When people think about PCI DSS, the focus is usually on security requirements and compliance duties. But before you jump into controls and assessments it’s good to figure out who PCI DSS actually covers. One of the main kinds of entities subject to PCI DSS is the merchant, meaning any business or organization that accepts payment cards for its goods or services.
Merchants are split into four levels, based on their annual transaction volume, where Level 1 merchants process more than 6 million transactions each year, or they’re any merchant that has seen a cardholder data breach. Compared with the lower-level merchants, Level 1 merchants typically end up needing an annual on-site PCI DSS assessment which includes a Report on Compliance (ROC) and an Attestation of Compliance (AOC), and that work is carried out by a Qualified Security Assessor (QSA). For other merchants below level 1, compliance validation often involves completing the appropriate Self-Assessment Questionnaire (SAQ). PCI DSS provides several SAQ types, including SAQ A, A-EP, B, B-IP, C-VT, C, P2PE, and D, each designed for different payment acceptance methods and cardholder data environments.
Figuring out the right merchant level, properly defining the scope, and then picking the right SAQ are usually the hardest parts of PCI compliance. If you get these things wrong, you can end up with needless expenses, extra compliance work, or worse, non-compliance.
And this is exactly where a Qualified Security Assessor (QSA) can be really helpful. A seasoned QSA supports merchants in setting the scope the right way, finding the exact requirements that apply, understanding SAQ eligibility in real terms, and creating pragmatic compliance plans. Instead of treating PCI DSS as this heavy, tangled obligation, merchants can lean on a QSA’s experience so compliance becomes more efficient, more cost-effective, and also more secure.
Merchants that maintain accurate asset inventories, regularly review access controls and automate evidence collection are often far better prepared for assessments than those relying on manual processes. By focusing on risk reduction, leveraging technologies such as tokenization and managed payment solutions, and maintaining open communication throughout the year, organizations can significantly reduce the effort required during assessment season. PCI compliance should not be viewed as a burden - it should serve as a framework that strengthens payment security while supporting business growth and customer trust.
What sort of challenges will merchants face in audits and what they can expect?
Many merchants underestimate the amount of work that goes into a PCI DSS assessment until the audit begins. It’s not rare to see common hurdles come up, like defining PCI scope the wrong way, picking the wrong SAQ, having documentation that feels incomplete, struggling to find enough evidence for the controls that are already implemented, facing holes in vulnerability management, and getting stuck on what third-party service provider responsibilities even look like in practice. On top of that, merchants often have trouble reading the PCI DSS requirements and figuring out how they map to their own payment setup, not just in theory but in their day to day reality.
A Qualified Security Assessor (QSA) can help smooth out these issues long before the assessment begins. A QSA supports merchants with clear guidance, including by pinning down the scope correctly, selecting the requirements that truly apply, checking the controls that already exist, and surfacing potential compliance gaps early. In that way, the merchant is less likely to hit expensive surprises once the audit is underway. Instead of only confirming compliance, a QSA usually functions more like a trusted advisor, helping the assessment feel faster and more organized, lowering remediation effort later on, and enabling merchants to reach PCI compliance with more certainty and less stress.
If you would like to get in touch with us to discuss how we can support your cybersecurity needs - please reach out to us: hello@onecybervalley.com
By 1 Cyber Valley | August 3rd, 2026 | Harry Lall