PCI DSS SAQ Selector — Identify the Right SAQ for Your Business
Not sure which PCI DSS Self‑Assessment Questionnaire (SAQ) applies to your business? Choosing the wrong SAQ can lead to gaps in compliance, audit failure, or unnecessary cost and effort.
Our PCI DSS SAQ Selector guides you through a few simple questions to help determine the correct SAQ based on how your organisation stores, processes, or transmits cardholder data. This tool reduces confusion, eliminates guesswork, and puts you on the right compliance path — quickly and confidently.
The right SAQ shapes your compliance cost & risk.
Several factors determine which SAQ applies to your business, and selecting the wrong one has measurable consequences.
Factors that determine your SAQ
- How payment cards are accepted (online, in‑store, phone, mail order)
- Whether cardholder data is stored or transmitted
- Use of third‑party payment processors
- Level of technical integration with payment systems
Risks of selecting an incorrect SAQ
- Non‑compliance findings during audits
- Unnecessary controls and testing
- Increased assessment cost and effort
- Contractual or regulatory exposure
From your first answer to a tailored result in under 60 seconds.
The selector mirrors the questions a QSA would ask in the first 5 minutes of a scoping call.
Tell us how you accept payments
Online, in‑person, phone/mail order, or a mix. We branch the logic based on your channel.
Confirm merchant or service provider
Service providers and merchants follow different SAQ tracks. We identify yours upfront.
Pick your SAQ type or ROC
Based on terminals, storage, and outsourcing, we narrow you to one of 9 SAQ types or a full Report on Compliance.
Get next-step guidance
You’ll see what controls apply, common pitfalls, and readiness next steps before you talk to a QSA.
SAQ Selector
Answers stay on your device. We don’t store anything — no cookies, no tracking, no signup.
Self Assessment Questionnaire (SAQ) Guidance
Not sure which SAQ applies to your business? Contact our PCI DSS experts for a free consultation.
What is an SAQ type? An SAQ type refers to the specific version of the Self-Assessment Questionnaire that a merchant or service provider must complete to validate their PCI DSS compliance. Each SAQ type is designed for a different business scenario, based on: how you accept payments (e-commerce, card-present, mail/telephone order), whether you store, process, or transmit cardholder data, and your technology setup (standalone terminals, virtual terminals, P2PE solutions). For example: SAQ A → for merchants that fully outsource all cardholder data handling. SAQ D → for merchants or service providers with complex environments or that store cardholder data.
Fully Outsourced E-Commerce / MOTO
- You are an e-commerce or mail/telephone order merchant
- All cardholder data functions are fully outsourced to PCI DSS–validated third parties
- Your systems do not store, process, or transmit cardholder data
E-Commerce with Payment Page Impact
- You are an e-commerce merchant
- You outsource payment processing, but your website can impact the security of the payment page (e.g., hosting scripts)
Imprint / Standalone Dial-Out
- You use only imprint machines or standalone dial-out terminals (no IP connectivity)
- You do not store cardholder data electronically
Standalone PTS Terminals (IP)
- You use only standalone PTS-approved payment terminals with an IP connection
- You do not store cardholder data electronically
Internet-Connected Payment App
- You have a payment application system connected to the internet
- You do not store cardholder data electronically
Web-Based Virtual Terminal
- You use a web-based virtual terminal on a dedicated device
- You do not store cardholder data electronically
Point-to-Point Encryption
- You use only a PCI-listed Point-to-Point Encryption (P2PE) solution for all card-present transactions
Complex Merchant Environments
- You do not qualify for any other SAQ type
- You store cardholder data electronically or have a complex environment
Eligible Service Providers
- You are a service provider eligible to complete an SAQ
- You store, process, or transmit cardholder data on behalf of clients
What criteria to consider? Taking the time to identify the right SAQ can alleviate a lot of hassle down the line. Make your decision with care and be proactive in your approach to compliance.
How often do I review my SAQ — and when must it change?
How often do I review my SAQ?
SAQ validation is annual at minimum — and triggered by significant changes.
What happens if I change my business?
Specific business changes can re-scope your PCI environment and SAQ type.
Clear Guidance. Confident PCI DSS Compliance.
From readiness to assessment, Cianaa provides expert guidance that removes uncertainty, reduces risk, and helps you achieve PCI DSS compliance with confidence.
