PCI SSC revises FAQ 1331 on using SAQs to scope ROC assessments

August 10, 2026

About: PCI DSS

#program-changes

On August 4, 2026, the PCI Security Standards Council (PCI SSC) published a revised update to FAQ 1331. The FAQ answers whether Self-Assessment Questionnaire (SAQ) eligibility criteria can guide which Payment Card Industry Data Security Standard (PCI DSS) requirements apply when a merchant completes a Report on Compliance (ROC).

PCI SSC said the May 2025 version of the FAQ could be misread on who decides compliance-adherence responsibilities. The August 2026 text puts that decision back with the merchant’s Compliance Accepting Entity (typically the acquirer or payment brand), not with a merchant and Qualified Security Assessor (QSA) alone.

What changed

The current FAQ 1331 states that SAQs are reporting tools for designated use cases, subject to the rules of the organizations that manage compliance programs. It now says SAQs should not be used as a “guide” for PCI DSS requirement applicability unless the approach is explicitly reviewed, discussed, and agreed with the merchant’s Compliance Accepting Entity.

In practice, that means:

  • Merchant and QSA agreement alone is not enough to treat an SAQ control set as the ROC applicability guide
  • Merchants must confirm validation and reporting expectations with their acquirer or payment brand before narrowing ROC testing that way
  • Related FAQ 1473 still explains how Compliance Accepting Entities and assessors divide roles when deciding applicability
  • Payment brand contact paths remain in FAQ 1142

PCI DSS requirements themselves did not change. This is guidance about assessment scoping and acceptance, not a new version of the standard. Merchants that never used SAQ eligibility criteria to prune a ROC are largely unaffected; merchants and QSAs that relied on the May 2025 reading need to reconfirm the approach with the accepting entity.

What to do now

  1. If you are in a ROC (or preparing one) and planned to use SAQ eligibility criteria to decide which requirements apply, pause and get written confirmation from your Compliance Accepting Entity.
  2. Ask your QSA to document how applicability and Not Applicable / Not Tested decisions will be evidenced under the revised FAQ 1331 and FAQ 1473.
  3. Re-check any draft Attestation of Compliance language that assumed SAQ-based ROC scoping without acquirer or brand agreement.
  4. Keep validating against the PCI DSS version and SAQ your accepting entity requires; this FAQ update does not replace SAQ A or other SAQ eligibility rules for self-assessment merchants.
  5. Follow PCI DSS on this site for further Council FAQ and program updates.

#program-changes

← Back to news