 4 requirements are set by individual acquiring banks rather than uniformly by card brands, most banks require quarterly ASV scans as a condition of compliance. Confirm directly with your acquirer.
Check the vendor against the PCI Security Standards Council's published list of approved ASVs before engaging them. Scan results from a non-approved vendor are not valid for PCI DSS compliance.

Authored by

Binoy Koonammavu blog image

Binoy Koonammavu, is the Founder and CEO of Secusy ASV, where he helps SMBs and fintech companies meet PCI DSS scanning requirements without the complexity of enterprise-grade tools. His writing focuses on making ASV compliance straightforward for growing businesses.

Share:

Related Post

 

Discover more from Secusy ASV

Subscribe now to keep reading and get access to the full archive.

Continue reading