PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

SAQ SPoC

SAQ SPoC includes PCI DSS requirements applicable to merchants that process account data only via a PCI-listed approved PTS Secure Card Reader-PIN (SCRP) device and accompanying commercial off-the-shelf (COTS) mobile device, as part of a validated PCI-listed SPoC solution.

SAQ SPoC at a glance

Who it is for

Attended card-present merchants using a validated PCI-listed SPoC solution

Payment channels

card-present only (attended)

Not applicable to

Unattended card-present (kiosks, self-checkout); MOTO; E-commerce; Service providers

Official page

PCI SSC SAQ Instructions and Guidelines v4.0.1 r1, page 22

Eligibility criteria

Every criterion below must be true for SAQ SPoC to apply. A single false criterion removes eligibility.

All payment processing is only via a card-present payment channel.
All cardholder data entry is via an SCRP that is part of a validated SPoC solution approved and listed by PCI SSC.
The only systems in the merchant's SPoC environment that store, process, or transmit account data are those used as part of the validated SPoC solution.
The merchant does not otherwise receive, transmit or store account data electronically.
This payment channel is not connected to any other systems/networks within the merchant environment.
Any account data the merchant might retain is on paper (for example, printed reports or receipts), and these documents are not received electronically.
The merchant has implemented all controls in the SPoC user guide provided by the SPoC Solution Provider.

What the selector checks

The free PCI Assessments Center SAQ selector turns the official criteria into a fail-closed checklist. These are the exact items it verifies for SAQ SPoC:

All payment processing is via an ATTENDED card-present channel (no unattended terminals, no MOTO, no e-commerce).
All cardholder data entry is via an SCRP that is part of a validated SPoC solution approved and listed by PCI SSC (non-PTS-listed magnetic-stripe readers are not eligible).
The only systems in our SPoC environment that store, process, or transmit account data are those used as part of that validated SPoC solution.
We do not otherwise receive, transmit, or store account data electronically.
This payment channel is NOT connected to any other systems / networks within our environment.
Any account data we retain is on paper only (printed reports/receipts) and is not received electronically.
We have implemented all controls in the SPoC user guide provided by the SPoC Solution Provider.

Baseline disqualifiers

Before any short-form SAQ can apply, the merchant must also satisfy these baseline checks:

We do NOT store any account data in electronic format on our systems, including legacy data (PAN, cardholder name, service code, expiration date, or sensitive authentication data). Paper-only receipts or reports are fine.
We are NOT a designated entity that our acquirer or payment brand has required to complete PCI DSS Appendix A3 / DESV.
Our acquirer or payment brand has NOT required us to complete a full Report on Compliance (ROC).
We have NOT experienced a confirmed account-data breach in the last 12 months that our acquirer has told us to escalate.

Common mistake

SPoC is not available for unattended terminals, MOTO, or e-commerce, and the channel must not be connected to your other systems.

Not sure if SAQ SPoC applies?

Run the free SAQ selector. It walks the official PCI SSC decision flow, records every answer, and re-derives the recommendation server-side with a confidence score — so you get a defensible record of why a given SAQ was chosen.

Source: PCI Security Standards Council, Self-Assessment Questionnaire Instructions and Guidelines for PCI DSS v4.0.1 r1. This guide is an independent summary and is not endorsed by PCI SSC.