Smart PCI DSS SAQ

PCI DSS SAQ Selector — Identify the Right SAQ for Your Business

Not sure which PCI DSS Self‑Assessment Questionnaire (SAQ) applies to your business? Choosing the wrong SAQ can lead to gaps in compliance, audit failure, or unnecessary cost and effort.

Our PCI DSS SAQ Selector guides you through a few simple questions to help determine the correct SAQ based on how your organisation stores, processes, or transmits cardholder data. This tool reduces confusion, eliminates guesswork, and puts you on the right compliance path — quickly and confidently.

Under 60 seconds
Aligned to PCI DSS v4.0
Free, no email required
QSA-validated logic
Standard PCI DSS v4.0
9 SAQ Types
Find yours in under 60 seconds
A
E-commerce Outsourced
B
Standalone Terminals
C
Connected Systems
D
Full Scope
Aligned to PCI SSC v4.0 SAQ guidance
Instant result
No iframe, no API calls
Why SAQ choice matters

The right SAQ shapes your compliance cost & risk.

Several factors determine which SAQ applies to your business, and selecting the wrong one has measurable consequences.

Factors that determine your SAQ

  • How payment cards are accepted (online, in‑store, phone, mail order)
  • Whether cardholder data is stored or transmitted
  • Use of third‑party payment processors
  • Level of technical integration with payment systems

Risks of selecting an incorrect SAQ

  • Non‑compliance findings during audits
  • Unnecessary controls and testing
  • Increased assessment cost and effort
  • Contractual or regulatory exposure
How it works

From your first answer to a tailored result in under 60 seconds.

The selector mirrors the questions a QSA would ask in the first 5 minutes of a scoping call.

1

Tell us how you accept payments

Online, in‑person, phone/mail order, or a mix. We branch the logic based on your channel.

2

Confirm merchant or service provider

Service providers and merchants follow different SAQ tracks. We identify yours upfront.

3

Pick your SAQ type or ROC

Based on terminals, storage, and outsourcing, we narrow you to one of 9 SAQ types or a full Report on Compliance.

4

Get next-step guidance

You’ll see what controls apply, common pitfalls, and readiness next steps before you talk to a QSA.

Start here

SAQ Selector

Answers stay on your device. We don’t store anything — no cookies, no tracking, no signup.

Your answers will appear here as you progress →
Choose the Right Self-Assessment Questionnaire

Self Assessment Questionnaire (SAQ) Guidance

Not sure which SAQ applies to your business? Contact our PCI DSS experts for a free consultation.

What is an SAQ type? An SAQ type refers to the specific version of the Self-Assessment Questionnaire that a merchant or service provider must complete to validate their PCI DSS compliance. Each SAQ type is designed for a different business scenario, based on: how you accept payments (e-commerce, card-present, mail/telephone order), whether you store, process, or transmit cardholder data, and your technology setup (standalone terminals, virtual terminals, P2PE solutions). For example: SAQ A → for merchants that fully outsource all cardholder data handling. SAQ D → for merchants or service providers with complex environments or that store cardholder data.

SAQ A

Fully Outsourced E-Commerce / MOTO

  • You are an e-commerce or mail/telephone order merchant
  • All cardholder data functions are fully outsourced to PCI DSS–validated third parties
  • Your systems do not store, process, or transmit cardholder data
SAQ A-EP

E-Commerce with Payment Page Impact

  • You are an e-commerce merchant
  • You outsource payment processing, but your website can impact the security of the payment page (e.g., hosting scripts)
SAQ B

Imprint / Standalone Dial-Out

  • You use only imprint machines or standalone dial-out terminals (no IP connectivity)
  • You do not store cardholder data electronically
SAQ B-IP

Standalone PTS Terminals (IP)

  • You use only standalone PTS-approved payment terminals with an IP connection
  • You do not store cardholder data electronically
SAQ C

Internet-Connected Payment App

  • You have a payment application system connected to the internet
  • You do not store cardholder data electronically
SAQ C-VT

Web-Based Virtual Terminal

  • You use a web-based virtual terminal on a dedicated device
  • You do not store cardholder data electronically
SAQ P2PE

Point-to-Point Encryption

  • You use only a PCI-listed Point-to-Point Encryption (P2PE) solution for all card-present transactions
SAQ D (Merchants)

Complex Merchant Environments

  • You do not qualify for any other SAQ type
  • You store cardholder data electronically or have a complex environment
SAQ D (Service Providers)

Eligible Service Providers

  • You are a service provider eligible to complete an SAQ
  • You store, process, or transmit cardholder data on behalf of clients

What criteria to consider? Taking the time to identify the right SAQ can alleviate a lot of hassle down the line. Make your decision with care and be proactive in your approach to compliance.

SAQ lifecycle

How often do I review my SAQ — and when must it change?

How often do I review my SAQ?

SAQ validation is annual at minimum — and triggered by significant changes.

AnnuallyEvery merchant or service provider using an SAQ must complete it at least once per year as part of their PCI DSS validation process.
After Significant ChangesMajor changes to your payment environment: adding payment channels, switching processors, new technologies handling CHD.
When PCI DSS Requirements ChangeE.g., transition from PCI DSS 3.2.1 to 4.0 introduced client-side controls, MFA for all CDE access, and updated retention policies.
Before Compliance DeadlinesFuture-dated requirements (e.g., those effective after March 31, 2025) must be implemented and reflected in your SAQ by the deadline.
When Eligibility ChangesIf your business model changes (e.g., from fully outsourced to hosting scripts), you may need to move from SAQ A to SAQ A-EP or another type.

What happens if I change my business?

Specific business changes can re-scope your PCI environment and SAQ type.

New Payment ChannelsIf you add e-commerce, mobile payments, or card-present terminals, your SAQ type may change (e.g., from SAQ A to SAQ A-EP or SAQ C).
Switching Service ProvidersIf you move to a new payment processor or gateway, you must review your SAQ to ensure the new setup still meets eligibility criteria.
Storing Cardholder DataIf you start storing cardholder data electronically, you will default to SAQ D (Merchant), the most comprehensive questionnaire.
Outsourcing or InsourcingIf you previously outsourced all payment processing (SAQ A) but now host scripts or handle transactions internally, you may need SAQ A-EP or SAQ C.
Technology ChangesImplementing new POS systems, cloud environments, or custom payment pages can expand your PCI DSS scope and require a different SAQ.
Ready when you are

Clear Guidance. Confident PCI DSS Compliance.

From readiness to assessment, Cianaa provides expert guidance that removes uncertainty, reduces risk, and helps you achieve PCI DSS compliance with confidence.

No obligation · ANZ-based team · Response within 1 business day