PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

SAQ D-Merchant

SAQ D for Merchants applies to merchants that are eligible to complete a self-assessment questionnaire but do not meet the criteria for any other SAQ type.

SAQ D-Merchant at a glance

Who it is for

All other SAQ-eligible merchants

Payment channels

any merchant channel not covered by another SAQ

Not applicable to

Service providers

Official page

PCI SSC SAQ Instructions and Guidelines v4.0.1 r1, page 23

Eligibility criteria

Every criterion below must be true for SAQ D-Merchant to apply. A single false criterion removes eligibility.

The merchant is eligible to complete a self-assessment questionnaire (as determined by its acquirer / payment brand).
The merchant does not meet the eligibility criteria of another SAQ type (e.g., stores account data electronically, or has additional PCI DSS requirements applicable to its environment).
The merchant accepts responsibility for all applicable PCI DSS requirements that apply to its environment.

Common mistake

SAQ D is not a failure state — it is the honest answer for most merchants who store data or run their own payment applications.

Not sure if SAQ D-Merchant applies?

Run the free SAQ selector. It walks the official PCI SSC decision flow, records every answer, and re-derives the recommendation server-side with a confidence score — so you get a defensible record of why a given SAQ was chosen.

Source: PCI Security Standards Council, Self-Assessment Questionnaire Instructions and Guidelines for PCI DSS v4.0.1 r1. This guide is an independent summary and is not endorsed by PCI SSC.