Transparency: the criteria behind every recommendation.

How assessments work

PCI Assessments Center does not guess. Every question and every eligibility clause is drawn verbatim from PCI SSC documents — currently PCI DSS Self-Assessment Questionnaire Instructions and Guidelines (v4.0.1 r1, April 2025) and PCI DSS v4.0.1. The decision tree runs at v4.0.1 r1.

Step 1 — QSA-vs-SAQ triage

Before we ask about payment channels, we confirm you are actually eligible to self-assess. Any of the following routes you to a QSA-led Report on Compliance instead of an SAQ:

  • Level 1 merchant (>6M Visa/Mastercard transactions/yr or brand-designated).
  • Level 1 service provider (>300k transactions/yr) — SAQ D-SP is Level 2 only.
  • Acquirer or payment brand has mandated a Report on Compliance.
  • Designated Entity subject to PCI DSS Appendix A3 (DESV).
  • Confirmed account-data breach in the last 12 months with acquirer escalation.

Source: PCI DSS v4.0.1 §4 Assessment Process; Visa/Mastercard validation levels.

Step 2 — Baseline SAQ disqualifiers

If you clear triage, we confirm the short-form baseline: no electronic storage of account data, no DESV designation, no ROC mandate, no recent breach. If any fails, you route to SAQ D-Merchant (or QSA if the failure is severe).

  • No electronic storage of PAN, cardholder name, service code, expiry, or SAD.
  • Not a Designated Entity (Appendix A3).
  • No ROC mandated by acquirer / payment brand.
  • No unresolved confirmed breach in the last 12 months.

Source: SAQ Instructions & Guidelines v4.0.1 r1, Eligibility (short-form SAQs).

Step 3 — Channel + method

You pick the payment channel (e-commerce, MOTO, card-present) and the acceptance method. If you accept multiple channels, every channel must independently qualify for the SAME SAQ or SAQ D-Merchant applies — we ask you to answer for the weakest-scope channel.

  • E-commerce: page origin decides SAQ A vs A-EP vs D.
  • MOTO / Card-present: acceptance method decides SAQ A, B, B-IP, C, C-VT, P2PE, SPoC, or D.
  • Multi-channel: the weakest channel sets the SAQ.

Source: PCI DSS Self-Assessment Questionnaire Instructions and Guidelines, "Which SAQ Best Applies to My Environment?" chart.

Step 4 — Verbatim eligibility checklist

For the candidate SAQ we present the official eligibility clauses verbatim. Every item is ticked by default; untick any that is not true for your environment. A single unticked clause fails-closed to the next strictest SAQ (usually D-Merchant). We never round up to a looser SAQ.

  • SAQ A — 7 clauses (fully outsourced e-commerce).
  • SAQ A-EP — 8 clauses (partially outsourced e-commerce affecting payment page).
  • SAQ B / B-IP / C / C-VT / P2PE / SPoC — official clauses from the front of each SAQ.
  • SAQ D-Merchant / D-SP — the catch-all when nothing shorter applies.

Source: Front matter of each individual PCI SSC SAQ v4.0.1.

Step 5 — Trace, attestation, report

Every question, answer, and unticked clause is written to a signed trace stored with your assessment and printed on the generated SAQ/AoC PDF. Before you start the SAQ we ask you to formally attest to the eligibility clauses. This gives you (and your acquirer) a defensible record of why that SAQ was chosen.

  • Full decision path stored as selector_trace on the assessment.
  • Attestation of eligibility clauses stored with the assessment.
  • ‘SAQ Selection Rationale’ section rendered into the final PDF.

Source: PCI Assessments Center audit trail.

Fail-closed by design

Ambiguity always routes to the stricter outcome: unclear triage → QSA; unclear channel → SAQ D-Merchant; unmet eligibility clause → next strictest SAQ. PCI Assessments Center will never recommend a shorter SAQ than the evidence supports.

Start an assessment

PCI Assessments Center operationalises PCI SSC guidance for convenience. It does not supersede eligibility criteria in the official SAQ or any direction from your acquirer or payment brand.