We start with a QSA-vs-SAQ triage (merchant / service-provider level, acquirer mandates, DESV, breach escalation), then walk the “Which SAQ Best Applies to My Environment?” chart in the PCI SSC PCI DSS Self-Assessment Questionnaire Instructions and Guidelines (v4.0.1 r1). Every eligibility clause must be confirmed before a short-form SAQ is recommended — any gap routes you to SAQ D or to a QSA engagement.
We start with a QSA-vs-SAQ triage so you don't spend time on an SAQ path when a Report on Compliance (ROC) is actually required.
Source: PCI DSS v4.0.1 §4 Assessment Process; SAQ Instructions & Guidelines v4.0.1 r1, Eligibility.