PCI Assessments Center
Loading your workspace…
SAQ C-VT includes PCI DSS requirements applicable to merchants that process account data only via third-party virtual payment terminal solutions on an isolated computing device connected to the Internet. Intended only for merchants that manually enter a single transaction at a time via a keyboard.
Merchants keying transactions into a third-party virtual terminal
card-present or MOTO (not e-commerce)
E-commerce channels; Service providers
PCI SSC SAQ Instructions and Guidelines v4.0.1 r1, page 19
Every criterion below must be true for SAQ C-VT to apply. A single false criterion removes eligibility.
The free PCI Assessments Center SAQ selector turns the official criteria into a fail-closed checklist. These are the exact items it verifies for SAQ C-VT:
Before any short-form SAQ can apply, the merchant must also satisfy these baseline checks:
Any attached card reader, any store-and-forward or batch capability, or any other electronic acceptance channel removes eligibility.
Run the free SAQ selector. It walks the official PCI SSC decision flow, records every answer, and re-derives the recommendation server-side with a confidence score — so you get a defensible record of why a given SAQ was chosen.
Source: PCI Security Standards Council, Self-Assessment Questionnaire Instructions and Guidelines for PCI DSS v4.0.1 r1. This guide is an independent summary and is not endorsed by PCI SSC.