Which PCI SAQ applies to you?
Which Self-Assessment Questionnaire you complete depends on one thing: how card data moves through your business. Fully outsourced merchants can qualify for SAQ A's 30 requirements, while a business whose agents hear card numbers over the phone usually faces SAQ D's 252. Answer the questions below and you'll have your likely SAQ in under a minute.
Question 1 of 8
Do you take any card payments at all?
Runs entirely in your browser — we don't collect or store your answers.
What are the nine SAQ types?
Every SAQ uses the official PCI DSS v4.0.1 requirements, unchanged. What differs is how many of them apply to your setup:
| SAQ | Requirements | Who it's for |
|---|---|---|
| SAQ A | 30 | Card-not-present, fully outsourced card handling |
| SAQ A-EP | 145 | E-commerce that controls the payment page but never touches card data |
| SAQ B | 28 | Imprint machines or standalone dial-out terminals |
| SAQ B-IP | 51 | Standalone terminals on your IP network |
| SAQ C | 128 | Internet-connected payment application, no data storage |
| SAQ C-VT | 55 | Virtual terminal on one dedicated, isolated computer |
| SAQ P2PE | 22 | PCI-listed point-to-point encryption solution |
| SAQ D (Merchants) | 252 | Everyone who doesn't qualify for a lighter SAQ |
| SAQ D (Service Providers) | 255 | Service providers completing a self-assessment |
Once you know your SAQ, the free Paytia Comply app walks you through every requirement with plain-English explanations and photo evidence capture, and our Compliance 101 series covers the background. If the answer was SAQ D and phone payments put you there, DTMF masking is how merchants get back to SAQ A.
Common questions
Which PCI SAQ applies to my business?+
It depends on how card data moves through your business. Fully outsourced card-not-present merchants are candidates for SAQ A (30 requirements); standalone terminal merchants for SAQ B or B-IP; virtual-terminal and payment-application setups for SAQ C-VT or C; PCI-listed encryption users for SAQ P2PE; and everyone else lands on SAQ D for Merchants, the 252-requirement catch-all. The checker on this page walks the same decision tree an assessor would.
How many PCI SAQ types are there?+
Nine: SAQ A, A-EP, B, B-IP, C, C-VT, P2PE, D for Merchants and D for Service Providers. They range from 22 requirements (P2PE) to 255 (D for Service Providers). Which one you complete depends on how you accept and handle card payments.
Does this checker collect my answers?+
No. It runs entirely in your browser — there's no form, no email gate and nothing is sent to us or anyone else. It's the same decision guide we publish in our free Chrome extension and open-source workbook.
Is the result official?+
It's a well-informed starting point, not a ruling. Your acquirer — the bank that processes your card payments — always has the final say on which SAQ you complete. If your setup is unusual, ask them or a QSA before you start filling anything in.
Why do phone payments usually mean SAQ D?+
When an agent hears or types card numbers, the phone system, call recordings, agent workstations and often the whole office network fall into PCI scope — which is SAQ D territory at 252 requirements. Descoping technology such as DTMF masking keeps card data out of all of those, which is how phone-payment merchants get back to SAQ A's 30 requirements.