Question 1
Step 1First — which best describes your organisation?
We start with a QSA-vs-SAQ triage so you don't spend time on an SAQ path when a Report on Compliance (ROC) is actually required.
Source: PCI DSS v4.0.1 §4 Assessment Process; SAQ Instructions & Guidelines v4.0.1 r1, Eligibility.