Skip to main content

Independent UK card payment reviews

07735 864 445

PCI, SCA & risk10 min read

PCI DSS SAQ Guide: Choose the Right Validation Route

A plain-English guide to PCI DSS v4.0.1 self-assessment questionnaires, scope and the questions to resolve with your acquirer before submitting.

Start with the payment flow

PCI DSS v4.0.1 is the current version of the standard. Before selecting a questionnaire, map where cardholder data can enter, pass through or be stored in your business and by your service providers.

PCI SSC provides SAQs for defined environments. Your acquirer or payment brand is the right place to confirm which validation it expects from you.

Common SAQ routes in plain English

SAQ familyTypical environment to investigate
ACard-not-present functions are fully outsourced and the merchant environment meets every eligibility criterion.
A-EPAn e-commerce site can affect payment security even though it does not electronically store, process or transmit account data.
B or B-IPSpecified imprint or standalone dial-out/IP terminal environments that meet the exact criteria.
C-VTIsolated virtual-terminal use on a computer with the required restrictions.
CPayment applications connected to the internet, with no electronic account-data storage.
P2PEA validated point-to-point encryption solution used within the stated eligibility conditions.
DMerchants not eligible for another SAQ, or environments with broader scope.

Why the label alone is not enough

Each SAQ has eligibility criteria. A hosted payment page, terminal or encryption claim does not by itself prove eligibility. Website scripts, connected systems, storage, telephone processes and service-provider responsibilities can all affect scope.

What to document

  • Every channel used to take a card payment.
  • All devices, webpages and staff processes involved.
  • Whether account data is stored in any format.
  • The payment and hosting providers involved.
  • Who receives the completed validation and when renewal is due.
  • Any vulnerability scanning or penetration-testing requirement communicated to you.

Use current documents

Use the current questionnaire and guidance linked by PCI SSC or your acquirer. Requirements and eligibility wording can change, so an old downloaded checklist should not be treated as the controlling document.

How to identify your PCI DSS SAQ in five minutes

Walk through the smallest number of questions needed to land on the right questionnaire.

  1. 1

    Do you accept cards online?

    If no, skip to step 3. If yes, continue.

  2. 2

    Does your website ever handle raw card data?

    If your customer types the card on a page hosted by your provider (Stripe Checkout, PayPal, redirect), you are SAQ A. If the form is embedded in your own page, you are SAQ A-EP.

  3. 3

    Do you take card-present payments?

    On a standalone terminal with no till integration, SAQ B-IP (IP) or SAQ B (dial-up). Ask your provider whether their solution is on the PCI P2PE list - if so, SAQ P2PE-HW.

  4. 4

    Do you have an integrated till or EPOS handling payments?

    SAQ C if the payment app is on your network but you do not store cardholder data. SAQ D if you store data or the system does not fit any narrower SAQ.

  5. 5

    Confirm merchant level with your acquirer

    Ask for your Visa and Mastercard merchant level in writing so you know whether an ASV scan or QSA audit is also required.

Want to understand what you are actually paying?

Send your latest merchant statement and Card Payment Connect will assess the charges, pricing structure and contract information available.

Get My Statement Reviewed

Official sources

About this guide

Published by Card Payment Connect, an independent card-payment consultancy for UK businesses. Reviewed by Matthew McCarthy, who has worked in UK merchant services for over a decade. Last reviewed 11 September 2026.

Frequently asked questions

Which PCI SAQ do I need?

It depends on the complete payment environment and the SAQ eligibility criteria. Describe your setup to the acquirer or payment provider that receives your validation and get the route confirmed.

Is SAQ A always for e-commerce?

No. It is for eligible fully outsourced card-not-present environments. A merchant website that can affect payment security may fall into a different route, so check the current criteria.

Does using a card machine remove PCI requirements?

Not automatically. A validated solution can reduce scope, but the device, connection, other channels and operating practices still need to match the relevant eligibility conditions.

How often should I revisit the scope?

At least when validation is due and whenever the payment setup changes. Confirm the actual timetable with the organisation receiving your validation.

Related reading

Related providers