PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

SAQ C

SAQ C includes PCI DSS requirements applicable to merchants with payment application systems (for example, point-of-sale systems) connected to the Internet, and that do not store electronic account data.

SAQ C at a glance

Who it is for

Merchants with a payment application connected to the Internet

Payment channels

card-present or MOTO (not e-commerce)

Not applicable to

E-commerce channels; Service providers

Official page

PCI SSC SAQ Instructions and Guidelines v4.0.1 r1, page 20

Eligibility criteria

Every criterion below must be true for SAQ C to apply. A single false criterion removes eligibility.

The merchant has a payment application system and an Internet connection on the same device and/or same local area network (LAN).
The payment application system is not connected to any other systems within the merchant environment (this can be achieved via network segmentation).
The physical location of the POS environment is not connected to other premises or locations, and any LAN is for a single store only.
The merchant does not store account data in electronic format.
Any account data the merchant might retain is on paper (for example, printed reports or receipts), and these documents are not received electronically.

What the selector checks

The free PCI Assessments Center SAQ selector turns the official criteria into a fail-closed checklist. These are the exact items it verifies for SAQ C:

We have a payment application system and an Internet connection on the same device and/or same local area network (LAN).
The payment application system is NOT connected to any other systems within our environment (segmentation is acceptable).
The physical location of the POS environment is NOT connected to other premises or locations, and any LAN is for a single store only.
We do not store account data in electronic format.
Any account data we retain is on paper only (printed reports/receipts) and is not received electronically.

Baseline disqualifiers

Before any short-form SAQ can apply, the merchant must also satisfy these baseline checks:

We do NOT store any account data in electronic format on our systems, including legacy data (PAN, cardholder name, service code, expiration date, or sensitive authentication data). Paper-only receipts or reports are fine.
We are NOT a designated entity that our acquirer or payment brand has required to complete PCI DSS Appendix A3 / DESV.
Our acquirer or payment brand has NOT required us to complete a full Report on Compliance (ROC).
We have NOT experienced a confirmed account-data breach in the last 12 months that our acquirer has told us to escalate.

Common mistake

The POS location must not be connected to other premises or locations — multi-site shared networks push you to SAQ D.

Not sure if SAQ C applies?

Run the free SAQ selector. It walks the official PCI SSC decision flow, records every answer, and re-derives the recommendation server-side with a confidence score — so you get a defensible record of why a given SAQ was chosen.

Source: PCI Security Standards Council, Self-Assessment Questionnaire Instructions and Guidelines for PCI DSS v4.0.1 r1. This guide is an independent summary and is not endorsed by PCI SSC.