PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · SAQ FAQ

PCI DSS SAQ frequently asked questions

Practical answers to the most common SAQ questions, grounded in the PCI SSC Self-Assessment Questionnaire Instructions and Guidelines v4.0.1 r1. If you need a defensible recommendation, use the free SAQ selector.

Questions and answers

Who decides which SAQ I complete?
You do, but your acquirer or payment brand is the compliance-accepting entity. PCI SSC publishes the eligibility criteria; the payment brands and your acquirer set validation and reporting requirements. Confirm your chosen SAQ with them before you submit.
What is the difference between SAQ A and SAQ A-EP?
SAQ A applies when every element of the payment page comes only and directly from a PCI DSS compliant third-party provider — typically a full redirect or a provider-hosted iframe. SAQ A-EP applies when your own website delivers part of the payment page or controls how the customer or their account data is redirected, such as Direct Post or JavaScript-created payment forms.
I accept payments through more than one channel. Do I need more than one SAQ?
Possibly. Each payment channel must independently meet the eligibility criteria of the SAQ used for it. PCI SSC advises merchants with more than one channel to consult their acquirer and payment brands about validation and reporting. Where channels cannot each satisfy the same criteria, SAQ D for Merchants covers the remainder.
Does storing card data electronically rule out a short-form SAQ?
Yes. Every short-form SAQ requires that no account data is stored in electronic format, including legacy data. If you store account data electronically, SAQ D for Merchants applies.
Are Secure Card Readers eligible for SAQ B-IP?
No. SAQ B-IP is limited to standalone PCI-listed approved PTS POI devices and explicitly excludes SCRs and SCRPs. The device must also not rely on another device, such as a computer or phone, to connect to the processor.
Is an SAQ enough, or do I need a QSA?
Level 1 merchants, Level 1 service providers, designated entities subject to PCI DSS Appendix A3, and anyone whose acquirer has mandated a Report on Compliance cannot self-assess. Everyone else may be eligible for an SAQ, subject to their acquirer's acceptance.
What is SAQ D and when does it apply?
SAQ D for Merchants is the catch-all SAQ for merchants that do not meet the eligibility criteria for any other SAQ. If you store account data electronically, run a mix of channels that cannot each use a short form, or otherwise fail a short-form SAQ's eligibility criteria, SAQ D for Merchants is the honest answer.
Can a service provider use any SAQ other than SAQ D for Service Providers?
No. SAQ D for Service Providers is the only SAQ available to service providers. It applies only to service providers that have been determined eligible to self-assess by their compliance-accepting entity.
What is a PCI-listed P2PE solution?
A PCI-listed Point-to-Point Encryption (P2PE) solution is a solution that appears on the PCI SSC list of validated P2PE Solutions. The merchant must implement every control in the P2PE Instruction Manual (PIM) provided by the solution provider. Using encrypting terminals that are not on the PCI-listed P2PE list does not qualify.
What is a PCI-listed SPoC solution?
A PCI-listed Software-based PIN Entry on COTS (SPoC) solution pairs a PCI-listed approved PTS Secure Card Reader-PIN (SCRP) with a commercial off-the-shelf (COTS) phone or tablet. It is only for attended card-present transactions and must be listed on the PCI SSC validated SPoC Solutions list.
Does using an iframe from a compliant provider automatically qualify for SAQ A?
Not automatically. Every element of the payment page delivered to the customer's browser must originate only and directly from the PCI DSS compliant provider. If your own site delivers any element of the payment page, or if you use scripts that could affect the payment page, SAQ A may not apply.
Where can I find the official SAQ criteria?
The definitive source is the PCI Security Standards Council Self-Assessment Questionnaire Instructions and Guidelines for PCI DSS v4.0.1 r1. Our guides mirror those criteria; the official document remains the compliance reference.

Not sure which answer applies to you?

Our free SAQ selector walks the official PCI SSC decision flow, records every answer, and re-derives the recommendation server-side with a confidence score — so you get a defensible record of why a given SAQ was chosen.

Source: PCI Security Standards Council, Self-Assessment Questionnaire Instructions and Guidelines for PCI DSS v4.0.1 r1. This FAQ is an independent summary and is not endorsed by PCI SSC.