Blog

PCI DSS SAQ Types: 10 Questionnaires for Australian Businesses

Written by Ajay Unni | Oct 6, 2026, 1:57:11 AM

In our previous blogs, we have talked about what is PCI DSS, the major benefits, and the consequences of non-compliance. We also looked at the PCI DSS requirements and merchant levels.

This blog dives deeper into the topic and focuses on the different types of questionnaires involved in the compliance process.

The Payment Card Industry Security Standards Council has designed ten Self-Assessment Questionnaires for PCI DSS v4.0.1 that are self-validation tools to assess the security of your cardholder data. The Self-Assessment Questionnaire or SAQ includes a series of questions for each applicable PCI Data Security Standard requirement, answered with responses such as ‘In Place’ or ‘Not in Place’. If a requirement is not in place, your organisation may be required to state the future remediation date and associated actions.

Before you start, the PCI Security Standards Council encourages merchants and service providers – including Australian businesses – to confirm with their acquirer (merchant bank) or the payment brands that they are eligible to complete an SAQ, and to understand any specific requirements or instructions.

There are different questionnaires available to meet different merchant and/or service provider environments, below is a list of the ten different self-assessment questionnaires:

SAQ A

This self-assessment questionnaire is not applicable for face-to-face channels and is to be completed by merchants who deal with ‘card not present’ transactions i.e. e-Commerce, mail or telephone order. If your organisation has outsourced all cardholder functions to PCI DSS compliant third-party service providers and does not electronically store, process or transmit cardholder data on your systems or premises, this SAQ is the right one for you. Since the January 2025 revision, e-commerce merchants must also confirm that their site is not susceptible to attacks from scripts that could affect their e-commerce systems. (Not applicable for Face to Face channels)

SAQ A-EP

The ‘A-EP’ self-assessment questionnaire is similar to SAQ A but refers to merchants who partially outsource payment processing to PCI DSS validated third parties, and who have a website(s) that doesn’t directly receive cardholder data but that can impact the security of the payment transaction. (Applicable to only e-Commerce channels)

SAQ B

This self-assessment questionnaire is applicable to merchants who use only imprint machines and/or standalone, dial-out terminals and have no electronic cardholder data transmission, processing and storage. (Not applicable to e-Commerce channels)

SAQ B-IP

The B-IP self-assessment questionnaire is applicable to all merchants who only utilise standalone, PTS-approved payment terminals with an IP connection to the payment processor, with no electronic cardholder data storage. This questionnaire covers terminals that are network-based whereas SAQ B is for terminals that transmit data through dial-up. (Not applicable to e-Commerce channels)

SAQ C-VT

This self-assessment questionnaire is designed for merchants who manually enter a single transaction at a time via a keyboard into an Internet-based virtual terminal solution that is provided and hosted by a PCI DSS validated third-party service provider. These merchants also do not store any cardholder data. (Not applicable to e-Commerce channels)

SAQ C

For merchants with payment application systems connected to the Internet, and who don’t store any cardholder data electronically. (Not applicable to e-Commerce channels)

SAQ P2PE

This self-assessment questionnaire is dedicated for merchants who use only a validated, PCI-listed point-to-point encryption (P2PE) solution, with no electronic card data storage. P2PE stands for point-to-point encryption, which uses specially-approved devices to capture and encrypt cardholder data before that data ever enters a merchant's computer network. (Not applicable to e-Commerce channels)

SAQ SPoC

This self-assessment questionnaire is for merchants using a commercial off-the-shelf mobile device (for example, a phone or tablet) with a secure card reader included on PCI SSC’s list of validated Software-based PIN Entry on COTS (SPoC) solutions. (Not applicable to unattended, mail/telephone order or e-Commerce channels)

SAQ D for Merchants

This is a self-assessment questionnaire for merchants who are not described in the above types of SAQs.

SAQ D for Service Providers

This is a self-assessment questionnaire for all service providers defined by a payment brand as eligible to complete an SAQ.

Is your business looking to get PCI DSS compliant? StickmanCyber's PCI DSS compliance service deploys a 5-step methodology to help you build trust with your customers and support secure transactions with PCI DSS Compliance.