PCI DSS Self-Assessment Questionnaires

The official SAQ types PCI SSC publishes for validating compliance, who each one is for, and how to confirm you are eligible.

Quick decision helper

Answer a couple of questions to find the right PCI path.

What are you trying to figure out?

What an SAQ is

A Self-Assessment Questionnaire (SAQ) is a PCI Security Standards Council reporting tool. Eligible merchants and service providers use it to assess their environment against PCI DSS and report the result.

An SAQ is not a certificate, and it is not a permission slip you pick from a menu. It is the form that matches a specific kind of payment environment. Each SAQ has eligibility criteria. If you miss even one of them, that SAQ is the wrong form.

PCI SSC publishes the current SAQs and the SAQ Instructions and Guidelines in its Document Library (filter by SAQ). Confirm eligibility with the organization that will receive your paperwork, usually your acquirer or payment brand, before you start filling anything in.

If a Report on Compliance (ROC) is required instead, none of the SAQs apply; the organization that receives your paperwork makes that call, and the PCI DSS page covers what to ask them. If a Qualified Security Assessor (QSA) has to review or sign the SAQ, see What is a QSA-validated SAQ?.

How to choose

Work through the payment environment, not the shortest questionnaire:

  1. Confirm you are allowed to self-assess at all.
  2. List every payment channel (e-commerce, terminals, phone orders, invoices, and so on).
  3. For each channel, ask where account data is entered, where it travels, and whether you store it.
  4. Check whether you rely on a PCI-listed solution, such as a validated point-to-point encryption (P2PE) solution or a listed Software-based PIN Entry on COTS (SPoC) solution. Several shorter SAQs exist only because those listings exist.
  5. Match the channel to a SAQ whose eligibility criteria you meet in full.
  6. If any channel does not fit a shorter SAQ, that channel belongs on SAQ D, and many organizations then use SAQ D for the whole assessment.

A Qualified Security Assessor company (QSAC) can still help you complete or review an SAQ. Some acquirers require that even when a ROC is not required.

For a shorter decision path, see Which PCI SAQ do I need?.

Merchant SAQs

These questionnaires are for merchants only.

SAQUse it when
ACard-not-present only (e-commerce or mail/telephone order). All processing is outsourced to PCI DSS compliant third-party service providers. You do not store, process, or transmit account data electronically. For e-commerce, the payment page or form delivered to the customer’s browser comes only and directly from that provider (redirect or embedded iframe). Face-to-face payments do not qualify.
A-EPE-commerce where payment processing is outsourced, but your website can affect the security of the payment (for example, you control scripts or page elements on the payment page). You still do not receive account data on your own systems.
BImprint machines and/or standalone dial-out terminals. No electronic storage of account data. Not for IP-connected terminals.
B-IPStandalone PCI-approved point-of-interaction terminals that connect over IP and are not mixed with other device types in the same network zone. No electronic storage of account data.
C-VTVirtual payment terminals (a web-based terminal you type card data into) on an isolated computer. No electronic storage of account data.
CA payment application connected to the internet. No electronic storage of account data.
P2PEHardware payment terminals used only in a PCI-listed P2PE solution. You do not store account data electronically and do not have access to it.
SPoCA commercial off-the-shelf phone or tablet plus a secure card reader, used only as part of a PCI-listed SPoC solution. Find listed solutions from the PCI SSC product and solution listings.
D (Merchant)Any other SAQ-eligible merchant environment, including any merchant that stores electronic account data, or whose channels do not fit a shorter SAQ.

The shorter SAQs omit requirements that do not apply to that environment. They are not a discount. If a requirement that matters in your cardholder data environment is missing from the form, you chose the wrong SAQ.

Service-provider SAQ

Service providers who are allowed to self-assess have one option: SAQ D for Service Providers. Merchant SAQs do not apply.

That questionnaire covers the full PCI DSS requirement set, including items marked for service providers only. Requirements that truly do not apply can be marked Not Applicable and explained in the appendix. Scope still has to be right first.

Several payment channels

A store with a website and a counter is two environments, not one SAQ by default.

PCI SSC allows a merchant to complete a separate SAQ for each channel when each channel independently meets that SAQ’s eligibility criteria. If any channel does not, SAQ D is the usual path for that environment. Ask the receiving organization whether it wants one packet or several.

Do not stitch together the shortest questions from two SAQs onto one form.

What you submit

A completed SAQ is paired with an Attestation of Compliance (AOC). Some programs also want passing Approved Scanning Vendor (ASV) scan reports or other evidence. The SAQ itself is the assessment record. The AOC is the summary you are more likely to share.

Get the current forms from the PCI SSC Document Library. Do not reuse an old version from a prior year or a vendor’s copy. The PCI SSC FAQ library covers common SAQ questions, including which SAQ to complete and how to handle more than one channel.

Published August 28, 2026. Updated September 3, 2026.