PCI DSS SAQ finder

Which PCI SAQ do you need? Find out before you sign.

Answer a few questions about how you take cards and where card data ends up. See your likely Self-Assessment Questionnaire for each channel, your merchant level, what that SAQ requires, and the items most often missed. Built for PCI DSS v4.0.1 and the 2025 SAQ A change.

SAQ finderSAMPLE
A-EP
Likely SAQ
SAQ A-EP
Online checkoutA-EP
In person, P2PE terminalsP2PE
Script criterionNot confirmed
Stored card dataNone
PCI DSS v4.0.1 · 10 SAQ types

We use this to send your summary. No newsletter sign-up. Privacy policy

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
How SAQs work

The right SAQ is the shortest one you actually qualify for

10
questionnaire types under PCI DSS v4.0.1, from SAQ A to SAQ D for Service Providers
2025
SAQ A revised on January 30: two script requirements out, a whole-site script criterion in
6M
card transactions a year, above which a Report on Compliance by a QSA replaces the SAQ
SAQ D
where you land if card data is stored electronically anywhere, including email and call recordings

A Self-Assessment Questionnaire lists only the PCI DSS requirements that apply to one way of taking cards. Qualify for a short one and you answer a fraction of the standard. File one you do not qualify for, and your Attestation of Compliance does not hold up when your acquirer or an investigator looks.

Two things decide the SAQ: how card data reaches your payment provider in each channel, and whether it lands anywhere on your systems. A hosted payment page keeps your site out of scope. A form your own page builds puts it back in. Card numbers in an inbox or a call recording rule out every short SAQ.

How the finder works: answer for each channel you use. The result shows the likely SAQ for each channel, the most demanding one overall, your merchant level by Visa's thresholds, the testing it requires and the items most often missed. Answering Not sure makes the result provisional and tells you what to check.

Your answers stay in your browser. If you ask for the summary, it arrives as a short Word document you can take to your acquirer or QSA. This is a guide to the likely SAQ, not an assessment.

FAQ

PCI SAQ questions, answered

A Self-Assessment Questionnaire is how a merchant or service provider that is allowed to self-assess validates PCI DSS compliance. Each SAQ type covers only the requirements that apply to one way of taking cards. You answer it, sign the Attestation of Compliance that goes with it, and submit both to your acquirer, the bank that set up your merchant account.

It depends on how card data reaches your payment provider and whether it lands on your systems. Online checkout fully outsourced through a redirect or a provider-served frame: SAQ A. Your page builds the payment form: SAQ A-EP. Standalone terminals: SAQ B or B-IP. Terminals from a PCI-listed P2PE solution: SAQ P2PE. A provider's virtual terminal on an isolated computer: SAQ C-VT. A segmented point-of-sale system: SAQ C. Card data stored electronically, or no shorter SAQ fits: SAQ D. Service providers use SAQ D for Service Providers.

On January 30, 2025, the PCI Security Standards Council revised SAQ A. It removed requirements 6.4.3 and 11.6.1, the payment page script controls (and the risk analysis tied to 11.6.1), and added an eligibility criterion: the merchant confirms its site is not susceptible to attacks from scripts that could affect its e-commerce systems. That criterion covers the whole site, not only checkout. Quarterly external scans by an Approved Scanning Vendor stayed in.

Your acquirer, or the payment brand, makes the final call. With more than one payment channel, your acquirer also decides whether you file one SAQ per channel or one that covers all of them. Use this finder to go into that conversation with an answer and the reasons for it.

Most merchants below 6 million card transactions a year self-assess with an SAQ. Above that, Level 1 merchants validate with a Report on Compliance by a Qualified Security Assessor. Mastercard adds rules for some Level 2 merchants, such as using a QSA or a certified Internal Security Assessor for certain SAQ types. You do not need a QSA to complete an SAQ, but having the scope checked before you sign is cheaper than finding out later that you filed the wrong one.

Your answers stay in your browser unless you ask for the summary. If you do, we keep your answers with your request so we can send it, and we never share them.

Ground truth. Not story.

Acquirers and assessors ask for evidence, not policies. We scope PCI environments, test the controls in your actual systems and show what holds up.

Since May 1, 2026, our forensic audits have prevented $2.2M in wire fraud, none of it flagged first by the client's IT team, managed service provider, bank or security tools.