SAQ Types A Through D, Explained
Eight questionnaires, one choice that shapes your whole PCI workload. Which SAQ type fits your payment setup — and what each one demands.
Why the SAQ type matters
Your SAQ type determines how many PCI DSS requirements you attest to — from a couple dozen (SAQ A) to the full set of 300+ (SAQ D). Picking correctly keeps the workload honest; picking wrong means either attesting to requirements that don't apply or, worse, skipping ones that do.
The eight types
| SAQ | Fits when | Workload |
|---|---|---|
| A | Card data never touches your systems — fully outsourced e-commerce (hosted payment page, iframe, or JS-based tokenization) | Lightest |
| A-EP | E-commerce, but your website affects payment-page security (e.g., you control the page hosting the iframe) | Light–moderate |
| B | Imprint machines or standalone dial-out terminals only, no electronic cardholder data storage | Light |
| B-IP | Standalone PTS-approved point-to-point terminals connected via IP, no electronic storage | Light |
| C-VT | Web-based virtual terminals only — manual key entry into an isolated device/browser, no electronic storage | Light–moderate |
| C | Payment application systems connected to the internet (e.g., POS systems), no electronic storage | Moderate |
| P2PE | Validated point-to-point encryption solution only, no electronic storage | Light |
| D | Everyone else — any merchant not fitting the narrower SAQs | Full requirements |
Turn reading into quotes. Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes, no obligation.
Request quotesHow to pick
Map how card data actually flows through your environment — not how the architecture diagram says it flows. The SAQ eligibility criteria are precise: one exception (a stored PAN in a log file, a terminal that isn't on the validated list) can push you from SAQ A to SAQ D. When in doubt, a QSA's scoping opinion is cheaper than a wrong attestation.
When you outgrow your SAQ
Growth changes the answer: crossing into Level 1 (6M+ transactions/year for most brands) moves you from SAQ to ROC. Plan the transition a year ahead — your first ROC cycle takes 4–9 months end to end.
Keep reading
ROC vs SAQ: Which PCI Validation Path Are You On?
The two roads through PCI DSS certification — what happens on each, who decides, and the expensive mistake of picking the wrong one.
What QSAs Actually Test: Inside ROC Fieldwork
Phase 4 demystified — the testing procedures, the evidence requests, and how to walk into fieldwork with everything ready.
What Happens If You Fail a PCI Assessment
Nobody passes on the first try. How findings, remediation, and re-testing actually work — and why “not yet compliant” isn't the disaster it sounds like.
Questions
We're on Shopify — which SAQ?
Typically SAQ A, since card data never touches your systems. Confirm with your acquirer; custom checkout code can change the answer.
Does SAQ D mean we failed?
No — SAQ D is simply the questionnaire for merchants whose setup doesn't fit the narrower SAQs. It's the most work, not a penalty.
Turn reading into quotes
Get scoped, comparable quotes from accredited QSA companies — free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match accredited QSA companies to your size and scope → they send scoped quotes directly. Free, no obligation.