PCI Assessments Center
Loading your workspace…
PCI compliance levels are assigned by the individual payment brands — not by the PCI Security Standards Council — and they determine how you must validate, not which requirements apply. Level 1 merchants and Level 1 service providers validate through a QSA-led Report on Compliance; lower levels may be eligible for a Self-Assessment Questionnaire, subject to their acquirer.
The free SAQ selector walks the official PCI SSC v4.0.1 decision flow, records every answer and re-derives the recommendation server-side with a confidence score.
Written by Haumaru Whānau QSAs. PCI DSS content paraphrased from PCI DSS v4.0.1 and PCI SSC published guidance; payment brand programmes are set by the brands and your acquirer. Independent summary; not endorsed by PCI SSC.