Skip to contentSkip to content
SAQ Decision Engine

Find Your PCI SAQ Type in 60 Seconds

Answer 4 questions about how you accept and process payments to determine which PCI DSS Self-Assessment Questionnaire applies.

Step 1 of 4

How do you accept payments?

Frequently Asked Questions

What is a PCI DSS SAQ?
A Self-Assessment Questionnaire (SAQ) is a validation tool for merchants and service providers to self-assess PCI DSS compliance. There are 9 SAQ types (A, A-EP, B, B-IP, C, C-VT, D-Merchant, D-SP, P2PE) each covering different payment environments.
How do I determine my SAQ type?
Your SAQ type depends on how you accept payments: fully outsourced (SAQ A), via standalone terminals (SAQ B), through web-based virtual terminals (SAQ C-VT), or through your own systems (SAQ D). Our SAQ Decision Engine determines your type in 4 questions.
What is the difference between SAQ A and SAQ D?
SAQ A has approximately 22 controls and applies to merchants who fully outsource payment processing (no electronic storage of card data). SAQ D has 300+ controls and applies to merchants who store, process, or transmit card data in their own environment.
Can my SAQ type change over time?
Yes. If you change how you accept payments (e.g., moving from an embedded payment page to a fully outsourced redirect), your SAQ type may change. Re-evaluate annually or whenever your payment infrastructure changes.