Critical ResourceVisa CEDP: Major Payments Disruption
Back to Glossary

PCI SAQ

Payment Card Industry Self-Assessment Questionnaire is a validation tool used by most merchants to demonstrate PCI DSS compliance through responses to security-related questions, with different questionnaire types (A, A-EP, B, B-IP, C, D, P2PE) based on the merchant's payment processing methods and environment.

The PCI Security Standards Council offers several SAQ types designed for different merchant scenarios, ranging from simple 22-question forms to comprehensive 329-question assessments. The correct SAQ depends on how the merchant accepts and processes payments. SAQ A (22 questions) is for e-commerce merchants who fully outsource payment processing to PCI-compliant third parties and don't store cardholder data. SAQ A-EP (178 questions) is for e-commerce merchants with website-hosted payment pages. SAQ B (41 questions) is for merchants using standalone, dial-out terminals. SAQ B-IP (82 questions) is for merchants using standalone IP-connected terminals. SAQ C (160 questions) is for merchants with payment applications connected to the internet. SAQ D-Merchant (329 questions) is the most comprehensive, for merchants not qualifying for other SAQs. SAQ P2PE-HW applies to merchants using validated point-to-point encryption solutions.

Selecting the correct SAQ is critical because using an unnecessarily complex form wastes time and resources, while using an overly simplified form that doesn't match the merchant's actual environment constitutes false compliance. Most e-commerce merchants using hosted payment pages or payment service providers qualify for SAQ A or A-EP, while retail merchants using modern terminals qualify for SAQ B-IP or P2PE-HW. The SAQ includes specific security requirements like maintaining firewall configurations, encrypting cardholder data transmission, regularly updating systems, restricting access to cardholder data, and implementing physical security measures.

Merchants must complete an SAQ annually, along with an Attestation of Compliance signed by an authorized officer confirming all requirements are met. Merchants at certain levels also require quarterly network vulnerability scans performed by an Approved Scanning Vendor (ASV). Failure to complete SAQs results in non-compliance fees from processors, and falsifying SAQs can result in severe penalties including account termination, MATCH listing, and liability for data breach costs if inadequate security leads to compromises.

Related Content

Optimize Your Payment Processing

Let Verisave analyze your merchant statement to identify hidden fees and misconfigurations related to pci saq.

Get a Free Audit

Related Terms