Get Demo
↑

PCI DSS SAQ A-EP: Partially Outsourced E-Commerce Eligibility

PCI DSS v4.0.1 SAQ A-EP - when your website does not receive account data but still affects payment security.

Published: September 2026 Compliance · PCI DSS 8-12 min read

SAQ A-EP covers e-commerce merchants with website(s) that do not themselves receive account data but that affect the security of the payment transaction and/or the integrity of the page that accepts the customer's account data. Processing (except the payment page) is outsourced to PCI DSS validated and compliant third parties. Merchant systems still must not electronically store, process, or transmit account data.

Related: SAQ A · SAQ types · Requirement 6 · Requirement 11.

Gotcha: For SAQ A-EP, PCI DSS requirements that refer to the cardholder data environment are applicable to the merchant website(s) - because the site impacts how account data is transmitted even though it does not receive account data. That is why A-EP is much larger (about 139 requirements per the SAQ Instructions table) than SAQ A.

Eligibility Criteria

Typical A-EP Patterns

SAQ A vs SAQ A-EP

SAQ A: all payment page/form elements originate only and directly from the TPSP. SAQ A-EP: elements may originate from the merchant or the TPSP. Applicable only to e-commerce; not for service providers.

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across SAQ and ROC validation paths.

Frequently Asked Questions

We use an iframe - is that SAQ A or A-EP?

Often SAQ A if all payment page/form elements originate only and directly from the TPSP and other SAQ A criteria are met. If the merchant delivers payment-form elements or scripts, evaluate SAQ A-EP.

Does SAQ A-EP apply to MOTO?

No. SAQ A-EP is applicable only to e-commerce channels.

Why is SAQ A-EP so much longer than SAQ A?

Merchant-controlled payment pages expand the applicable control set, including CDE-referencing requirements applied to the merchant website.

SAQ selector · SAQ types · SAQ A · SAQ D · Requirement 6 (6.4.3) · Requirement 11 (11.6.1)

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!