Diff: FAQ #1133

Why are there multiple PCI DSS Self-assessment Questionnaires (SAQs)?

Earlier Version
Later Version
Removed
Added
TheThere are multiple versions of PCI Data Security Standard Self-assessmentDSS SAQs to meet various merchant scenarios, depending on how each merchant organization stores, processes, or transmits cardholder data (CHD) and/or sensitive authentication data (SAD). For more information on how to determine which SAQ applies best to a merchant environment and how to complete an SAQ, refer to 'PCI DSS Self-Assessment Questionnaire (SAQ) is a validation tool to assist merchantsInstructions and service providers in demonstrating their compliance with the PCI Data Security Standard (PCI DSS) through a self- assessment, as permitted by the payment brands.

There are multiple versions of the SAQ to meet various scenarios, depending on how your organization stores, processes, or transmits cardholder data. For more information on how to complete the SAQ, please refer to the ?Self-Assessment Questionnaire Instructions and Guidelines?,
Guidelines', available in the Document Library.

Merchants should also consult with their compliance-accepting entity - the entity to which the SAQ will be submitted (typically, an acquirer (merchant bank) or the payment brands directlybrands) to determine if they are eligible or required to submit an SAQ, and if so, which SAQ is appropriate for their environment.

SAQ D for Service Providers is the ONLY SAQ for SAQ-eligible service providers. All other SAQs are for merchant use only.

Refer to FAQ 1215: What is a PCI DSS Self-Assessment Questionnaire?