Get Demo
↑

PCI DSS SAQ D for Merchants and Service Providers

PCI DSS v4.0.1 SAQ D - the full self-assessment for merchants who do not fit another SAQ, and the only SAQ for eligible service providers.

Published: September 2026 Compliance · PCI DSS 8-12 min read

SAQ D for Merchants applies to merchants eligible to complete an SAQ who do not meet criteria for any other SAQ type. SAQ D for Service Providers applies to all service providers defined by a payment brand as eligible to complete an SAQ - and it is the only SAQ option for those service providers.

Related: SAQ types · ROC and AOC · SAQ vs ROC · 12 requirements.

Gotcha: SAQ D is still a self-assessment tool, not a ROC. Brand and acquirer programs decide whether you are SAQ-eligible at all. Level 1 / ROC-required entities typically cannot substitute SAQ D. Conversely, being "small" does not auto-qualify you for SAQ A if your architecture fails A's criteria - you may land on SAQ D.

SAQ D for Merchants

Examples of environments where SAQ D may apply (from the SAQ Instructions):

SAQ D for Service Providers

For PCI DSS v4.x, SAQ D for Service Providers requires additional documentation in Section 2a and specifies that service providers Describe Results for each PCI DSS requirement - a higher reporting bar than many merchant SAQs.

SAQ D vs ROC

SAQ D remains a self-attested questionnaire plus AOC. A ROC is a detailed assessment report, typically produced with a QSA when your compliance program requires it. See ROC and AOC and SAQ vs ROC.

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across SAQ and ROC validation paths.

Frequently Asked Questions

Is SAQ D the same for merchants and service providers?

Same family, different documents and expectations. The service provider version adds Describe Results and Section 2a documentation.

If I store PAN, can I still use SAQ A?

No. SAQ A forbids electronic store, process, or transmit of account data on merchant systems. Storage typically points to SAQ D (or a ROC if required).

Does SAQ D include all 12 requirements?

It is the comprehensive SAQ aligned to applicable PCI DSS requirements for that entity type - treat it as the full self-assessment path, not a reduced SAQ A-style subset.

SAQ selector · SAQ types · SAQ A · ROC and AOC · QSA vs ISA vs ASV · 12 requirements

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!