Official PCI SSC v4.0.1 r1 decision flow — fail-closed.

Assessments — find your correct PCI validation path

We start with a QSA-vs-SAQ triage (merchant / service-provider level, acquirer mandates, DESV, breach escalation), then walk the “Which SAQ Best Applies to My Environment?” chart in the PCI SSC PCI DSS Self-Assessment Questionnaire Instructions and Guidelines (v4.0.1 r1). Every eligibility clause must be confirmed before a short-form SAQ is recommended — any gap routes you to SAQ D or to a QSA engagement.

Question 1

First — which best describes your organisation?

We start with a QSA-vs-SAQ triage so you don't spend time on an SAQ path when a Report on Compliance (ROC) is actually required.

Source: PCI DSS v4.0.1 §4 Assessment Process; SAQ Instructions & Guidelines v4.0.1 r1, Eligibility.