← All postsHow-to

PCI SAQ: choosing the right questionnaire is most of the job

There are several self-assessment questionnaires and they differ enormously in length. Answering the wrong one carefully is worse than answering the right one quickly.

How-toP

A PCI SAQ — self-assessment questionnaire — is the document by which a merchant validates its compliance with the payment card data security standard without a formal on-site assessment. It comes in several variants, each written for a particular way of accepting cards, and the variants differ from a couple of dozen questions to several hundred.

Choosing the variant is therefore the decision that determines the size of the exercise, and it is not a preference. The variant is dictated by how your business accepts payments and how much of your environment touches card data. Completing a short questionnaire when your environment requires the long one is an invalid attestation, not a shortcut.

How the PCI SAQ variants differ

  • The shortest variants are for merchants who have fully outsourced card handling — a hosted payment page or a redirect where card data never reaches your systems or your website’s code.
  • A middle variant covers e-commerce where your site delivers the payment page or scripts that could affect it, which brings your web environment into scope even though you never store a card number.
  • Separate variants exist for card-present terminals, standalone dial-out terminals, virtual terminals and point-to-point encryption solutions.
  • The longest variant applies where none of the others fit — typically where card data is stored, processed or transmitted by your own systems.
  • Service providers have their own variant, distinct from any of the merchant ones.

The attestation is the part that binds

Each questionnaire is accompanied by an attestation of compliance, signed by an officer of the business, confirming that the answers are accurate. That signature is what your acquirer relies on and what would be examined after an incident. It is also why the questionnaire should not be completed by whoever has capacity: the person answering needs to know how payments actually flow, and the person signing needs to have satisfied themselves that the answers are true rather than aspirational.

Answering "yes" to a control you intend to implement is the single most dangerous habit in this document. Where a control is not in place, the standard provides for documenting it and remediating rather than pretending — and an inaccurate attestation discovered after a breach changes the character of the conversation with your acquirer entirely.

Where merchants get the variant wrong

The commonest error is assuming the shortest e-commerce variant applies because a payment provider is used. If your own page loads the payment form, or your site serves scripts on the page where the card is entered, the shorter variant generally does not apply — and script integrity has become an explicit focus of the standard for exactly this reason. Confirm the variant with your acquirer or provider in writing before completing anything, because the wrong choice invalidates the whole submission.

Completing it as a repeatable exercise

The questionnaire recurs annually and most answers are stable, so the work is retrieval rather than reasoning — provided last year’s answers and their evidence were kept. Ettex Forms holds the questionnaire with answers and owners per section so next year starts from this year rather than from blank, Ettex Records keeps the completed questionnaire, the attestation and the supporting evidence per year, and which variant you need follows from pci compliance levels.

Plainly: this is a forms and records tool, not a PCI product. We do not host questionnaires for acquirers, run scans or attest to anything. The current questionnaire versions come from the standards body and the requirement to submit comes from your acquirer.

Frequently asked

What is a PCI SAQ?

A self-assessment questionnaire by which a merchant validates compliance with the card data security standard without a formal on-site assessment.

How do I know which SAQ applies?

It depends on how you accept payments and how much of your environment touches card data. Confirm it with your acquirer or payment provider in writing.

Who signs the attestation?

An officer of the business, confirming the answers are accurate. The signature is what the acquirer relies on.

What if a control is not in place?

Document it and remediate rather than answering yes. An inaccurate attestation is a far more serious position than a known gap being worked on.

IP
Written by Ivan P.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.