PCI Assessments Center
Loading your workspace…
SAQ C includes PCI DSS requirements applicable to merchants with payment application systems (for example, point-of-sale systems) connected to the Internet, and that do not store electronic account data.
Merchants with a payment application connected to the Internet
card-present or MOTO (not e-commerce)
E-commerce channels; Service providers
PCI SSC SAQ Instructions and Guidelines v4.0.1 r1, page 20
Every criterion below must be true for SAQ C to apply. A single false criterion removes eligibility.
The free PCI Assessments Center SAQ selector turns the official criteria into a fail-closed checklist. These are the exact items it verifies for SAQ C:
Before any short-form SAQ can apply, the merchant must also satisfy these baseline checks:
The POS location must not be connected to other premises or locations — multi-site shared networks push you to SAQ D.
Run the free SAQ selector. It walks the official PCI SSC decision flow, records every answer, and re-derives the recommendation server-side with a confidence score — so you get a defensible record of why a given SAQ was chosen.
Source: PCI Security Standards Council, Self-Assessment Questionnaire Instructions and Guidelines for PCI DSS v4.0.1 r1. This guide is an independent summary and is not endorsed by PCI SSC.