PCI SAQ support

Self-Assessment Questionnaires (SAQs) are verification tools provided by the PCI SSC that help merchants and service providers report their PCI DSS compliance. Several SAQ types apply depending on payment-processing methods.

The PCI SAQ applies to small merchants and service providers who must comply with all applicable PCI DSS standards but do not have to undergo an on-site assessment or submit a Report on Compliance:

  • Level 2 Service Providers processing fewer than 300,000 credit card transactions annually.
  • Level 2, 3 and 4 Merchants processing fewer than 6,000,000 credit card transactions annually.
SC2labs provides assistance in completing SAQs.

Merchants:

  • SAQ A — account data functions completely outsourced; e-commerce or mail/telephone-order (card-not-present).
  • SAQ A-EP — e-commerce merchants whose website does not receive account data but affects payment security.
  • SAQ B — imprint machines or standalone, dial-out terminals only.
  • SAQ B-IP — standalone, PCI-listed approved PTS POI devices with an IP connection.
  • SAQ C-VT — third-party virtual payment terminal on an isolated device.
  • SAQ C — payment application systems connected to the Internet, no electronic account-data storage.
  • SAQ P2PE — account data processed only via a validated PCI-listed P2PE solution.
  • SAQ D for Merchants — merchants eligible for self-assessment but not meeting other SAQ criteria.

Service Providers: SAQ D for Service Providers — the only SAQ option for service providers.

We can assist at every stage and level of the SAQ:

  • when the type of SAQ to be completed is unknown, or to verify the right selection;
  • through SAQ consultation or a comprehensive service with workshops;
  • a review service to assess whether the SAQ has been completed correctly;
  • a dedicated SAQ assessment where a QSA auditor's signature is required.

You may also be interested in:

ASV Scanning
Pentests
Training
Information Security Policy