10 Types of Payment Card Industry Self-Assessment Questionnaires

Ajay Unni
Ajay Unni CEO,StickmanCyber
October 6, 2026 3 min read

In our previous blogs, we have talked about what is PCI DSS, the major benefits, and the consequences of non-compliance. We also looked at the PCI DSS requirements and merchant levels.

This blog dives deeper into the topic and focuses on the different types of questionnaires involved in the compliance process.

The Payment Card Industry Security Standards Council has designed ten Self-Assessment Questionnaires for PCI DSS v4.0.1 that are self-validation tools to assess the security of your cardholder data. The Self-Assessment Questionnaire or SAQ includes a series of questions for each applicable PCI Data Security Standard requirement, answered with responses such as ‘In Place’ or ‘Not in Place’. If a requirement is not in place, your organisation may be required to state the future remediation date and associated actions.

Before you start, the PCI Security Standards Council encourages merchants and service providers – including Australian businesses – to confirm with their acquirer (merchant bank) or the payment brands that they are eligible to complete an SAQ, and to understand any specific requirements or instructions.

There are different questionnaires available to meet different merchant and/or service provider environments, below is a list of the ten different self-assessment questionnaires:

SAQ A

This self-assessment questionnaire is not applicable for face-to-face channels and is to be completed by merchants who deal with ‘card not present’ transactions i.e. e-Commerce, mail or telephone order. If your organisation has outsourced all cardholder functions to PCI DSS compliant third-party service providers and does not electronically store, process or transmit cardholder data on your systems or premises, this SAQ is the right one for you. Since the January 2025 revision, e-commerce merchants must also confirm that their site is not susceptible to attacks from scripts that could affect their e-commerce systems. (Not applicable for Face to Face channels)

SAQ A-EP

The ‘A-EP’ self-assessment questionnaire is similar to SAQ A but refers to merchants who partially outsource payment processing to PCI DSS validated third parties, and who have a website(s) that doesn’t directly receive cardholder data but that can impact the security of the payment transaction. (Applicable to only e-Commerce channels)

SAQ B

This self-assessment questionnaire is applicable to merchants who use only imprint machines and/or standalone, dial-out terminals and have no electronic cardholder data transmission, processing and storage. (Not applicable to e-Commerce channels)

SAQ B-IP

The B-IP self-assessment questionnaire is applicable to all merchants who only utilise standalone, PTS-approved payment terminals with an IP connection to the payment processor, with no electronic cardholder data storage. This questionnaire covers terminals that are network-based whereas SAQ B is for terminals that transmit data through dial-up. (Not applicable to e-Commerce channels)

SAQ C-VT

This self-assessment questionnaire is designed for merchants who manually enter a single transaction at a time via a keyboard into an Internet-based virtual terminal solution that is provided and hosted by a PCI DSS validated third-party service provider. These merchants also do not store any cardholder data. (Not applicable to e-Commerce channels)

SAQ C

For merchants with payment application systems connected to the Internet, and who don’t store any cardholder data electronically. (Not applicable to e-Commerce channels)

SAQ P2PE

This self-assessment questionnaire is dedicated for merchants who use only a validated, PCI-listed point-to-point encryption (P2PE) solution, with no electronic card data storage. P2PE stands for point-to-point encryption, which uses specially-approved devices to capture and encrypt cardholder data before that data ever enters a merchant's computer network. (Not applicable to e-Commerce channels)

SAQ SPoC

This self-assessment questionnaire is for merchants using a commercial off-the-shelf mobile device (for example, a phone or tablet) with a secure card reader included on PCI SSC’s list of validated Software-based PIN Entry on COTS (SPoC) solutions. (Not applicable to unattended, mail/telephone order or e-Commerce channels)

SAQ D for Merchants

This is a self-assessment questionnaire for merchants who are not described in the above types of SAQs.

SAQ D for Service Providers

This is a self-assessment questionnaire for all service providers defined by a payment brand as eligible to complete an SAQ.

Is your business looking to get PCI DSS compliant? StickmanCyber's PCI DSS compliance service deploys a 5-step methodology to help you build trust with your customers and support secure transactions with PCI DSS Compliance.

Ajay Unni

Ajay Unni

CEO,StickmanCyber Ajay Unni is CEO of StickmanCyber, leading the team in delivering cybersecurity, risk, and compliance solutions. He holds a Master of IT and a Bachelor of Computer Science, is a PCI Qualified Security Assessor and Certified Information Systems Auditor, and has served as CREST Vice Chairman and a member of the NSW Government Cyber Security Taskforce. With over 25 years in the industry, Ajay is a sought-after voice on the Australian cyber threat landscape.

Master of IT B. Computer Science PCI Qualified Security Assessor Certified Information Systems Auditor (CISA) CREST Vice Chairman NSW Gov Cyber Security Taskforce

Cybersecurity As A Service for Australian Organisations

StickmanCyber helps mid-market businesses across Australia and New Zealand reduce cyber risk, strengthen compliance, and build security maturity without the cost and complexity of managing it all internally.

Combining experienced cybersecurity specialists with AI-powered delivery, StickmanCyber provides practical, Cyber Done support across risk assessments, compliance, remediation, and ongoing protection — acting as a trusted partner from strategy through to certification and beyond.

CREST Accredited PCI-DSS ISO 27001 Essential Eight Since 2006
Book a free consultation
Risk Assessment & Essential EightUnderstand your current maturity and gaps
Compliance & CertificationISO 27001, PCI DSS, SOC 2 and more
Penetration & VAPTFind gaps, strengthen controls, build resilience
24/7 Monitoring via StickSecureContinuous visibility across your environment

Recent Posts