PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

SAQ B

SAQ B includes PCI DSS requirements applicable to merchants that process account data only via imprint machines or standalone, dial-out terminals.

SAQ B at a glance

Who it is for

Card-present and MOTO merchants using imprint machines or dial-out terminals

Payment channels

card-present or MOTO (not e-commerce)

Not applicable to

E-commerce channels; Service providers

Official page

PCI SSC SAQ Instructions and Guidelines v4.0.1 r1, page 17

Eligibility criteria

Every criterion below must be true for SAQ B to apply. A single false criterion removes eligibility.

The merchant uses only an imprint machine and/or uses only standalone, dial-out terminals (connected via a phone line to the merchant processor) to take customers' payment card information.
The standalone, dial-out terminals are not connected to any other systems within the merchant environment.
The standalone, dial-out terminals are not connected to the Internet.
The merchant does not store account data in electronic format.
Any account data the merchant might retain is on paper (for example, printed reports or receipts), and these documents are not received electronically.

What the selector checks

The free PCI Assessments Center SAQ selector turns the official criteria into a fail-closed checklist. These are the exact items it verifies for SAQ B:

We use only imprint machines and/or only standalone dial-out terminals (connected via a phone line to our processor) to take card details.
The standalone dial-out terminals are NOT connected to any other systems within our environment.
The standalone dial-out terminals are NOT connected to the Internet.
We do not store account data in electronic format.
Any account data we retain is on paper only (printed reports/receipts) and is not received electronically.

Baseline disqualifiers

Before any short-form SAQ can apply, the merchant must also satisfy these baseline checks:

We do NOT store any account data in electronic format on our systems, including legacy data (PAN, cardholder name, service code, expiration date, or sensitive authentication data). Paper-only receipts or reports are fine.
We are NOT a designated entity that our acquirer or payment brand has required to complete PCI DSS Appendix A3 / DESV.
Our acquirer or payment brand has NOT required us to complete a full Report on Compliance (ROC).
We have NOT experienced a confirmed account-data breach in the last 12 months that our acquirer has told us to escalate.

Common mistake

The moment a terminal reaches the processor over IP, SAQ B stops applying and SAQ B-IP (or SAQ D) becomes the path.

Not sure if SAQ B applies?

Run the free SAQ selector. It walks the official PCI SSC decision flow, records every answer, and re-derives the recommendation server-side with a confidence score — so you get a defensible record of why a given SAQ was chosen.

Source: PCI Security Standards Council, Self-Assessment Questionnaire Instructions and Guidelines for PCI DSS v4.0.1 r1. This guide is an independent summary and is not endorsed by PCI SSC.