Find Your Correct PCI SAQ Fast
Answer a few questions to see which PCI DSS SAQ applies to your payment flow, with scope notes you can share.
What this selector does
Maps your payment channel (e‑commerce, in‑person, or virtual terminal), integration, and card‑data handling to the correct Self‑Assessment Questionnaire. The logic follows PCI DSS v4.0.1 eligibility criteria and references official PCI SSC guidance.
Worked example: a merchant using only hosted checkout (all payment page elements from a PCI DSS compliant provider) with no card data on their systems will see SAQ A with a short explanation and scope notes to copy into an internal ticket.
What to confirm
Your acquirer has the final say. If your setup spans multiple channels or stores electronic cardholder data, the safe default is SAQ D.
This tool reflects PCI DSS v4.0.1 and today’s date; it is not legal advice.
Put the number into an operating plan
Frequently asked questions
What is the difference between SAQ A and SAQ A‑EP?
SAQ A applies when all payment page elements originate from a PCI DSS compliant provider (e.g., redirect or iFrame). If your site hosts any payment page element or captures/posts card data, you likely need SAQ A‑EP.
When can I use SAQ P2PE?
When you use only PCI‑listed P2PE hardware terminals with no electronic storage of cardholder data. Your provider must be listed, and you still have operational responsibilities.
We take payments in more than one way. Which SAQ applies?
Multiple channels often require SAQ D, unless each channel is fully isolated and validated separately. Use the selector for each channel, then confirm with your acquirer.