Every organisation that accepts, transmits and stores payments must complete one or more Self-Assessment Questionnaires (SAQ) to evidence PCI compliance.
A range of SAQs has been developed to suit a variety of business types, since organisations come in all shapes and sizes.
The very first step towards correct completion is to identify which SAQs are applicable to your organisation.
Use our chart to see which SAQs are correct for you.
Choosing the wrong Self-Assessment Questionnaire is one of the most common early mistakes in a PCI DSS programme. This datasheet names all eight SAQ types and explains what distinguishes them: SAQ A for fully outsourced payments, A-EP for partially outsourced e-commerce, B and B-IP for imprint machines and standalone terminals, C and C-VT for internet-connected systems and virtual terminals, P2PE-HW for validated hardware, and SAQ D for everything else. SAQ D carries the heaviest burden, including vulnerability testing. Use it to work out which questionnaire your payment channels actually require before committing to an assessment.
