PCI Assessments Center
Loading your workspace…
SAQ A-EP includes PCI DSS requirements applicable to e-commerce merchants with a website(s) that does not itself receive account data but which does affect the security of the payment transaction and/or the integrity of the page that accepts the customer's account data.
Partially outsourced e-commerce merchants
e-commerce only
Non e-commerce channels; Service providers
PCI SSC SAQ Instructions and Guidelines v4.0.1 r1, page 16
Every criterion below must be true for SAQ A-EP to apply. A single false criterion removes eligibility.
The free PCI Assessments Center SAQ selector turns the official criteria into a fail-closed checklist. These are the exact items it verifies for SAQ A-EP:
Before any short-form SAQ can apply, the merchant must also satisfy these baseline checks:
If any element of your payment page is delivered by your own site, SAQ A is not available to you no matter how little data you touch.
Run the free SAQ selector. It walks the official PCI SSC decision flow, records every answer, and re-derives the recommendation server-side with a confidence score — so you get a defensible record of why a given SAQ was chosen.
Source: PCI Security Standards Council, Self-Assessment Questionnaire Instructions and Guidelines for PCI DSS v4.0.1 r1. This guide is an independent summary and is not endorsed by PCI SSC.