The Self-Assessment Questionnaire (SAQ) is the primary compliance validation tool for PCI DSS Level 2, 3, and 4 merchants. Choosing the correct SAQ type is critical because it determines which PCI DSS requirements you must validate against. Completing the wrong SAQ or incorrectly assessing your eligibility can result in non-compliant status even if your security controls are adequate. This guide explains each SAQ type, helps you determine which one applies to your organization, and provides practical guidance for completing the questionnaire accurately.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
Monthly billing · cancel anytime · 30-day money-back guarantee
Your SAQ type depends on how you process, store, and transmit cardholder data. SAQ A for fully outsourced with no data on your systems. SAQ A-EP for e-commerce with website impact on payment security. SAQ B/B-IP/C/C-VT for various terminal configurations. SAQ D for complex environments. Confirm with your acquiring bank.
SAQ A is for merchants that fully redirect customers to a third-party hosted payment page with no cardholder data touching merchant systems. SAQ A-EP is for e-commerce merchants that outsource processing but whose website elements (like embedded iframes) could impact payment security.
Question counts vary: SAQ A has approximately 22, SAQ A-EP around 140, SAQ B about 41, SAQ B-IP about 82, SAQ C about 160, SAQ C-VT about 79, SAQ D over 300, and SAQ P2PE about 33. The counts may vary slightly by PCI DSS version.
Yes. If you cannot meet a specific requirement exactly as stated, you may implement a compensating control that meets the intent and rigor of the original requirement. Each compensating control must be documented on a Compensating Controls Worksheet explaining why the original cannot be met and how the alternative provides equivalent protection.
An authorized executive officer of the company must sign the Attestation of Compliance, confirming the accuracy and completeness of the self-assessment. This is typically a C-level executive or authorized representative who can attest on behalf of the organization.
SAQs must be completed annually and submitted to your acquiring bank. However, PCI DSS compliance is a continuous obligation. Organizations should maintain compliance throughout the year and be prepared to demonstrate compliance at any time, not just during the annual assessment.
Completing the wrong SAQ can result in a finding of non-compliance because you may not have validated all requirements applicable to your processing environment. Your acquiring bank may reject the submission and require you to complete the correct SAQ type. Always confirm your SAQ type with your acquirer before starting.
PoliWriter generates all the policies, mappings, and audit-ready artifacts referenced in this guide — customized to your AWS / GitHub / Okta stack. 60+ integrations, continuous monitoring, evidence collection — at a fraction of Vanta's price.
PoliWriter creates all the policies you need for PCI DSS compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free