PCI DSS

What is a PCI SAQ?

Short answer

A PCI SAQ is a Self-Assessment Questionnaire: the form a merchant or service provider completes to validate PCI DSS compliance without a full assessment by a Qualified Security Assessor. There are several versions, each covering a different way of accepting payments, and each one prints its eligibility criteria at the front. You complete the questionnaire, attach a signed Attestation of Compliance, and give it to your acquirer or whoever asked for it.

Last updated

What an SAQ is for

Validation is the act of reporting your compliance to someone who requires it: an acquirer, a card brand, or a customer. An SAQ is the self-reported route. You answer each applicable requirement In Place, In Place with CCW (a compensating control worksheet), Not Applicable, Not Tested or Not in Place, then sign an Attestation of Compliance. A questionnaire with Not in Place answers is still a legitimate submission, and it tells the recipient where you are rather than claiming something untrue.

The SAQ types

SAQ A is for merchants who fully outsource all cardholder data functions to compliant third parties, with no card data on their own systems. SAQ A-EP is for e-commerce merchants whose site does not receive card data but does affect the security of the payment transaction, for example by serving the page that loads the processor’s form. SAQ B covers imprint machines or standalone dial-out terminals with no electronic storage. SAQ B-IP covers standalone terminals with an IP connection. SAQ C is for merchants with a payment application connected to the internet but no electronic cardholder data storage, and SAQ C-VT for those using one isolated virtual terminal. SAQ P2PE is for merchants using a validated point-to-point encryption solution, and SAQ SPoC for those using a PCI-listed software-based PIN entry solution on a commercial off-the-shelf device. SAQ D is the long one, in two editions: SAQ D for Merchants, and SAQ D for Service Providers.

How you find out which one applies

Eligibility is not a preference. Each SAQ states its criteria at the front, and the questions are about your payment flow: does card data touch your systems, do you store it, what sort of terminal or integration do you use. Read the current version of the criteria against how you actually take payment, and confirm with your acquirer, which is the party that accepts your submission.

When an SAQ is not enough

Level 1 merchants and Level 1 service providers need a Report on Compliance produced by a Qualified Security Assessor, or by a qualified internal auditor where the card brand allows it. Levels are set by the card brands from transaction volume, and the thresholds differ by brand, so your acquirer is the authority on which one you are. A customer or partner can also insist on a QSA assessment regardless of your level.

Where Keel fits

Keel tracks PCI DSS v4.0.1 at its second-level requirements (for example 6.3 and 11.3) as controls with owners, status and evidence. It does not track the defined requirements an SAQ asks about line by line, and /frameworks/pci-dss/ states that gap. Keel is not a QSA and does not sign your attestation.

FAQ

What does SAQ stand for?

Self-Assessment Questionnaire. It is the PCI DSS validation document completed by the organization itself rather than by a Qualified Security Assessor.

Which SAQ is the shortest?

SAQ A, for merchants who fully outsource every cardholder data function so no card data touches their environment. Each version has grown in v4, so check the current form rather than relying on an old count of questions.

Who do I send the SAQ to?

Whoever required it, which is usually your acquiring bank. Some card brands and some enterprise customers ask for the Attestation of Compliance directly.

Does a service provider complete an SAQ?

A service provider below Level 1 can validate with SAQ D for Service Providers. Level 1 service providers need a Report on Compliance.

How often do I complete one?

Annually, and again if your payment flow changes enough to move you to a different SAQ.

Next step

Get audit-ready with Keel

The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.