Skip to content

Which PCI DSS SAQ type fits my shop?

The likely PCI DSS questionnaire for a small online shop follows the payment-page design: a genuine processor-hosted redirect or iframe points toward SAQ A, code that can influence an embedded payment page points toward SAQ A-EP, and storing card numbers puts the work on SAQ D; the acquirer makes the final determination.

Start with where cards are entered

Ask whether every card field lives on a validated processor's page and whether anything on your own site can rewrite, intercept, or otherwise influence the redirect or iframe. If the handoff is genuinely hosted and your page cannot affect it, the guide describes SAQ A as the shortest path. Keep the processor's Attestation of Compliance and a current administrator list, complete your own SAQ, and ask the acquirer whether an ASV scan applies. Pure redirects are often exempt from ASV scanning, but not always.

Recognize SAQ A-EP signals

Your page enters SAQ A-EP territory when code you control participates in the payment page. Examples include a JavaScript SDK, custom fields, a styling script, or an embedded widget assembled by your checkout. The card number may still never reach your server, but the page is part of the payment flow. The guide calls for a script inventory, change and tamper detection under requirements 6.4.3 and 11.6.1, strict documented patching for the CMS, plugins, and theme, segmentation, and quarterly ASV scans. The questionnaire is roughly 139 questions, so scope should be confirmed early.

Know when SAQ D applies

Storing card numbers anywhere—such as a CRM, spreadsheet, support ticket, or call recording—overrides the simpler hosted model in the guide and puts the merchant on SAQ D. That path covers all 12 PCI DSS requirements, including encryption at rest and documented key management, quarterly ASV scans, an annual penetration test, segmentation testing, and a sustained control program. The guide suggests considering whether storage can end and a validated processor can take over, but that is a decision to confirm with the acquirer.

Do not confuse guidance with eligibility

Revenue, a shopping-cart platform, and the hosting company do not decide the SAQ by themselves. A website used only for in-person, phone, or postal payments may not have a website SAQ at all; the terminal or phone-payment provider handles its own scope. Use the small-business checklist for evidence and the decision guide for the questions, then obtain the final ruling from the acquirer. If you need a plan overview, see pci.hosting plans; a ticket is guidance, not a formal QSA opinion.


Was this article helpful?

mood_bad Dislike 0
mood Like 0
visibility Views: 23