PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

SAQ D-SP

SAQ D for Service Providers applies to all service providers defined by a payment brand as being eligible to complete a self-assessment questionnaire. For PCI DSS v4.x, SAQ D for Service Providers requires additional documentation in Section 2a and specifies that service providers 'Describe Results' for each PCI DSS requirement.

SAQ D-SP at a glance

Who it is for

Service providers eligible to self-assess

Payment channels

n/a — service providers

Not applicable to

Merchants

Official page

PCI SSC SAQ Instructions and Guidelines v4.0.1 r1, page 23

Eligibility criteria

Every criterion below must be true for SAQ D-SP to apply. A single false criterion removes eligibility.

The organisation is a service provider as defined by the payment brands.
The organisation has been determined by its compliance-accepting entity to be eligible to self-assess (not required to undergo a QSA-led Report on Compliance).

What the selector checks

The free PCI Assessments Center SAQ selector turns the official criteria into a fail-closed checklist. These are the exact items it verifies for SAQ D-SP:

Our organisation is a service provider as defined by the payment brands.
Our compliance-accepting entity (acquirer or payment brand) has determined we are eligible to self-assess and are not required to undergo a QSA-led Report on Compliance.

Common mistake

It is the only SAQ available to service providers. Level 1 service providers cannot use it.

Not sure if SAQ D-SP applies?

Run the free SAQ selector. It walks the official PCI SSC decision flow, records every answer, and re-derives the recommendation server-side with a confidence score — so you get a defensible record of why a given SAQ was chosen.

Source: PCI Security Standards Council, Self-Assessment Questionnaire Instructions and Guidelines for PCI DSS v4.0.1 r1. This guide is an independent summary and is not endorsed by PCI SSC.