SAQ D
SAQ D is a type of PCI DSS Self-Assessment Questionnaire that businesses use to check and report their own compliance with payment card security requirements. It is the longest and most comprehensive questionnaire, and it serves as the catch-all option for organizations that store, process, or transmit card data and do not qualify for one of the shorter, more narrowly scoped questionnaires. There are separate versions for merchants and for service providers.
SAQ D is a Self-Assessment Questionnaire published by the PCI Security Standards Council for use by SAQ-eligible entities in self-validating adherence to PCI DSS. It exists in two forms: SAQ D for Merchants, which applies to SAQ-eligible merchants that do not meet the eligibility criteria for any other SAQ type, and SAQ D for Service Providers, which applies to all service providers defined by a payment brand as SAQ-eligible. Because it functions as the catch-all questionnaire, SAQ D covers the broadest set of applicable PCI DSS requirements relative to other SAQ types, reflecting environments that electronically store, process, or transmit cardholder data. The specific requirement content, wording, and numbering vary by PCI DSS version (for example between v3.x and v4.0), so practitioners should validate against the current SAQ D document and PCI DSS version published by the PCI SSC and confirm SAQ eligibility with the applicable payment brand or acquirer.
Why it matters
SAQ D matters because it is the fallback validation path for organizations whose payment environments are too broad or complex to fit any of the shorter, narrowly scoped questionnaires. Merchants and service providers that electronically store, process, or transmit cardholder data, and that do not meet the eligibility criteria for another SAQ type, use SAQ D to self-assess and report their adherence to PCI DSS. Because it functions as the catch-all, it covers the broadest set of applicable PCI DSS requirements, which means it typically demands the most extensive documentation and control validation of any SAQ.
Getting the questionnaire selection right is consequential. Choosing a shorter SAQ when SAQ D actually applies can leave applicable requirements unassessed, creating a gap between reported compliance and the actual control environment. Conversely, treating an environment as fully in scope when it could be reduced through segmentation, tokenization, or other validated methods can impose unnecessary assessment burden. The evidence indicates that SAQ eligibility is determined by the applicable payment brand or acquirer, so practitioners should confirm which SAQ type applies rather than assuming.
Because the specific requirement content, wording, and numbering differ across PCI DSS versions, an organization completing SAQ D should validate against the current SAQ D document and PCI DSS version published by the PCI SSC. Relying on outdated questionnaire content can misstate which controls are in effect and how they are evidenced.
Who it's relevant to
Inside SAQ D
Common questions
Answers to the questions practitioners most commonly ask about SAQ D.