What are the steps needed to use the Self-assessment Questionnaire (SAQ) to validate compliance with PCI DSS?
In accordance with payment brands? compliance programs, those merchants and service providers who are permitted by the payment brands to validate their compliance with the PCI DSS using a Self-assessment Questionnaire (SAQ) may need to complete the following steps:
- Complete the SAQ according to the Self- Assessment Questionnaire Instructions and Guidelines document.
- Complete a clean vulnerability scan with a PCI SSC Approved Scanning Vendor (ASV), and obtain evidence of a passing scan from the ASV.
- Complete the relevant Attestation of Compliance in its entirety (located in the SAQ).
- Submit the SAQ, evidence of a passing scan, and the Attestation of Compliance, along with any other requested documentation, to your acquirer or payment brand.
Merchants should consult with their acquirer (merchant bank) or the payment brands directly to determine if they are eligible or required to submit an SAQ, and if so, which SAQ is appropriate for their environment.