PCI DSS SAQ Wizard
Find the right Self-Assessment Questionnaire for your business based on how you process payments
Understanding SAQs
Self-Assessment Questionnaires (SAQs) are validation tools for eligible merchants and service providers who self-assess their PCI DSS compliance. Different SAQs exist for various business environments, with varying complexity:
- SAQ A: Simplest (22 requirements) - For fully outsourced card processing
- SAQ B/B-IP: For merchants using only standalone terminals
- SAQ C/C-VT: For merchants with payment systems connected to the internet
- SAQ A-EP: For e-commerce merchants with partial outsourcing
- SAQ D: Most complex (329 requirements) - For merchants storing card data or with complex environments
Step 1: Identify Business Type
Service Providers
Select this option
Organizations that process, store, or transmit cardholder data on behalf of other businesses.
Merchants
Select this option
Businesses that accept payment cards directly from customers for goods or services.
Step 2: Estimate PCI Level
Your level determines your validation requirements based on transaction volume.
Please select a business type in Step 1 to see the appropriate level options.
Level 4 Merchant
SAQ eligibleLess than 20,000 e-commerce or 1 million total transactions annually
Level 3 Merchant
SAQ eligible20,000 to 1 million e-commerce transactions annually
Level 2 Merchant
SAQ eligible1 million to 6 million total transactions annually
Level 1 Merchant
ROC requiredMore than 6 million transactions annually or had a data breach
Level 2 Service Provider
SAQ D-SP eligibleLess than 300,000 transactions annually
Level 1 Service Provider
ROC requiredMore than 300,000 transactions annually
Step 3: Payment Environment & Channel Analysis
Answer these questions about your payment environment and select your payment channels to determine the appropriate SAQ.
Storage of Electronic Payment Account Data
Does merchant store any account data, including legacy data?
PCI-listed P2PE Solution
Does merchant accept transactions protected by a PCI-listed P2PE Solution?
PCI-listed SPoC Solution
Does merchant accept transactions protected by a PCI-listed SPoC Solution?
Card-present Transactions
Physical card transactions using terminals, POS systems, or imprint machines
MOTO Transactions
Mail Order/Telephone Order transactions where cards are not physically present
E-commerce Transactions
Online transactions through websites or mobile apps
Your perspective on this PCI DSS requirement matters! Share your implementation experiences, challenges, or questions below. Your insights help other organizations improve their compliance journey and build a stronger security community.Comment Policy