PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

SAQ C-VT

SAQ C-VT includes PCI DSS requirements applicable to merchants that process account data only via third-party virtual payment terminal solutions on an isolated computing device connected to the Internet. Intended only for merchants that manually enter a single transaction at a time via a keyboard.

SAQ C-VT at a glance

Who it is for

Merchants keying transactions into a third-party virtual terminal

Payment channels

card-present or MOTO (not e-commerce)

Not applicable to

E-commerce channels; Service providers

Official page

PCI SSC SAQ Instructions and Guidelines v4.0.1 r1, page 19

Eligibility criteria

Every criterion below must be true for SAQ C-VT to apply. A single false criterion removes eligibility.

The only payment processing is via a virtual payment terminal accessed by an Internet-connected web browser.
The virtual payment terminal solution is provided and hosted by a PCI DSS compliant third-party service provider.
The PCI DSS compliant virtual payment terminal solution is only accessed via a computing device that is isolated in a single location, and is not connected to other locations or systems.
The computing device does not have software installed that causes account data to be stored (for example, no batch processing or store-and-forward).
The computing device does not have any attached hardware devices that are used to capture or store account data (for example, no attached card readers).
The merchant does not otherwise receive, transmit, or store account data electronically through any channels.
Any account data the merchant might retain is on paper (for example, printed reports or receipts), and these documents are not received electronically.

What the selector checks

The free PCI Assessments Center SAQ selector turns the official criteria into a fail-closed checklist. These are the exact items it verifies for SAQ C-VT:

The only payment processing on this channel is via a virtual payment terminal accessed by an Internet-connected web browser.
The virtual payment terminal solution is provided and hosted by a PCI DSS compliant TPSP.
We access the virtual terminal via a computer that is isolated in a single location (not connected to other locations or systems).
The computer does NOT have software installed that causes account data to be stored (no batch processing or store-and-forward).
The computer does NOT have any attached hardware (e.g. card readers) that captures or stores account data.
We do not otherwise receive, transmit, or store account data electronically through any channel.
Any account data we retain is on paper only (printed reports/receipts) and is not received electronically.

Baseline disqualifiers

Before any short-form SAQ can apply, the merchant must also satisfy these baseline checks:

We do NOT store any account data in electronic format on our systems, including legacy data (PAN, cardholder name, service code, expiration date, or sensitive authentication data). Paper-only receipts or reports are fine.
We are NOT a designated entity that our acquirer or payment brand has required to complete PCI DSS Appendix A3 / DESV.
Our acquirer or payment brand has NOT required us to complete a full Report on Compliance (ROC).
We have NOT experienced a confirmed account-data breach in the last 12 months that our acquirer has told us to escalate.

Common mistake

Any attached card reader, any store-and-forward or batch capability, or any other electronic acceptance channel removes eligibility.

Not sure if SAQ C-VT applies?

Run the free SAQ selector. It walks the official PCI SSC decision flow, records every answer, and re-derives the recommendation server-side with a confidence score — so you get a defensible record of why a given SAQ was chosen.

Source: PCI Security Standards Council, Self-Assessment Questionnaire Instructions and Guidelines for PCI DSS v4.0.1 r1. This guide is an independent summary and is not endorsed by PCI SSC.