Which PCI SAQ do I need?
How to match your payment channels to the correct PCI DSS Self-Assessment Questionnaire.
The short version
You do not pick a Self-Assessment Questionnaire (SAQ) because it is short. You pick it because your payment environment matches its eligibility criteria in full.
Confirm three things first:
- Your acquirer or payment brand allows you to self-assess (a Report on Compliance may be required instead).
- How you take payments, channel by channel.
- Whether account data is stored, processed, or transmitted on systems you control, or only by a PCI DSS compliant provider or a PCI-listed solution.
Then match each channel to an official SAQ. The types, eligibility, and official forms are in PCI DSS Self-Assessment Questionnaires. If a QSA has to review or sign the SAQ, see What is a QSA-validated SAQ?.
How to think about it
- How do you take payments? E-commerce, terminals, phone or mail order, invoices, and mobile readers are different channels.
- Do you store or process cardholder data? Electronic storage usually means SAQ D for merchants, not a shorter form.
- Who controls the payment page or device? A redirect or iframe to a compliant provider can be SAQ A. Merchant-controlled scripts on the payment page are a different questionnaire (SAQ A-EP). A PCI-listed point-to-point encryption or Software-based PIN Entry on COTS solution can open a shorter path, but only if you meet every criterion.
If any channel does not fit a shorter SAQ, use SAQ D for that environment. Service providers who may self-assess use SAQ D for Service Providers only.
If the answer is a ROC rather than an SAQ, no questionnaire applies and you will engage a QSA company for a full assessment; the PCI DSS page covers how to confirm which one you have been assigned.
Published July 30, 2026. Updated September 3, 2026.