Choosing the Right PCI DSS SAQ: A Merchant’s Guide to Self-Assessment Questionnaires
For the majority of small and mid-sized merchants, PCI DSS compliance is validated not through an on-site audit but through a Self-Assessment Questionnaire, or SAQ. Choosing the correct SAQ is essential: pick one that is too narrow and you may understate your obligations, pick one too broad and you create needless work. This guide clarifies which questionnaire fits which business model.
How Merchant Level Affects Validation
Card brands classify merchants into levels based on annual transaction volume. Level 1 merchants, typically those processing over six million transactions a year, generally require a Report on Compliance from a Qualified Security Assessor or an internal auditor. Levels 2 through 4 are usually eligible to validate through an SAQ, though individual acquiring banks can impose stricter requirements, so always confirm expectations with your acquirer.
The SAQ Types Explained
SAQ A
Designed for card-not-present merchants who have fully outsourced all cardholder data functions to compliant third parties. Think e-commerce sites using a hosted payment page or full redirect. This is the shortest questionnaire because the merchant never handles card data directly, though version 4.0 added new requirements around the security of the merchant’s own site.
SAQ A-EP
Applies to e-commerce merchants who partially outsource payment processing but whose website can still affect the security of the transaction, such as sites using a direct-post or JavaScript-based integration. It is considerably longer than SAQ A because the merchant’s environment can influence the payment.
SAQ B and B-IP
For merchants using standalone dial-out terminals (B) or standalone IP-connected terminals (B-IP), with no electronic cardholder data storage. Common among small brick-and-mortar businesses.
SAQ C and C-VT
SAQ C covers merchants with payment application systems connected to the internet. C-VT applies to those using a web-based virtual terminal on an isolated computer with no electronic storage.
SAQ P2PE
The shortest hardware-based questionnaire, available only to merchants using a validated point-to-point encryption solution listed by the PCI SSC.
SAQ D
The catch-all. SAQ D applies to all other merchants and to service providers, and it covers the full breadth of PCI DSS requirements. If you store cardholder data electronically for any reason, you almost certainly fall here, and you should plan for a substantial validation effort rather than a quick questionnaire.
Match the SAQ to Your Data Flow
The safest way to choose is to trace exactly where a card number travels from the moment a customer enters it. If it never touches your systems, you are likely in SAQ A territory. If your page collects it, posts it, or hosts scripts that could intercept it, you move up to A-EP or beyond. Physical terminals, virtual terminals, and validated encryption each map to their own dedicated questionnaire, so let the actual flow, not convenience, drive the decision.
Common Mistakes to Avoid
- Assuming SAQ A applies when your site loads payment scripts directly, which usually pushes you to SAQ A-EP.
- Overlooking connected systems that expand your obligations beyond the payment page.
- Forgetting that SAQ eligibility can change when you modify your checkout integration or add a new sales channel.
The SAQ you complete is a reflection of how card data flows through your environment. When the flow changes, revisit your eligibility.
Conclusion
Selecting the right SAQ starts with an honest map of how cardholder data enters, moves through, and leaves your business. When in doubt, consult your acquiring bank or a Qualified Security Assessor before you attest. Getting this decision right protects you from both wasted effort and the far greater cost of an inaccurate attestation that unravels after an incident.