Self-Assessment Questionnaire (SAQ)
A Self-Assessment Questionnaire (SAQ) is a tool that lets certain merchants and service providers check and report their own compliance with PCI DSS instead of undergoing a full on-site assessment. It applies to organizations that are eligible for self-validation based on how they accept and handle payment card data. Different SAQ types exist for different business situations, so an organization must use the version that matches how it processes transactions.
The SAQ is a set of PCI DSS validation tools published by the PCI Security Standards Council to help SAQ-eligible merchants and service providers perform and report the results of a self-assessment against applicable PCI DSS requirements. Multiple SAQ types exist, each scoped to a specific acceptance channel and processing environment; for example, SAQ A addresses merchants whose cardholder data functions are completely outsourced to validated third parties. Eligibility for a given SAQ, and the subset of requirements it covers, depends on the organization's payment acceptance model, and the SAQ is distinct from a full Report on Compliance (ROC) produced during an on-site assessment. SAQ content, eligibility criteria, and requirement mappings differ by PCI DSS version; SAQs for PCI DSS v4.0.1 were made available in October 2024, and practitioners should confirm the correct SAQ type and current version against the published standards rather than assuming fixed criteria.
Why it matters
The SAQ is the primary mechanism by which eligible merchants and service providers demonstrate PCI DSS compliance without the cost and effort of a full on-site assessment culminating in a Report on Compliance (ROC). For the large population of smaller merchants and organizations that outsource most or all of their cardholder data handling, the SAQ makes validation practical and proportionate to their risk profile. It gives acquirers and payment networks a documented statement that the organization has evaluated itself against the applicable PCI DSS requirements.
The stakes lie in selecting the correct SAQ type. Because each SAQ is scoped to a specific payment acceptance model and covers only a subset of PCI DSS requirements, using a version that does not match how an organization actually processes transactions can lead to an incomplete assessment that overlooks requirements genuinely in scope. An organization that believes its cardholder data functions are fully outsourced, for example, may nonetheless retain scope through redirect mechanisms, page integration, or supporting systems, and choosing an SAQ that assumes complete outsourcing could leave real exposure unaddressed.
SAQ content, eligibility criteria, and requirement mappings change between PCI DSS versions. The PCI Security Standards Council made SAQs for PCI DSS v4.0.1 available in October 2024, and the correct SAQ type and current version should be confirmed against the published standards rather than assumed from prior practice. Treating an SAQ as a fixed checklist across versions risks misalignment with the requirements that actually apply.
Who it's relevant to
Inside SAQ
Common questions
Answers to the questions practitioners most commonly ask about SAQ.