We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Free interactive tool

Which PCI DSS SAQ applies to you?

Answer three quick questions about how you accept card payments and get an indicative read on your Self-Assessment Questionnaire type — from the lightest SAQ A to the full SAQ D — and what decides it.

1. Which best describes you?
2. Do you store account data electronically after authorisation?
3. How do you accept card payments? (pick the option covering ALL your channels)

How SAQ selection works

Nine SAQ types, one right answer

SAQ A, A-EP, B, B-IP, C, C-VT, P2PE and the two SAQ D variants each match a specific payment-channel pattern. Completing the wrong one means either wasted effort or invalid validation.

Eligibility is strict

Every lighter SAQ carries eligibility criteria — one channel outside them and you fall back to SAQ D. Mixed channels can require more than one SAQ, and your acquirer makes the final call.

Your SAQ is a scoping choice

Tokenisation, validated P2PE or fully outsourcing card capture can legitimately move you from SAQ D to a far lighter questionnaire. The cheapest control is the one you make out of scope.

Not sure you’re in scope? Start there →Explore our PCI DSS QSA services →