PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free reference · PCI DSS v4.0.1

SAQ comparison matrix

A side-by-side view of every PCI DSS v4.0.1 SAQ: who it is for, which payment channels it covers, and the one condition that disqualifies each shorter form. Use this to short-list the right SAQ, then confirm with our free selector.

At a glance

SAQ A
Who it is for
Card-not-present merchants (e-commerce and MOTO)
Channels
e-commerce or MOTO (card-not-present)
Key condition
The merchant accepts only card-not-present (e-commerce or mail/telephone-order) transactions.
Common disqualifier
v4.0.1 adds an explicit script criterion: you must confirm your site is not susceptible to attacks from scripts that could affect your e-commerce systems.
SAQ A-EP
Who it is for
Partially outsourced e-commerce merchants
Channels
e-commerce only
Key condition
The merchant accepts only e-commerce transactions.
Common disqualifier
If any element of your payment page is delivered by your own site, SAQ A is not available to you no matter how little data you touch.
SAQ B
Who it is for
Card-present and MOTO merchants using imprint machines or dial-out terminals
Channels
card-present or MOTO (not e-commerce)
Key condition
The merchant uses only an imprint machine and/or uses only standalone, dial-out terminals (connected via a phone line to the merchant processor) to take customers' payment card information.
Common disqualifier
The moment a terminal reaches the processor over IP, SAQ B stops applying and SAQ B-IP (or SAQ D) becomes the path.
SAQ B-IP
Who it is for
Merchants using standalone IP-connected PTS POI terminals
Channels
card-present or MOTO (not e-commerce)
Key condition
The merchant uses only standalone, PCI-listed approved PTS POI devices (excludes SCRs and SCRPs) connected via IP to merchant's payment processor to take customers' payment card information.
Common disqualifier
Secure Card Readers (SCR) and SCRPs are explicitly excluded from SAQ B-IP, and the device must not rely on a computer, phone, or tablet to reach the processor.
SAQ C-VT
Who it is for
Merchants keying transactions into a third-party virtual terminal
Channels
card-present or MOTO (not e-commerce)
Key condition
The only payment processing is via a virtual payment terminal accessed by an Internet-connected web browser.
Common disqualifier
Any attached card reader, any store-and-forward or batch capability, or any other electronic acceptance channel removes eligibility.
SAQ C
Who it is for
Merchants with a payment application connected to the Internet
Channels
card-present or MOTO (not e-commerce)
Key condition
The merchant has a payment application system and an Internet connection on the same device and/or same local area network (LAN).
Common disqualifier
The POS location must not be connected to other premises or locations — multi-site shared networks push you to SAQ D.
SAQ P2PE
Who it is for
Merchants using a validated PCI-listed P2PE solution
Channels
card-present or MOTO (not e-commerce)
Key condition
All payment processing is via a validated PCI-listed P2PE solution.
Common disqualifier
An expired listing is not a validated solution. "Encrypting terminals" that are not PCI-listed P2PE do not qualify.
SAQ SPoC
Who it is for
Attended card-present merchants using a validated PCI-listed SPoC solution
Channels
card-present only (attended)
Key condition
All payment processing is only via a card-present payment channel.
Common disqualifier
SPoC is not available for unattended terminals, MOTO, or e-commerce, and the channel must not be connected to your other systems.
SAQ D-Merchant
Who it is for
All other SAQ-eligible merchants
Channels
any merchant channel not covered by another SAQ
Key condition
The merchant is eligible to complete a self-assessment questionnaire (as determined by its acquirer / payment brand).
Common disqualifier
SAQ D is not a failure state — it is the honest answer for most merchants who store data or run their own payment applications.
SAQ D-SP
Who it is for
Service providers eligible to self-assess
Channels
n/a — service providers
Key condition
The organisation is a service provider as defined by the payment brands.
Common disqualifier
It is the only SAQ available to service providers. Level 1 service providers cannot use it.

Pairwise comparisons

The pairs merchants confuse most often, factor by factor.

SAQ A vs SAQ A-EP

Applicable channels
SAQ A: E-commerce or MOTO
SAQ A-EP: E-commerce only
Payment page origin
SAQ A: Every element originates directly from a PCI DSS compliant TPSP
SAQ A-EP: Merchant site delivers some payment-page elements; account data goes to a TPSP
Merchant system receives account data?
SAQ A: No
SAQ A-EP: No, but the merchant website affects payment-page integrity
CDE scope on merchant website
SAQ A: Not applicable (no CDE on merchant systems)
SAQ A-EP: Merchant website is in-scope as it directly impacts how account data is transmitted

SAQ B vs SAQ B-IP

Terminal type
SAQ B: Imprint machines or standalone dial-out terminals
SAQ B-IP: Standalone PCI-listed PTS POI devices (excludes SCR/SCRP)
Connectivity
SAQ B: Phone line only, no Internet
SAQ B-IP: IP-connected to payment processor
Other systems on the network
SAQ B: Terminals not connected to other systems
SAQ B-IP: POI devices isolated from other systems (segmentation)

SAQ C-VT vs SAQ C

Data entry
SAQ C-VT: Manual keyboard entry into a third-party virtual terminal
SAQ C: Transactions flow through a merchant payment application
Applicable channels
SAQ C-VT: Card-present or MOTO
SAQ C: Card-present or MOTO
System scope
SAQ C-VT: Isolated single computing device accessing a TPSP-hosted virtual terminal
SAQ C: POS or PC-based payment application on a segmented LAN, single location
Attached card readers
SAQ C-VT: Not permitted
SAQ C: May be part of the payment application

SAQ P2PE vs SAQ SPoC

Solution type
SAQ P2PE: PCI-listed Point-to-Point Encryption solution
SAQ SPoC: PCI-listed Software-based PIN Entry on COTS solution
Device
SAQ P2PE: P2PE-listed payment terminal
SAQ SPoC: PTS-approved SCRP + merchant COTS device (phone/tablet)
Applicable channels
SAQ P2PE: Card-present or MOTO
SAQ SPoC: Attended card-present only (no MOTO, no e-commerce, no unattended)
Merchant obligations
SAQ P2PE: Implement controls in the P2PE Instruction Manual (PIM)
SAQ SPoC: Implement controls in the SPoC user guide

SAQ D for Merchants

The catch-all for merchants who do not meet any short-form SAQ criteria, including merchants that store account data electronically or mix channels that cannot each use the same short form.

Read the SAQ D-Merchant guide

SAQ D for Service Providers

The only SAQ available to service providers. Only applies when the compliance-accepting entity has determined the service provider is eligible to self-assess.

Read the SAQ D-SP guide

A comparison table does not replace eligibility

These summaries are a quick reference. The actual SAQ you complete must satisfy every eligibility criterion in the PCI SSC Self-Assessment Questionnaire Instructions and Guidelines v4.0.1 r1, and your acquirer or payment brand remains the compliance-accepting entity.

Still deciding?

Run the free SAQ selector. It walks the official decision flow, records every answer, and re-derives the recommendation server-side with a confidence score.