What is Self-Assessment Questionnaire?
Definition
A Self-Assessment Questionnaire (SAQ) is a PCI DSS validation tool for merchants and service providers who are not required to undergo a full on-site QSA assessment. There are multiple SAQ types (A, A-EP, B, B-IP, C, C-VT, D, P2PE) based on how the organization handles cardholder data.
In Depth
SAQs allow smaller merchants to validate PCI DSS compliance without the expense of a full QSA assessment. The correct SAQ type depends entirely on how the merchant processes payment cards. SAQ A is the simplest, for merchants that fully outsource all cardholder data functions to PCI-compliant third parties (like using a hosted payment page). SAQ A-EP applies to e-commerce merchants that outsource payment processing but whose website could affect the security of the transaction. SAQ D is the most comprehensive and applies to any merchant or service provider that does not fit another SAQ category. Selecting the wrong SAQ type is a common compliance mistake — organizations sometimes choose a simpler SAQ than their payment flow warrants, creating a false sense of compliance. To determine the correct SAQ, organizations must accurately document their payment data flow and understand every point where cardholder data could be exposed. Acquiring banks and payment brands may challenge an organization's SAQ selection if a breach occurs and the wrong SAQ was used.
Related Frameworks
Related Terms
PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards mandated by major credit card brands to protect cardholder data. It applies to any organization that stores, processes, or transmits credit card information regardless of size.
Qualified Security Assessor
A Qualified Security Assessor (QSA) is an independent security professional certified by the PCI Security Standards Council to validate an organization's compliance with PCI DSS. QSAs conduct on-site assessments and produce the Report on Compliance (ROC) required for Level 1 merchants.
Cardholder Data Environment
The Cardholder Data Environment (CDE) encompasses all people, processes, and technology that store, process, or transmit cardholder data or sensitive authentication data. Properly scoping the CDE is the critical first step in PCI DSS compliance.
PCI Compliance
PCI compliance refers to an organization's adherence to PCI DSS requirements for protecting cardholder data. Compliance is validated annually through either a QSA assessment (Level 1) or Self-Assessment Questionnaire (Levels 2-4), and quarterly through network vulnerability scans by an Approved Scanning Vendor.
Generate compliance docs with PoliWriter
Stop reading about compliance and start achieving it. PoliWriter generates audit-ready policies customized to your organization in hours.
Get Started Free