PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

SAQ A

SAQ A includes only those PCI DSS requirements applicable to merchants with account data functions completely outsourced to PCI DSS validated and compliant third parties, where the merchant retains only paper reports or receipts with account data.

SAQ A at a glance

Who it is for

Card-not-present merchants (e-commerce and MOTO)

Payment channels

e-commerce or MOTO (card-not-present)

Not applicable to

Face-to-face channels; Service providers

Official page

PCI SSC SAQ Instructions and Guidelines v4.0.1 r1, page 15

Eligibility criteria

Every criterion below must be true for SAQ A to apply. A single false criterion removes eligibility.

The merchant accepts only card-not-present (e-commerce or mail/telephone-order) transactions.
All processing of account data is entirely outsourced to a PCI DSS compliant third-party service provider (TPSP)/payment processor.
The merchant does not electronically store, process, or transmit any account data on merchant systems or premises, but relies entirely on a TPSP(s) to handle all these functions.
The merchant has confirmed that TPSP(s) are PCI DSS compliant for the services being used by the merchant.
Any account data the merchant might retain is on paper (for example, printed reports or receipts), and these documents are not received electronically.

Additional e-commerce criteria

For e-commerce channels, SAQ A also requires:

All elements of the payment page(s)/form(s) delivered to the customer's browser originate only and directly from a PCI DSS compliant TPSP/payment processor.
The merchant has confirmed that their site is not susceptible to attacks from scripts that could affect the merchant's e-commerce system(s).

What the selector checks

The free PCI Assessments Center SAQ selector turns the official criteria into a fail-closed checklist. These are the exact items it verifies for SAQ A:

We accept only card-not-present (e-commerce) transactions on this channel.
All processing of account data is entirely outsourced to a PCI DSS compliant TPSP / payment processor.
We do not electronically store, process, or transmit any account data on our systems or premises — we rely entirely on the TPSP.
We have confirmed that our TPSP(s) are PCI DSS compliant for the services we use.
Any account data we retain is on paper only (printed reports/receipts) and is not received electronically.
Every element of the payment page(s)/form(s) delivered to the customer's browser originates only and directly from a PCI DSS compliant TPSP.
We have confirmed that our site is not susceptible to attacks from scripts that could affect our e-commerce systems.

Baseline disqualifiers

Before any short-form SAQ can apply, the merchant must also satisfy these baseline checks:

We do NOT store any account data in electronic format on our systems, including legacy data (PAN, cardholder name, service code, expiration date, or sensitive authentication data). Paper-only receipts or reports are fine.
We are NOT a designated entity that our acquirer or payment brand has required to complete PCI DSS Appendix A3 / DESV.
Our acquirer or payment brand has NOT required us to complete a full Report on Compliance (ROC).
We have NOT experienced a confirmed account-data breach in the last 12 months that our acquirer has told us to escalate.

Common mistake

v4.0.1 adds an explicit script criterion: you must confirm your site is not susceptible to attacks from scripts that could affect your e-commerce systems.

Not sure if SAQ A applies?

Run the free SAQ selector. It walks the official PCI SSC decision flow, records every answer, and re-derives the recommendation server-side with a confidence score — so you get a defensible record of why a given SAQ was chosen.

Source: PCI Security Standards Council, Self-Assessment Questionnaire Instructions and Guidelines for PCI DSS v4.0.1 r1. This guide is an independent summary and is not endorsed by PCI SSC.