We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Free tool

Which PCI DSS SAQ do you need?

Answer a few questions about how you accept cards and see your likely SAQ type — A, A-EP, B, B-IP, C, C-VT, P2PE or D — with the eligibility criteria that matter, checked against PCI DSS v4.

1. Are you a merchant or a service provider?

How SAQ selection really works

The SAQ follows the money flow

Your SAQ type is decided by how account data moves — who serves the payment page, where terminals connect, and whether anything is ever stored. Change the flow and you change the SAQ.

Storage always means SAQ D

Electronically storing account data after authorisation puts every requirement in scope, whatever your channel. Most merchants who think they need storage can eliminate it — and drop to a far shorter SAQ.

Your acquirer has the final say

SAQ eligibility is granted by your acquirer and the payment brands, not self-declared. A short QSA conversation before you commit avoids validating against the wrong questionnaire.

SAQ questions we hear every week

What is a PCI DSS SAQ?

A Self-Assessment Questionnaire is the validation document eligible merchants and service providers complete instead of a full QSA Report on Compliance. Each SAQ type contains only the requirements relevant to a specific way of accepting cards.

Which SAQ is the shortest?

SAQ A, for fully outsourced card-not-present payments, is the shortest, with P2PE close behind. SAQ D is the full standard and applies whenever account data is stored electronically or no other SAQ fits.

Can one business need two SAQs?

Yes. A merchant with both a shop terminal and an online store often validates each channel separately — for example SAQ B-IP for the terminals and SAQ A for the website. Some acquirers instead ask for the single most comprehensive SAQ.

Do SAQ A merchants need a penetration test?

SAQ A itself does not require one, but if your website delivers the payment form or its script you are in SAQ A-EP territory, which does. Misclassifying A-EP as A is one of the most common PCI mistakes we see.

Not sure PCI DSS applies to you at all? Run the scope checker first. Ready to validate? Start from the PCI DSS compliance service, grab the free evidence checklist, or estimate testing spend with the VAPT cost calculator.