PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

SAQ B-IP

SAQ B-IP includes PCI DSS requirements applicable to merchants that process account data only via standalone, PCI-listed approved PTS POI devices with an IP connection to the payment processor. An exception applies for PTS POI devices classified as Secure Card Readers (SCR) and Secure Card Readers for PIN (SCRPs); merchants using SCRs or SCRPs are not eligible for this SAQ.

SAQ B-IP at a glance

Who it is for

Merchants using standalone IP-connected PTS POI terminals

Payment channels

card-present or MOTO (not e-commerce)

Not applicable to

E-commerce channels; Service providers

Official page

PCI SSC SAQ Instructions and Guidelines v4.0.1 r1, page 18

Eligibility criteria

Every criterion below must be true for SAQ B-IP to apply. A single false criterion removes eligibility.

The merchant uses only standalone, PCI-listed approved PTS POI devices (excludes SCRs and SCRPs) connected via IP to merchant's payment processor to take customers' payment card information.
The standalone, IP-connected POI devices are validated to the PTS POI program as listed on the PCI SSC website (excludes SCRs and SCRPs).
The standalone, IP-connected PTS POI devices are not connected to any other systems within the merchant environment (this can be achieved via network segmentation).
The only transmission of account data is from the approved PTS POI devices to the payment processor.
The PTS POI device does not rely on any other device — e.g., computer, mobile phone, tablet — to connect to the payment processor.
The merchant does not store account data in electronic format.
Any account data the merchant might retain is on paper (for example, printed reports or receipts), and these documents are not received electronically.

What the selector checks

The free PCI Assessments Center SAQ selector turns the official criteria into a fail-closed checklist. These are the exact items it verifies for SAQ B-IP:

We use only standalone, PCI-listed approved PTS POI devices (excluding SCRs and SCRPs) connected via IP to our payment processor.
The standalone IP-connected POI devices are validated to the PTS POI program as listed on the PCI SSC website (an expired listing is not validated — check with your acquirer).
The standalone IP-connected PTS POI devices are NOT connected to any other systems within our environment (segmentation is acceptable).
The only transmission of account data is from the approved PTS POI devices to the payment processor.
The PTS POI device does NOT rely on any other device (computer, mobile phone, tablet) to connect to the processor.
We do not store account data in electronic format.
Any account data we retain is on paper only (printed reports/receipts) and is not received electronically.

Baseline disqualifiers

Before any short-form SAQ can apply, the merchant must also satisfy these baseline checks:

We do NOT store any account data in electronic format on our systems, including legacy data (PAN, cardholder name, service code, expiration date, or sensitive authentication data). Paper-only receipts or reports are fine.
We are NOT a designated entity that our acquirer or payment brand has required to complete PCI DSS Appendix A3 / DESV.
Our acquirer or payment brand has NOT required us to complete a full Report on Compliance (ROC).
We have NOT experienced a confirmed account-data breach in the last 12 months that our acquirer has told us to escalate.

Common mistake

Secure Card Readers (SCR) and SCRPs are explicitly excluded from SAQ B-IP, and the device must not rely on a computer, phone, or tablet to reach the processor.

Not sure if SAQ B-IP applies?

Run the free SAQ selector. It walks the official PCI SSC decision flow, records every answer, and re-derives the recommendation server-side with a confidence score — so you get a defensible record of why a given SAQ was chosen.

Source: PCI Security Standards Council, Self-Assessment Questionnaire Instructions and Guidelines for PCI DSS v4.0.1 r1. This guide is an independent summary and is not endorsed by PCI SSC.