PCI SAQ
Payment Card Industry Self-Assessment Questionnaire is a validation tool used by most merchants to demonstrate PCI DSS compliance through responses to security-related questions, with different questionnaire types (A, A-EP, B, B-IP, C, D, P2PE) based on the merchant's payment processing methods and environment.
The PCI Security Standards Council offers several SAQ types designed for different merchant scenarios, ranging from simple 22-question forms to comprehensive 329-question assessments. The correct SAQ depends on how the merchant accepts and processes payments. SAQ A (22 questions) is for e-commerce merchants who fully outsource payment processing to PCI-compliant third parties and don't store cardholder data. SAQ A-EP (178 questions) is for e-commerce merchants with website-hosted payment pages. SAQ B (41 questions) is for merchants using standalone, dial-out terminals. SAQ B-IP (82 questions) is for merchants using standalone IP-connected terminals. SAQ C (160 questions) is for merchants with payment applications connected to the internet. SAQ D-Merchant (329 questions) is the most comprehensive, for merchants not qualifying for other SAQs. SAQ P2PE-HW applies to merchants using validated point-to-point encryption solutions.
Selecting the correct SAQ is critical because using an unnecessarily complex form wastes time and resources, while using an overly simplified form that doesn't match the merchant's actual environment constitutes false compliance. Most e-commerce merchants using hosted payment pages or payment service providers qualify for SAQ A or A-EP, while retail merchants using modern terminals qualify for SAQ B-IP or P2PE-HW. The SAQ includes specific security requirements like maintaining firewall configurations, encrypting cardholder data transmission, regularly updating systems, restricting access to cardholder data, and implementing physical security measures.
Merchants must complete an SAQ annually, along with an Attestation of Compliance signed by an authorized officer confirming all requirements are met. Merchants at certain levels also require quarterly network vulnerability scans performed by an Approved Scanning Vendor (ASV). Failure to complete SAQs results in non-compliance fees from processors, and falsifying SAQs can result in severe penalties including account termination, MATCH listing, and liability for data breach costs if inadequate security leads to compromises.
Related Content
Optimize Your Payment Processing
Let Verisave analyze your merchant statement to identify hidden fees and misconfigurations related to pci saq.
Get a Free AuditRelated Terms
3D Secure
An authentication protocol for online card transactions that adds an additional verification layer between the cardholder and issuing bank, shifting fraud liability from merchants to card issuers when properly implemented.
ACH Payment
Automated Clearing House payment is an electronic bank-to-bank payment method that transfers funds directly between bank accounts through the ACH network, typically used for direct deposits, bill payments, and recurring transactions.
Acquirer
A financial institution that processes credit card payments on behalf of merchants, maintains merchant accounts, and facilitates the settlement of funds from card-issuing banks to merchant bank accounts.
Address Verification Service (AVS)
A fraud prevention tool that compares the numeric portions of a billing address provided during a transaction against the address registered with the card-issuing bank, returning match result codes to help merchants assess transaction risk.
Aggregator
A payment service provider that enables multiple merchants to process card transactions under a single master merchant account rather than each merchant having their own dedicated merchant account, common with services like Square, Stripe, and PayPal.