SAQ A-EP
PCIComplianceHubLast updated
The Self-Assessment Questionnaire for e-commerce merchants that outsource payment processing to a PCI DSS compliant third party but whose own website can affect the security of the transaction: a direct post to the provider, a payment form served from the merchant origin, or merchant-controlled scripts able to reach the payment page. The merchant does not store account data electronically. Embedding a provider-hosted payment page in an iframe is not on its own an A-EP trigger; that integration sits under SAQ A. A-EP is substantially longer than SAQ A because the merchant website is in scope.
Applies to. E-commerce merchants only, whose website does not receive account data but controls how customers or their data reach the provider, or delivers scripts that affect the payment page.
Example. A merchant serves its own card form and posts the data straight to the provider (direct post), or loads a provider script that builds the form on the merchant page. Either is A-EP: 139 requirements, against 27 for SAQ A.
Limits. The line between A and A-EP is the payment page: if any element of the page delivered to the browser originates from the merchant's website, SAQ A does not apply. A merchant hosted by a third party must also confirm the host is compliant, including Appendix A1 if it is a multi-tenant provider. A-EP still requires no electronic storage of account data; a merchant that stores any is on SAQ D.