Get Demo
↑

PCI DSS SAQ A: Full Outsourcing Eligibility, Script Criteria, and ASV Scans

PCI DSS v4.0.1 SAQ A - card-not-present full outsourcing eligibility, e-commerce.

Published: September 2026 Compliance · PCI DSS 8-12 min read

SAQ A includes only the PCI DSS requirements applicable to merchants with account data functions completely outsourced to PCI DSS validated and compliant third parties, where the merchant retains only paper reports or receipts with account data. It covers e-commerce or mail/telephone-order (card-not-present) channels. It is not applicable to face-to-face channels or to service providers.

Related: SAQ A-EP · SAQ types · ASV scans · Requirement 11.

Gotcha: As of the January 2025 SAQ A (October 2024 version retired 31 March 2025), Requirements 6.4.3, 11.6.1, and supporting 12.3.1 were removed from SAQ A. E-commerce merchants instead confirm the site is not susceptible to script attacks that could affect e-commerce systems. Techniques such as those in 6.4.3 and 11.6.1 remain one way to support that confirmation (per SSC FAQ), especially for iframes, but they are no longer SAQ A checklist items. Requirements 11.3.2 / 11.3.2.1 ASV scanning remain in SAQ A for redirect/iframe host systems.

Eligibility Criteria

Confirm all of the following for the payment channel:

E-Commerce Methods That Can Fit SAQ A

Does not fit SAQ A: merchant creates the payment form (Direct Post); merchant delivers scripts that build or support the payment page - see SAQ A-EP.

Approximate applicable requirement counts from the SAQ Instructions table: no webpage access ~14*; redirect ~27*; iframe ~27* (* explanatory notes in SAQ A).

ASV Scanning in SAQ A

For redirect and iframe hosts, quarterly external ASV scans under 11.3.2 (and after significant change under 11.3.2.1) apply to the merchant system(s) hosting those pages. The PCI SSC ASV Resource Guide calls this out as a first-time SAQ A obligation for many merchants.

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across SAQ and ROC validation paths.

Frequently Asked Questions

Are 6.4.3 and 11.6.1 still in SAQ A?

No in the current SAQ A (January 2025 version effective 31 March 2025). They remain in PCI DSS and in broader SAQs such as A-EP and D. SAQ A uses the script-susceptibility eligibility criterion instead.

Does the script eligibility criterion apply to URL redirects?

Per the SSC FAQ, the new criterion applies to merchants with a webpage that includes a TPSP embedded payment page/form (iframe). It does not apply to pure redirects or fully outsourced payment with no merchant webpage involvement. Confirm with current FAQ/SAQ text and your acquirer.

Can a service provider use SAQ A?

No. SAQ A is not applicable to service providers.

SAQ types · SAQ selector · SAQ A-EP · SAQ D · ASV scan requirements · Requirement 11 · SAQ vs ROC

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!