A Self-Assessment Questionnaire (SAQ) is a self-attestation tool for Merchants handling payment cards as part of Payment Card Industry Data Security Standard (PCI DSS) compliance.
A SAQ is a PCI DSS-provided form for Merchants to:
SAQs are lighter-weight than third-party assessments to generate a Report on Compliance (ROC) by a PCI Qualified Security Assessor (PCI QSA).
| SAQ type | Typical situation | Policies and standards |
|---|---|---|
| SAQ A | Card-not-present, payment fully outsourced | SAQ A |
| SAQ A-EP | E-commerce site that partly controls the payment page | SAQ A-EP |
| SAQ B | Imprint machines or standalone dial-out terminals | SAQ B |
| SAQ B-IP | Standalone IP-connected payment terminals | SAQ B-IP |
| SAQ C | Payment application systems connected to the internet | SAQ C |
| SAQ C-VT | Manual entry into a virtual terminal | SAQ C-VT |
| SAQ D (merchant) | All other merchants | SAQ D merchant |
| SAQ D (service provider) | Service providers eligible to self-assess | SAQ D service provider |
Eligibility rules are set by the PCI Security Standards Council; confirm your SAQ type against the current SAQ instructions.