PCI Assessments Center
Loading your workspace…
SAQ A includes only those PCI DSS requirements applicable to merchants with account data functions completely outsourced to PCI DSS validated and compliant third parties, where the merchant retains only paper reports or receipts with account data.
Card-not-present merchants (e-commerce and MOTO)
e-commerce or MOTO (card-not-present)
Face-to-face channels; Service providers
PCI SSC SAQ Instructions and Guidelines v4.0.1 r1, page 15
Every criterion below must be true for SAQ A to apply. A single false criterion removes eligibility.
For e-commerce channels, SAQ A also requires:
The free PCI Assessments Center SAQ selector turns the official criteria into a fail-closed checklist. These are the exact items it verifies for SAQ A:
Before any short-form SAQ can apply, the merchant must also satisfy these baseline checks:
v4.0.1 adds an explicit script criterion: you must confirm your site is not susceptible to attacks from scripts that could affect your e-commerce systems.
Run the free SAQ selector. It walks the official PCI SSC decision flow, records every answer, and re-derives the recommendation server-side with a confidence score — so you get a defensible record of why a given SAQ was chosen.
Source: PCI Security Standards Council, Self-Assessment Questionnaire Instructions and Guidelines for PCI DSS v4.0.1 r1. This guide is an independent summary and is not endorsed by PCI SSC.