Start with the payment flow
PCI DSS v4.0.1 is the current version of the standard. Before selecting a questionnaire, map where cardholder data can enter, pass through or be stored in your business and by your service providers.
PCI SSC provides SAQs for defined environments. Your acquirer or payment brand is the right place to confirm which validation it expects from you.
Common SAQ routes in plain English
| SAQ family | Typical environment to investigate |
|---|---|
| A | Card-not-present functions are fully outsourced and the merchant environment meets every eligibility criterion. |
| A-EP | An e-commerce site can affect payment security even though it does not electronically store, process or transmit account data. |
| B or B-IP | Specified imprint or standalone dial-out/IP terminal environments that meet the exact criteria. |
| C-VT | Isolated virtual-terminal use on a computer with the required restrictions. |
| C | Payment applications connected to the internet, with no electronic account-data storage. |
| P2PE | A validated point-to-point encryption solution used within the stated eligibility conditions. |
| D | Merchants not eligible for another SAQ, or environments with broader scope. |
Why the label alone is not enough
Each SAQ has eligibility criteria. A hosted payment page, terminal or encryption claim does not by itself prove eligibility. Website scripts, connected systems, storage, telephone processes and service-provider responsibilities can all affect scope.
What to document
- Every channel used to take a card payment.
- All devices, webpages and staff processes involved.
- Whether account data is stored in any format.
- The payment and hosting providers involved.
- Who receives the completed validation and when renewal is due.
- Any vulnerability scanning or penetration-testing requirement communicated to you.
Use current documents
Use the current questionnaire and guidance linked by PCI SSC or your acquirer. Requirements and eligibility wording can change, so an old downloaded checklist should not be treated as the controlling document.
How to identify your PCI DSS SAQ in five minutes
Walk through the smallest number of questions needed to land on the right questionnaire.
- 1
Do you accept cards online?
If no, skip to step 3. If yes, continue.
- 2
Does your website ever handle raw card data?
If your customer types the card on a page hosted by your provider (Stripe Checkout, PayPal, redirect), you are SAQ A. If the form is embedded in your own page, you are SAQ A-EP.
- 3
Do you take card-present payments?
On a standalone terminal with no till integration, SAQ B-IP (IP) or SAQ B (dial-up). Ask your provider whether their solution is on the PCI P2PE list - if so, SAQ P2PE-HW.
- 4
Do you have an integrated till or EPOS handling payments?
SAQ C if the payment app is on your network but you do not store cardholder data. SAQ D if you store data or the system does not fit any narrower SAQ.
- 5
Confirm merchant level with your acquirer
Ask for your Visa and Mastercard merchant level in writing so you know whether an ASV scan or QSA audit is also required.
Want to understand what you are actually paying?
Send your latest merchant statement and Card Payment Connect will assess the charges, pricing structure and contract information available.
Get My Statement ReviewedOfficial sources
About this guide
Published by Card Payment Connect, an independent card-payment consultancy for UK businesses. Reviewed by Matthew McCarthy, who has worked in UK merchant services for over a decade. Last reviewed 11 September 2026.