Q: What Volume Determines PCI DSS Requirements? A: Read on
June 19, 2009
This is a question as a PCI QSA i’m always asked, that is, “What volume or transaction level will ultimately determine my PCI DSS compliance requirements?
Well, here you go:
For Merchants, this is the information you need to know about volume and transaction levels.
For Service Providers, this is the information you need to know about volume and transaction levels.
Keep in mind that for service providers seeking to become Payment Card Industry Data Security Standards (PCI DSS) compliant, most, if not all, will essentially have to undertake a Level 1 PCI DSS annual on-site assessment, which culminates with the issuance of a PCI DSS Report on Compliance, simply known as the ROC.

