| SAQ A | Card-not-present merchants (e-commerce and MOTO) | e-commerce or MOTO (card-not-present) | The merchant accepts only card-not-present (e-commerce or mail/telephone-order) transactions. | v4.0.1 adds an explicit script criterion: you must confirm your site is not susceptible to attacks from scripts that could affect your e-commerce systems. |
|---|
| SAQ A-EP | Partially outsourced e-commerce merchants | e-commerce only | The merchant accepts only e-commerce transactions. | If any element of your payment page is delivered by your own site, SAQ A is not available to you no matter how little data you touch. |
|---|
| SAQ B | Card-present and MOTO merchants using imprint machines or dial-out terminals | card-present or MOTO (not e-commerce) | The merchant uses only an imprint machine and/or uses only standalone, dial-out terminals (connected via a phone line to the merchant processor) to take customers' payment card information. | The moment a terminal reaches the processor over IP, SAQ B stops applying and SAQ B-IP (or SAQ D) becomes the path. |
|---|
| SAQ B-IP | Merchants using standalone IP-connected PTS POI terminals | card-present or MOTO (not e-commerce) | The merchant uses only standalone, PCI-listed approved PTS POI devices (excludes SCRs and SCRPs) connected via IP to merchant's payment processor to take customers' payment card information. | Secure Card Readers (SCR) and SCRPs are explicitly excluded from SAQ B-IP, and the device must not rely on a computer, phone, or tablet to reach the processor. |
|---|
| SAQ C-VT | Merchants keying transactions into a third-party virtual terminal | card-present or MOTO (not e-commerce) | The only payment processing is via a virtual payment terminal accessed by an Internet-connected web browser. | Any attached card reader, any store-and-forward or batch capability, or any other electronic acceptance channel removes eligibility. |
|---|
| SAQ C | Merchants with a payment application connected to the Internet | card-present or MOTO (not e-commerce) | The merchant has a payment application system and an Internet connection on the same device and/or same local area network (LAN). | The POS location must not be connected to other premises or locations — multi-site shared networks push you to SAQ D. |
|---|
| SAQ P2PE | Merchants using a validated PCI-listed P2PE solution | card-present or MOTO (not e-commerce) | All payment processing is via a validated PCI-listed P2PE solution. | An expired listing is not a validated solution. "Encrypting terminals" that are not PCI-listed P2PE do not qualify. |
|---|
| SAQ SPoC | Attended card-present merchants using a validated PCI-listed SPoC solution | card-present only (attended) | All payment processing is only via a card-present payment channel. | SPoC is not available for unattended terminals, MOTO, or e-commerce, and the channel must not be connected to your other systems. |
|---|
| SAQ D-Merchant | All other SAQ-eligible merchants | any merchant channel not covered by another SAQ | The merchant is eligible to complete a self-assessment questionnaire (as determined by its acquirer / payment brand). | SAQ D is not a failure state — it is the honest answer for most merchants who store data or run their own payment applications. |
|---|
| SAQ D-SP | Service providers eligible to self-assess | n/a — service providers | The organisation is a service provider as defined by the payment brands. | It is the only SAQ available to service providers. Level 1 service providers cannot use it. |
|---|