Which PCI SAQ do you need? Find out before you sign.
Answer a few questions about how you take cards and where card data ends up. See your likely Self-Assessment Questionnaire for each channel, your merchant level, what that SAQ requires, and the items most often missed. Built for PCI DSS v4.0.1 and the 2025 SAQ A change.
The right SAQ is the shortest one you actually qualify for
A Self-Assessment Questionnaire lists only the PCI DSS requirements that apply to one way of taking cards. Qualify for a short one and you answer a fraction of the standard. File one you do not qualify for, and your Attestation of Compliance does not hold up when your acquirer or an investigator looks.
Two things decide the SAQ: how card data reaches your payment provider in each channel, and whether it lands anywhere on your systems. A hosted payment page keeps your site out of scope. A form your own page builds puts it back in. Card numbers in an inbox or a call recording rule out every short SAQ.
How the finder works: answer for each channel you use. The result shows the likely SAQ for each channel, the most demanding one overall, your merchant level by Visa's thresholds, the testing it requires and the items most often missed. Answering Not sure makes the result provisional and tells you what to check.
Your answers stay in your browser. If you ask for the summary, it arrives as a short Word document you can take to your acquirer or QSA. This is a guide to the likely SAQ, not an assessment.
PCI SAQ questions, answered
Acquirers and assessors ask for evidence, not policies. We scope PCI environments, test the controls in your actual systems and show what holds up.
Since May 1, 2026, our forensic audits have prevented $2.2M in wire fraud, none of it flagged first by the client's IT team, managed service provider, bank or security tools.
.png)