Which PCI SAQ do I need?

How to match your payment channels to the correct PCI DSS Self-Assessment Questionnaire.

The short version

You do not pick a Self-Assessment Questionnaire (SAQ) because it is short. You pick it because your payment environment matches its eligibility criteria in full.

Confirm three things first:

  1. Your acquirer or payment brand allows you to self-assess (a Report on Compliance may be required instead).
  2. How you take payments, channel by channel.
  3. Whether account data is stored, processed, or transmitted on systems you control, or only by a PCI DSS compliant provider or a PCI-listed solution.

Then match each channel to an official SAQ. The types, eligibility, and official forms are in PCI DSS Self-Assessment Questionnaires. If a QSA has to review or sign the SAQ, see What is a QSA-validated SAQ?.

How to think about it

  1. How do you take payments? E-commerce, terminals, phone or mail order, invoices, and mobile readers are different channels.
  2. Do you store or process cardholder data? Electronic storage usually means SAQ D for merchants, not a shorter form.
  3. Who controls the payment page or device? A redirect or iframe to a compliant provider can be SAQ A. Merchant-controlled scripts on the payment page are a different questionnaire (SAQ A-EP). A PCI-listed point-to-point encryption or Software-based PIN Entry on COTS solution can open a shorter path, but only if you meet every criterion.

If any channel does not fit a shorter SAQ, use SAQ D for that environment. Service providers who may self-assess use SAQ D for Service Providers only.

If the answer is a ROC rather than an SAQ, no questionnaire applies and you will engage a QSA company for a full assessment; the PCI DSS page covers how to confirm which one you have been assigned.

Published July 30, 2026. Updated September 3, 2026.