Payments Glossary · Risk & Compliance

SAQ Types (Self-Assessment Questionnaires)

Also called SAQ A, SAQ B-IP, SAQ C-VT, SAQ D, SAQ P2PE

The short-form PCI validation documents; which one you use depends on how card data touches your systems, and it changes your workload enormously.

What it is

A Self-Assessment Questionnaire is how most small and mid-sized merchants validate PCI DSS compliance each year. You complete the questionnaire that matches your card acceptance method and sign an Attestation of Compliance. The type you qualify for is the single biggest determinant of how much PCI work you actually do, ranging from roughly two dozen questions to several hundred. The practical map for a small business. Card-present only, on a validated point-to-point encryption terminal, no e-commerce: SAQ P2PE, the shortest path, or SAQ B-IP for an IP-connected standalone terminal without validated P2PE. Mail order and telephone order using a hosted virtual terminal on an isolated machine with no storage: SAQ C-VT. E-commerce with a full redirect or fully outsourced payment page: SAQ A. E-commerce with embedded hosted fields or an iframe: still SAQ A, but only if you can satisfy the v4.0.1 eligibility criterion about script attacks. Anything where card numbers touch your own environment or a custom checkout: SAQ D, which is the real one, with quarterly scans by an Approved Scanning Vendor and substantial documentation. Under v4.0.1 there are exactly two ways an embedded-form merchant can satisfy the SAQ A script criterion, per PCI SSC FAQ 1588: implement the 6.4.3 and 11.6.1 techniques yourself, or obtain written confirmation from a PCI DSS compliant payment processor that its embedded solution, implemented as specified, includes protections against script attacks.

Why it matters to your business

Choosing the right questionnaire is the cheapest risk reduction available to a small merchant. Getting moved from SAQ D to SAQ P2PE by swapping to a validated encrypting terminal can remove quarterly scanning, hundreds of questions, and most of your breach exposure in one hardware change. Getting it wrong in the other direction means you signed an attestation that does not describe your business. This is education, not legal advice. The attestation you sign is a contractual representation to your acquirer; if you are unsure whether your answers are accurate, get help before signing.

Where it gets contested

The recurring dispute is merchants being pushed into the wrong questionnaire, in both directions. Some processors' portals default everyone to SAQ A because it is short and generates a fast completion statistic, including merchants who key card numbers into a spreadsheet or store them in a booking system. Others push merchants toward SAQ D and a paid remediation package when a validated P2PE terminal would have collapsed the scope entirely. There is also a genuine architectural fight. Moving a merchant to a redirect checkout is often the cheapest compliant design available, and it is rarely recommended, because it looks slightly worse on the checkout page and because nobody earns a subscription from it. The gray area is self-attestation itself. The merchant signs. If the answers are wrong because the portal guessed at the environment, the merchant carries the consequence, not the portal.

How to check it yourself

Log into your processor's PCI portal and look at which SAQ it has assigned you. Then write down, in one sentence, every place a card number physically exists in your business: terminal, tablet, paper form, booking software, voicemail, email inbox. If that sentence does not match the questionnaire, the questionnaire is wrong.

Receipts

Claims above that are checkable, with where to check them. Published so you do not have to take anyone's word for it.