Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient  |  Got Questions? +1-307-241-8740
ComplianceForge

What is a SAQ?

Direct Answer

A Self-Assessment Questionnaire (SAQ) is a self-attestation tool for Merchants handling payment cards as part of Payment Card Industry Data Security Standard (PCI DSS) compliance.

A SAQ is a PCI DSS-provided form for Merchants to:

  • Select the appropriate SAQ type (A, B, C, D, etc.);
  • Self-report compliance with each relevant PCI DSS requirement;
  • Provide evidence (e.g., network diagrams, encryption configs, log samples);
  • Submit an Attestation of Compliance (AOC); and
  • Document compensating controls, or remediation plans, if not fully compliant.

SAQs are lighter-weight than third-party assessments to generate a Report on Compliance (ROC) by a PCI Qualified Security Assessor (PCI QSA).

Which SAQ type applies?

SAQ typeTypical situationPolicies and standards
SAQ ACard-not-present, payment fully outsourcedSAQ A
SAQ A-EPE-commerce site that partly controls the payment pageSAQ A-EP
SAQ BImprint machines or standalone dial-out terminalsSAQ B
SAQ B-IPStandalone IP-connected payment terminalsSAQ B-IP
SAQ CPayment application systems connected to the internetSAQ C
SAQ C-VTManual entry into a virtual terminalSAQ C-VT
SAQ D (merchant)All other merchantsSAQ D merchant
SAQ D (service provider)Service providers eligible to self-assessSAQ D service provider

Eligibility rules are set by the PCI Security Standards Council; confirm your SAQ type against the current SAQ instructions.