Fundamentals

SAQ Types A Through D, Explained

Eight questionnaires, one choice that shapes your whole PCI workload. Which SAQ type fits your payment setup — and what each one demands.

Why the SAQ type matters

Your SAQ type determines how many PCI DSS requirements you attest to — from a couple dozen (SAQ A) to the full set of 300+ (SAQ D). Picking correctly keeps the workload honest; picking wrong means either attesting to requirements that don't apply or, worse, skipping ones that do.

The eight types

SAQFits whenWorkload
ACard data never touches your systems — fully outsourced e-commerce (hosted payment page, iframe, or JS-based tokenization)Lightest
A-EPE-commerce, but your website affects payment-page security (e.g., you control the page hosting the iframe)Light–moderate
BImprint machines or standalone dial-out terminals only, no electronic cardholder data storageLight
B-IPStandalone PTS-approved point-to-point terminals connected via IP, no electronic storageLight
C-VTWeb-based virtual terminals only — manual key entry into an isolated device/browser, no electronic storageLight–moderate
CPayment application systems connected to the internet (e.g., POS systems), no electronic storageModerate
P2PEValidated point-to-point encryption solution only, no electronic storageLight
DEveryone else — any merchant not fitting the narrower SAQsFull requirements

Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.

Request quotes

How to pick

Map how card data actually flows through your environment — not how the architecture diagram says it flows. The SAQ eligibility criteria are precise: one exception (a stored PAN in a log file, a terminal that isn't on the validated list) can push you from SAQ A to SAQ D. When in doubt, a QSA's scoping opinion is cheaper than a wrong attestation.

When you outgrow your SAQ

Growth changes the answer: crossing into Level 1 (6M+ transactions/year for most brands) moves you from SAQ to ROC. Plan the transition a year ahead — your first ROC cycle takes 4–9 months end to end.

Keep reading

ROC vs SAQ: Which PCI Validation Path Are You On?

The two roads through PCI DSS certification — what happens on each, who decides, and the expensive mistake of picking the wrong one.

What QSAs Actually Test: Inside ROC Fieldwork

Phase 4 demystified — the testing procedures, the evidence requests, and how to walk into fieldwork with everything ready.

What Happens If You Fail a PCI Assessment

Nobody passes on the first try. How findings, remediation, and re-testing actually work — and why “not yet compliant” isn't the disaster it sounds like.

Questions

We're on Shopify — which SAQ?

Typically SAQ A, since card data never touches your systems. Confirm with your acquirer; custom checkout code can change the answer.

Does SAQ D mean we failed?

No — SAQ D is simply the questionnaire for merchants whose setup doesn't fit the narrower SAQs. It's the most work, not a penalty.

Turn reading into quotes

Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.

Get a free quote