Self-Assessment Questionnaires (SAQs) are verification tools provided by the PCI SSC that help merchants and service providers report their PCI DSS compliance. Several SAQ types apply depending on payment-processing methods.
The PCI SAQ applies to small merchants and service providers who must comply with all applicable PCI DSS standards but do not have to undergo an on-site assessment or submit a Report on Compliance:
- Level 2 Service Providers processing fewer than 300,000 credit card transactions annually.
- Level 2, 3 and 4 Merchants processing fewer than 6,000,000 credit card transactions annually.
SC2labs provides assistance in completing SAQs.
Merchants:
- SAQ A — account data functions completely outsourced; e-commerce or mail/telephone-order (card-not-present).
- SAQ A-EP — e-commerce merchants whose website does not receive account data but affects payment security.
- SAQ B — imprint machines or standalone, dial-out terminals only.
- SAQ B-IP — standalone, PCI-listed approved PTS POI devices with an IP connection.
- SAQ C-VT — third-party virtual payment terminal on an isolated device.
- SAQ C — payment application systems connected to the Internet, no electronic account-data storage.
- SAQ P2PE — account data processed only via a validated PCI-listed P2PE solution.
- SAQ D for Merchants — merchants eligible for self-assessment but not meeting other SAQ criteria.
Service Providers: SAQ D for Service Providers — the only SAQ option for service providers.
We can assist at every stage and level of the SAQ:
- when the type of SAQ to be completed is unknown, or to verify the right selection;
- through SAQ consultation or a comprehensive service with workshops;
- a review service to assess whether the SAQ has been completed correctly;
- a dedicated SAQ assessment where a QSA auditor's signature is required.
You may also be interested in:
Reference: PCI SSC Document Library.



