PCI DSS Self-Assessment Questionnaire Guide: Pick the Right SAQ
PCI DSS Self-Assessment Questionnaire Guide: Pick the Right SAQ
Most SMBs overcomply with PCI DSS because they pick the wrong questionnaire. They file SAQ D — the full thing — when their actual card handling qualifies them for SAQ A or SAQ P2PE, a fraction of the questions. The SAQ is determined by how you handle card data, not by how big you are.
A Self-Assessment Questionnaire (SAQ) is the reporting tool a merchant or service provider completes to document its PCI DSS compliance instead of commissioning a full Report on Compliance with a QSA. PCI SSC publishes several SAQs, each scoped to a specific way of handling card data. The rule is simple in principle: use the SAQ that matches your actual card-handling channel, and if more than one channel applies, use the SAQ that covers all of them (usually SAQ D). The execution is where SMBs slip — picking D by default, or not realizing a scope change moved them to a narrower SAQ.
This guide walks the SAQs an SMB is likely to qualify for, how to choose, and how the scope reduction work changes the answer. The SAQ titles and eligibility below reflect the public PCI SSC SAQ structure; confirm your selection against the current SAQ Instructions and Guidelines document on the PCI SSC site before filing.
The SAQs, from narrowest to broadest
SAQ A — card-not-present, and the payment page is entirely outsourced. You redirect or iframe to a processor-hosted payment page, and your systems never store, process, or transmit cardholder data. The shortest SAQ. If you run an e-commerce store and the customer types card details into a processor’s form, this is likely yours.
SAQ A-EP — card-not-present e-commerce, and you do some payment-page processing yourself (a redirect, or elements on your own page) but you do not store cardholder data. More questions than A because your systems touch the payment flow.
SAQ B — card-present or mail/telephone order, with no electronic storage of cardholder data (imprint machines or standalone dial-out terminals that do not store CHD).
SAQ B-IP — card-present with IP-connected payment terminals that do not store cardholder data.
SAQ C — you operate a payment application connected to the internet (a virtual terminal through a web browser, for example), and do not store CHD on your systems.
SAQ P2PE — you use a PCI-validated point-to-point encryption solution for card-present payments, and you do not store CHD. The validated P2PE scope cut shows up here as a short questionnaire.
SAQ D — the catch-all. Any merchant that does not meet the criteria for a narrower SAQ, including those that store cardholder data, and all service providers. The full PCI DSS requirement set. If you store PANs, you are here.
SAQ P2PE-HW / C-VT and other narrow variants exist for specific setups; the principle is the same — match the channel, take the narrowest fit.
How to choose
Walk three questions in order:
1. Do you store cardholder data (PAN) or sensitive authentication data? If yes → SAQ D (or stop storing it and re-ask). Storage is the single factor most likely to land you in the full questionnaire. 2. What channel do you use? Card-not-present e-commerce, card-present terminal, virtual terminal, or a mix. 3. Is the channel outsourced or validated? Processor-hosted payment page → A. P2PE-validated solution → P2PE. Your own payment-page processing → A-EP. IP terminal with no storage → B-IP.
If you have more than one channel — say, an e-commerce store (A) and a card-present terminal (P2PE) — you cannot file two narrow SAQs. You file the one that covers both, which is usually D, unless the channels share a single validated outsourcing model. This is why simplifying to one channel is itself a compliance lever: an SMB that drops its in-store terminal and moves everything to a processor-hosted web payment can move from D to A.
The scope-reduction interaction
Every scope-reduction control can change your SAQ:
- Stop storing PANs (tokenize) → out of D into a channel-based SAQ.
- Move the payment page to the processor (hosted/iframe) → A or A-EP instead of D.
- Adopt a P2PE-validated solution → P2PE instead of B-IP or D.
- Drop a second channel → no longer forced into D by the "covers all channels" rule.
The SAQ you file is downstream of the architecture. An SMB that invests a month in scope reduction often drops an entire SAQ tier, which is a larger saving than any single control.
The [6.4.3 / 11.6.1] factor for e-commerce
If you file SAQ A or A-EP, you run a payment page, which brings in requirements 6.4.3 and 11.6.1 — script management and tamper detection. The exception: a pure SAQ A where the payment page is entirely the processor’s iframe pushes those requirements to the processor. The cleaner the outsourcing, the shorter both the SAQ and the 6.4.3/11.6.1 work.
Filing and the Attestation of Compliance
The SAQ is completed, signed by an authorized officer (the Attestation of Compliance), and submitted to your acquirer or payment brand as they direct. Self-assessment does not mean self-certification of the result — the controls must actually be in place, and the SAQ is a declaration under the card brand programs. Misrepresenting the environment on an SAQ is a compliance failure with contractual consequences, not a paperwork error.
For some merchants — large transaction volumes, certain channel combinations, or after a breach — a QSA-led Report on Compliance replaces the SAQ. Your acquirer tells you if you are in that band.
How this fits the series
This is the use-case companion to the PCI DSS pillar. It assumes you have read the scope reduction piece, because the SAQ you file is a function of the scope you ended up with. The TRA template is referenced by several SAQ requirements where a frequency is defined by targeted risk analysis.
What to do next
Identify your single card-handling channel (or decide to consolidate to one). Match it to the narrowest SAQ above. If you land on D, ask which stored data or second channel is keeping you there — that is the lever to pull. Confirm your selection against the current PCI SSC SAQ Instructions and Guidelines, then complete the questionnaire against the controls you actually run. Filing the right SAQ is an hour; getting into the position to file the narrow one is the work.
Unsure which SAQ fits your setup? Book a 30-min **PCI scope reduction + readiness review** — we map your card-handling channels, tell you which SAQ applies, and flag the scope change that drops you a tier. Bilingual EN/FR, no obligation.
Get Your Free Security Readiness Assessment
Map your controls, identify compliance gaps, and secure your systems before the audit.