• Easy 3-min Quiz

    to identify which SAQ you need to fill-out

  • There's 8 types of SAQ

    Self-Assessment Questionnaire

    BECOME COMPLIANT
    Submit the appropriate SAQ form to your payment provider along with a passed ASV scan report.
    MAINTAIN COMPLIANCE
    Submit a passed ASV scan to your payment provider every three months and your SAQ once a year.

    SAQ A

    For merchants who outsource all cardholder data processing to PCI DSS-compliant third parties. No electronic storage, processing, or transmission of cardholder data on your systems. Any retained data must be on paper (e.g., receipts).

    E-commerce or mail/telephone order (MOTO) transactions where cards are not present.

    Must fully outsource to validated providers; no electronic data handling allowed. Shortest SAQ.

    SAQ A-EP

    Similar to SAQ A, but for e-commerce where you control the redirection to the third-party processor (e.g., your website handles the initial data entry page). No electronic storage on your systems.

    E-commerce transactions only

    Outsourcing required except for the data ingestion page; no electronic data storage.

    SAQ B

    For merchants using imprint machines or standalone dial-out terminals (connected via phone line to processor). No electronic storage of cardholder data.

    Brick-and-mortar (card-present) or MOTO environments.

    Limited to specific hardware; no internet-connected systems or electronic storage.

    SAQ B-IP

    For merchants using standalone, PIN Transaction Security (PTS)-approved point-of-interaction (POI) devices with IP connection to the processor. No electronic storage.

    Brick-and-mortar or MOTO.

    Devices must be PTS-approved and isolated; no other electronic data handling.

    SAQ C

    For merchants with payment application systems (e.g., POS) connected to the internet, but no electronic storage of cardholder data.

    Brick-and-mortar or MOTO with internet-connected apps.

    Systems must not store data electronically; requires segmentation from other networks.

    SAQ C-VT

    For merchants using third-party virtual terminals on an isolated computing device (e.g., entering single transactions via keyboard). No electronic storage.

    Brick-and-mortar or MOTO with virtual terminals.

    Device must be isolated; hosted by validated provider; manual entry only.

    SAQ P2PE

    For merchants using validated Point-to-Point Encryption (P2PE) solutions (hardware-based) to encrypt data from entry to processor. No electronic storage of unencrypted data.

    Brick-and-mortar or MOTO with P2PE terminals.

    Solution must be PCI-listed and validated; reduces scope significantly.

    SAQ D

    The full questionnaire for merchants or service providers who don't qualify for other SAQs. Covers all PCI DSS requirements; allows electronic storage if compliant.

    Any scenario not covered above, including those with electronic storage or custom setups.

    Catch-all option; separate versions for merchants (SAQ D-Merchant) and service providers (SAQ D-Service Provider). Longest and most comprehensive SAQ.

  • Need help filling out the form?

    We understand the PCI jargon and can make the process painless for you.

    SAQ assistance

    SAQ assistance

    A$510.00
    Let us help you to fill in the SAQ self-questionnaire form, which will take us approximately 3 hours. Once we finish you'll need to check over all the answers and sign that they are true and correct. After signing you simply email it to your payment gateway (or bank) along with a passed AVS scan report if you wish to become compliant. This SAQ form needs to be re-lodged every 12 months.

    MONEY-BACK GUARANTEE
    If our tech team is unable to fully understand your server or deployment scenario (for example some sophisticated corporate instances) we refund the amount paid in full and recommend some more expensive consultants for your case. The absolute top technicians in the PCI field normally charge between $400 to $600 per hour.
    Quantity
    Coming soon