SAQ A

PCIComplianceHubLast updated

The Self-Assessment Questionnaire for card-not-present merchants, e-commerce or mail and telephone order, that have outsourced all account data functions to PCI DSS compliant third parties and neither store, process nor transmit account data on their own systems. Two e-commerce integrations qualify: a full redirect to the provider, and a provider payment page or form embedded in the merchant page, typically in an iframe. Hosting that iframe does not by itself move a merchant to SAQ A-EP; what does is the merchant page collecting or handling the card data itself, as with a direct post or a form built by merchant-loaded script. For e-commerce channels, every element of the payment form delivered to the browser must originate only and directly from the compliant provider, and the merchant must confirm that its site is not susceptible to attacks from scripts that could affect its e-commerce systems, a criterion added to SAQ A for v4.x.

Applies to. Card-not-present merchants only. Not face-to-face channels and not service providers.
Example. A merchant whose checkout page is entirely hosted and managed by its provider, with no access to the page, answers 14 requirements. One that redirects to or embeds the provider's form answers 27, including quarterly ASV scans of its own website.
Limits. The script-attack criterion is written for e-commerce channels, not for embedded forms alone; the Council's comparison table lists it against SAQ A as such. The instructions state the criterion without prescribing how it is confirmed, so ask the provider and the acquirer what they will accept. The redirect and embedded integrations also gained quarterly ASV scans and scans after significant change (11.3.2 and 11.3.2.1) in v4.x, because a compromised merchant page can send customers elsewhere. MOTO channels have their own criteria, not shown in the e-commerce table.
In PCI DSS v4.0.1. 11.3.2, 11.3.2.1