Get Demo
↑

Free PCI DSS Scope and SAQ Selector Tool

Free PCI DSS SAQ selector - answer a few scoping questions to see likely SAQ A, A-EP, B, B-IP, C, C-VT, P2PE, SPoC, or D - then confirm with your acquirer.

Published: September 2026 Compliance · PCI DSS 8-12 min read

Use this lightweight selector to get a starting hypothesis for which Self-Assessment Questionnaire may fit. Eligibility is defined in the PCI SSC SAQ Instructions and must be confirmed by your acquirer. Service providers eligible to self-assess use only SAQ D for Service Providers.

Related: SAQ types · SAQ A · SAQ A-EP · SAQ D · CDE scoping · Scope reduction.

Gotcha: Your acquirer can mandate a stricter path than the wizard suggests. SPoC and brand-specific rules need human confirmation.

SAQ Selector

This is an on-page helper - not a downloadable calculator and not a legal determination.

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help merchants and service providers collect QSA-ready evidence across scoping, cloud, and SAQ/ROC validation paths.

Frequently Asked Questions

Is the selector binding?

No. Only acquirer/brand confirmation plus meeting all SAQ eligibility criteria matters.

What if we have e-commerce and stores?

Mixed channels often require multiple SAQs or SAQ D - discuss with your acquirer.

Do service providers use SAQ A?

No. Eligible service providers use SAQ D for Service Providers (or ROC).

SAQ types · SAQ A · SAQ A-EP · SAQ D · CDE scoping · Scope reduction

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!