SAQ (Self Assessment Questionnaire)
PCIComplianceHubLast updated
A validation document an eligible organization completes itself, rather than engaging an assessor, to record how it meets PCI DSS. There are nine questionnaires, each scoped to a specific way of accepting payments: A, A-EP, B, B-IP, C, C-VT, P2PE, SPoC and D, with D published in separate merchant and service provider versions. Each has strict eligibility criteria, and selecting the wrong one is a common and consequential error, because it can leave whole categories of requirement unassessed. Eligibility to self-assess at all is set by the payment brands and the acquirer, based on merchant or service provider level.
Applies to. Merchants and service providers that the payment brands and their acquirer permit to validate by self-assessment, and that meet every eligibility criterion of the questionnaire they choose.
Example. A small e-commerce merchant using a provider's redirect, storing no account data and confirming its site is not susceptible to script attacks, completes SAQ A and its Attestation of Compliance and sends both to its acquirer.
Limits. Eligibility is checked twice. Whether the entity may self-assess at all is the acquirer's and the brands' decision; whether a given SAQ fits is decided by that SAQ's own criteria. The questionnaires are validation tools, not a reduced standard: an SAQ omits requirements because the environment it describes cannot have the risk they address, and an environment that has that risk must use a fuller SAQ or SAQ D. The instructions recommend confirming with the acquirer or the brands which SAQ applies.