We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Open resource · no email gate · CC BY 4.0 · v1.0.0

The PCI DSS SAQ eligibility table

All nine Self-Assessment Questionnaire types, who each is for, and the eligibility catch that usually trips people. The authoritative criteria are the SAQ documents in the PCI SSC document library — and your acquirer makes the final call.

Raw Markdown →Interactive selector →

SAQ A

E-commerce / MOTO, fully outsourced

Who it is for: Card-not-present merchants with ALL account data functions fully outsourced to PCI DSS validated third parties (hosted page, full redirect or compliant iframe).

Watch out: Your systems must never touch card data; recent revisions tightened e-commerce page-security expectations.

SAQ A-EP

E-commerce, partially outsourced

Who it is for: E-commerce merchants whose website doesn't receive card data but controls how it is sent to the processor (direct post / JavaScript from your page).

Watch out: Much heavier than SAQ A — your web environment is in scope. A full redirect/iframe integration is often cheaper than A-EP compliance.

SAQ B

Imprint / dial-out terminals

Who it is for: Merchants using imprint machines or standalone dial-out terminals only, no electronic storage.

Watch out: Only while terminals are truly dial-out; moving to IP connectivity shifts you to B-IP.

SAQ B-IP

Standalone IP terminals

Who it is for: Merchants with standalone, PTS-approved terminals connected over IP, no electronic storage.

Watch out: The terminals' IP path is in scope — segment it.

SAQ C-VT

Virtual terminal

Who it is for: Merchants keying one transaction at a time into a virtual terminal on an isolated workstation.

Watch out: Eligibility hinges on isolation: dedicated workstation, no storage, no batch processing.

SAQ C

Connected POS / payment application

Who it is for: Merchants with POS or payment-application systems connected to the internet, no electronic storage.

Watch out: Segmentation from the rest of the network is what keeps this scope from spreading.

SAQ P2PE

Validated P2PE hardware

Who it is for: Merchants using only hardware terminals from a PCI-listed, validated P2PE solution.

Watch out: Only LISTED, validated P2PE solutions qualify — not any 'encrypting' terminal.

SAQ D (Merchant)

Everything else

Who it is for: All merchants not meeting a lighter SAQ's eligibility — including anyone storing account data electronically.

Watch out: Before accepting SAQ D, scope: tokenisation, P2PE or outsourcing capture can move you to a far lighter SAQ.

SAQ D (Service Provider)

Service providers

Who it is for: Service providers eligible to self-assess; many acquirers and brands require a QSA-led ROC for larger providers instead.

Watch out: Confirm early which path your customers and acquirers will actually accept.

Mixed channels, or not sure?

Mixed channels can require more than one SAQ, and storing account data electronically means SAQ D regardless of channel. As a PCI SSC-listed QSA company we confirm SAQ type and eligibility as part of scoping.

Run the 3-question selector →

v1.0.0 · updated 2026-08-01 · CC BY 4.0 — reuse with attribution to CyberSigma.