Articles & Blogs

How To Choose The Right PCI SAQ For Your Organization?

March 18, 2024 | By Accorian
PCI SAQ

Written By: Eishu Richhariya and Neelabh Ghosh ||

The surge in ransomware attacks, with an average total cost of $5.13 million in 2023 (a 13% increase from 2022), underscores the critical need for organizations to prioritize robust security measures. One crucial defense line is ensuring compliance with the Payment Card Industry Data Security Standard (PCI DSS). However, choosing the right PCI SAQ (Self-Assessment Questionnaire) is vital for achieving PCI compliance.

What is PCI SAQ?

The PCI Self-Assessment Questionnaire (SAQ) is a validation tool designed to help merchants and service providers assess compliance with the Payment Card Industry Data Security Standard (PCI DSS).

Each SAQ has a “Before You Begin” section that describes the cardholder environment to be addressed. Following that, a series of “yes” or “no” questions about various aspects of credit card processing operations and security measures, such as system configuration, network security, and access control.

There are ten PCI SAQs. Choosing the right PCI SAQ among the ten available options (one for service providers and nine for merchants) might be challenging. The selection process considers factors such as credit card transaction volume and cardholder data management.

Let’s understand how to choose the right SAQ for your business.

Note: Another essential part of SAQs is the Attestation of Compliance (AOC), a formal document detailing compliance with PCI DSS rules.

Understanding The Business Model – 4 PCI Levels

1. PCI Level 1

2. PCI Level 2

3. PCI Level 3

4. PCI Level 4

Which Type of SAQ is Right For Your Business?

1. SAQ A

Businesses that only maintain paper records containing account data and outsource card data functions might consider SAQ A. This SAQ allows them to function as mail-order or phone-order businesses without handling electronic account information. It does not apply to face-to-face channels or service providers. It is just for card-not-present transactions.

Eligibility Requirements:

2. SAQ A-EP

Card details aren’t stored electronically for online retailers that do not process account data digitally and entrust part of their payment administration to PCI DSS-compliant 3rd parties. Hence, SAQ A-EP significantly impacts transaction security. It explicitly targets e-commerce channels, excluding service providers.

Eligibility Requirements

3. SAQ B

SAQ B is explicitly designed for retailers operating in traditional stores or handling payments via mail/telephone orders. It’s also tailored for those utilizing imprint machines or standalone dial-out terminals for payment processing. The only exception involves e-commerce channels and service providers. As long as electronically stored account data is not involved, SAQ B ensures PCI DSS compliance.

Eligibility Requirements:

4. SAQ B-IP

Brick-and-mortar stores and mail-order/ phone-order businesses using standalone, PCI-approved point-of-sale terminals (excluding SCRs and SCRPs)can leverage SAQ B-IP for streamlined PCI compliance. This self-assessment questionnaire caters specifically to their needs, focusing on security for internet-connected terminals without cardholder data storage. Unlike broader SAQs, B-IP simplifies the process while ensuring robust security measures.

Eligibility Requirements:

5. SAQ C

SAQ C is designated for merchants who do not retain electronic account data and who operate using point-of-sale (POS) systems or other internet-connected payment application systems. It’s not intended for service providers or e-commerce outlets.

Eligibility Requirements:

6. SAQ C-VT

SAQ C-VT is intended for merchants who process cardholder data through Virtual Payment Terminal systems without the need to read data from a real card.

Eligibility Requirements:

7. SAQ P2PE

SAQ P2PE is a self-assessment questionnaire designed for businesses that utilize PCI-listed P2PE, a specific type of payment security technology. With P2PE, sensitive card data, starting from the entry point (e.g., magnetic stripe read, chip read, or keystroke entry), is encrypted until it reaches the secure environment of the payment processor, where it is decrypted for processing. Merchants adhering to SAQ P2PE standards do not handle unencrypted account data on any computer system; they solely use these trusted P2PE payment terminals.

Eligibility Requirements:

8. SAQ SPoC

SAQ SPoC is designed for merchants who utilize Commercial Off-The-Shelf (COTS) mobile devices and PCI-approved Secure Card Reader-PIN (SCRP) in a validated Software-based PIN Entry on COTS (SPoC) solution for card-present transactions. This SAQ is exclusively intended for merchants accepting face-to-face payments.

Eligibility Requirements:

9. SAQ D for Merchants

If a merchant does not qualify for any other AQ type but requires a self-assessment questionnaire, they should use SAQ D for merchants. This applies to merchants who:

10. SAQ D for Service Providers

Any service provider approved by a payment brand for the self-assessment questionnaire and who stores credit card data must adhere to SAQ D for Service Providers. This implies that service providers processing fewer than 300,000 card transactions have the option to file a Report on Compliance (ROC) or use SAQ D. However, those processing more transactions must report their compliance in detail.

Choose Accorian For Your PCI DSS Compliance

Accorian holds the prestigious distinction of having a team of highly Qualified PCI QSAs (Qualified Security Assessors) specializing in assessing PCI compliance, particularly emphasizing network infrastructure. We are also CREST accredited and an ASV (Approved Scan Vendor). Our PCI accreditations underline our expertise and credibility in cybersecurity and PCI DSS compliance.

Tags: PCI DSS Compliance, payment card industry, PCI compliance, PCI DSS data security standard, PCI security standards, PCI QSA, data security standards

Recent Blog

Ready to Start?

Ready to Start?​


Drop your CVs to joinourteam@accorian.com

Interested Position

Download Case study

Download SOC2 Guide