WithPCI Logo
WithPCI.com

PCI DSS SAQ Wizard

Find the right Self-Assessment Questionnaire for your business based on how you process payments

Step 1: Business Type
1 2 3

Understanding SAQs

Self-Assessment Questionnaires (SAQs) are validation tools for eligible merchants and service providers who self-assess their PCI DSS compliance. Different SAQs exist for various business environments, with varying complexity:

  • SAQ A: Simplest (22 requirements) - For fully outsourced card processing
  • SAQ B/B-IP: For merchants using only standalone terminals
  • SAQ C/C-VT: For merchants with payment systems connected to the internet
  • SAQ A-EP: For e-commerce merchants with partial outsourcing
  • SAQ D: Most complex (329 requirements) - For merchants storing card data or with complex environments

Step 1: Identify Business Type

Service Providers

Select this option

Organizations that process, store, or transmit cardholder data on behalf of other businesses.

Merchants

Select this option

Businesses that accept payment cards directly from customers for goods or services.

Step 2: Estimate PCI Level

Your level determines your validation requirements based on transaction volume.

Please select a business type in Step 1 to see the appropriate level options.

Step 3: Payment Environment & Channel Analysis

Answer these questions about your payment environment and select your payment channels to determine the appropriate SAQ.

Storage of Electronic Payment Account Data

Does merchant store any account data, including legacy data?

PCI-listed P2PE Solution

Does merchant accept transactions protected by a PCI-listed P2PE Solution?

PCI-listed SPoC Solution

Does merchant accept transactions protected by a PCI-listed SPoC Solution?

Card-present Transactions

Physical card transactions using terminals, POS systems, or imprint machines

MOTO Transactions

Mail Order/Telephone Order transactions where cards are not physically present

E-commerce Transactions

Online transactions through websites or mobile apps

Your perspective on this PCI DSS requirement matters! Share your implementation experiences, challenges, or questions below. Your insights help other organizations improve their compliance journey and build a stronger security community.Comment Policy