Get Demo
↑

PCI DSS SAQ Types Explained: A, A-EP, B, B-IP, C, C-VT, D, P2PE and SPoC

PCI DSS v4.0.1 SAQ types - eligibility overview for A, A-EP, B, B-IP, C, C-VT, P2PE, SPoC, and D (merchants and service providers).

Published: September 2026 Compliance · PCI DSS 8-12 min read

PCI DSS Self-Assessment Questionnaires (SAQs) are alternate validation tools for merchants and service providers that are not required by an acquirer or payment brand to submit a Report on Compliance (ROC). Being SAQ-eligible means (1) your compliance program allows self-assessment and (2) you meet the SAQ Eligibility Criteria in the chosen SAQ. Always confirm with the organization that will receive the SAQ before you start.

Related: SAQ selector · SAQ A · SAQ A-EP · SAQ D · ROC and AOC · SAQ vs ROC.

Gotcha: Matching a short description is not enough. You must meet all eligibility criteria for that SAQ. Service providers eligible to self-assess use only SAQ D for Service Providers - never SAQ A, A-EP, B, C, or the other merchant SAQs.

SAQ Types at a Glance

SAQ
Who it is for
Not for
Card-not-present (e-commerce or MOTO); all account-data functions fully outsourced to PCI DSS compliant TPSPs; no electronic CHD on merchant systems
Face-to-face; service providers
E-commerce partially outsourced; merchant site does not receive account data but affects payment security / page integrity
Non-e-commerce; service providers
B
Imprint and/or standalone dial-out terminals only; no electronic storage
E-commerce; service providers
B-IP
Standalone PCI-listed approved PTS POI (not SCR/SCRP) with IP to processor; isolated; no electronic storage
E-commerce; SCR/SCRP; service providers
C-VT
Manual entry into third-party virtual payment terminal on isolated device; no electronic storage
E-commerce; service providers
C
Payment application systems connected to Internet; isolated; single store; no electronic storage
E-commerce; multi-location LANs; service providers
P2PE
Only validated PCI-listed P2PE solution terminals; no clear-text account data access; no electronic storage
E-commerce; service providers
SPoC (new v4.x)
Attended card-present via PCI-listed SPoC (COTS + PTS SCRP); no clear-text access; no electronic storage
Unattended CP, MOTO, e-commerce; non-PTS MSRs; service providers
All other SAQ-eligible merchants
Service providers
SAQ-eligible service providers (only SP SAQ)
Merchants (use D for Merchants)

E-Commerce Quick Path

Requirement counts from the SAQ Instructions table (v4.x): fully outsourced with no webpage access ~14*; URL redirect ~27*; iframe ~27*; Direct Post / merchant scripts - A-EP ~139; all other e-commerce - SAQ D (all applicable requirements). Asterisks refer to explanatory notes in SAQ A.

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across SAQ and ROC validation paths.

Frequently Asked Questions

Can I pick SAQ A because most of my volume is outsourced?

Only if you meet all SAQ A criteria for that channel. Mixed channels may need multiple SAQs or SAQ D.

Do service providers ever use SAQ A?

No. SAQ-eligible service providers use SAQ D for Service Providers only.

Is SPoC the same as P2PE?

No. Different PCI standards and listings (SPoC vs P2PE), and different eligibility and device models (COTS plus SCRP vs PTS POI in a P2PE solution).

PCI DSS hub · SAQ selector · SAQ A · SAQ A-EP · SAQ D · ROC and AOC · SAQ vs ROC · 12 requirements

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!