PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

SAQ A-EP

SAQ A-EP includes PCI DSS requirements applicable to e-commerce merchants with a website(s) that does not itself receive account data but which does affect the security of the payment transaction and/or the integrity of the page that accepts the customer's account data.

SAQ A-EP at a glance

Who it is for

Partially outsourced e-commerce merchants

Payment channels

e-commerce only

Not applicable to

Non e-commerce channels; Service providers

Official page

PCI SSC SAQ Instructions and Guidelines v4.0.1 r1, page 16

Eligibility criteria

Every criterion below must be true for SAQ A-EP to apply. A single false criterion removes eligibility.

The merchant accepts only e-commerce transactions.
All processing of account data, with the exception of the payment page, is entirely outsourced to a PCI DSS compliant TPSP/payment processor.
The merchant's e-commerce website does not receive account data but controls how customers, or their account data, are redirected to a PCI DSS compliant TPSP/payment processor.
If the merchant website is hosted by a TPSP, the TPSP is compliant with all applicable PCI DSS requirements (including PCI DSS Appendix A if the TPSP is a multi-tenant hosting provider).
Each element of the payment page(s) delivered to the customer's browser originates from either the merchant's website or a PCI DSS compliant TPSP.
The merchant does not electronically store, process, or transmit any account data on merchant systems or premises, but relies entirely on a TPSP(s) to handle all these functions.
The merchant has confirmed that the TPSP(s) are PCI DSS compliant for the services being used by the merchant.
Any account data the merchant might retain is on paper (for example, printed reports or receipts), and these documents are not received electronically.

What the selector checks

The free PCI Assessments Center SAQ selector turns the official criteria into a fail-closed checklist. These are the exact items it verifies for SAQ A-EP:

We accept only e-commerce transactions on this channel.
All processing of account data, with the exception of the payment page, is entirely outsourced to a PCI DSS compliant TPSP / payment processor.
Our e-commerce website does NOT receive account data but controls how customers, or their account data, are redirected to a PCI DSS compliant TPSP / payment processor.
If our website is hosted by a TPSP, that TPSP is compliant with all applicable PCI DSS requirements (including PCI DSS Appendix A if it is a multi-tenant hosting provider).
Each element of the payment page(s) delivered to the customer's browser originates from either our website or a PCI DSS compliant TPSP.
We do not electronically store, process, or transmit any account data on our systems or premises — we rely entirely on the TPSP.
We have confirmed the TPSP(s) are PCI DSS compliant for the services we use.
Any account data we retain is on paper only (printed reports/receipts) and is not received electronically.

Baseline disqualifiers

Before any short-form SAQ can apply, the merchant must also satisfy these baseline checks:

We do NOT store any account data in electronic format on our systems, including legacy data (PAN, cardholder name, service code, expiration date, or sensitive authentication data). Paper-only receipts or reports are fine.
We are NOT a designated entity that our acquirer or payment brand has required to complete PCI DSS Appendix A3 / DESV.
Our acquirer or payment brand has NOT required us to complete a full Report on Compliance (ROC).
We have NOT experienced a confirmed account-data breach in the last 12 months that our acquirer has told us to escalate.

Common mistake

If any element of your payment page is delivered by your own site, SAQ A is not available to you no matter how little data you touch.

Not sure if SAQ A-EP applies?

Run the free SAQ selector. It walks the official PCI SSC decision flow, records every answer, and re-derives the recommendation server-side with a confidence score — so you get a defensible record of why a given SAQ was chosen.

Source: PCI Security Standards Council, Self-Assessment Questionnaire Instructions and Guidelines for PCI DSS v4.0.1 r1. This guide is an independent summary and is not endorsed by PCI SSC.