Fundamentals

PCI SAQ Types Explained: A, A-EP, B, B-IP, C, C-VT, D, and P2PE

Why the SAQ type matters

Completing the wrong SAQ is one of the most common PCI failures: merchants attest on SAQ A when their checkout actually touches card data, and acquirers reject the attestation. Your SAQ type is determined by how you accept cards -- not by preference. Get it confirmed by your acquirer in writing before you start.

Every SAQ type

SAQWho it's for
SAQ ACard-not-present merchants that fully outsource card processing (e.g., redirect or iframe to a PCI-compliant provider) and never touch card data.
SAQ A-EPE-commerce merchants whose website affects payment-page security (e.g., scripts you control on the checkout page) but that still outsource processing.
SAQ BMerchants using imprint machines or standalone dial-out terminals only -- no electronic cardholder data storage.
SAQ B-IPMerchants using standalone IP-connected PTS-approved terminals only -- no electronic storage.
SAQ C-VTMerchants keying transactions into a virtual terminal on an isolated computer -- web-based, no electronic storage.
SAQ CMerchants with payment application systems connected to the internet but no electronic cardholder data storage.
SAQ P2PEMerchants using a validated point-to-point encryption solution listed by the PCI SSC -- dramatically reduced scope.
SAQ D (Merchants)Everyone else: any merchant not eligible for the above. The full requirement set -- the longest questionnaire.

The most common picks

Most small e-commerce merchants land on SAQ A (fully hosted checkout) or SAQ A-EP (you control checkout-page scripts -- and under v4.x, those scripts now need inventory and integrity controls per requirements 6.4.3 and 11.6.1). Most single-terminal retailers land on SAQ B-IP. If none of the narrow SAQs fit, you're SAQ D -- budget accordingly.

How to confirm yours

  • Ask your acquirer in writing. They decide which validation they accept -- their answer overrides any guide.
  • Map your actual card flows. If card data touches your servers, SAQ A is off the table no matter what your checkout vendor claims.
  • Re-check after changes. A new checkout integration or terminal type can change your SAQ type mid-year.
  • Consider P2PE. A validated P2PE solution can collapse a SAQ D scope into SAQ P2PE -- often the highest-ROI PCI decision a retailer makes.

Questions

Can I choose SAQ A to make PCI easier?

No -- eligibility is determined by your card-acceptance method, not preference. Using the wrong SAQ produces an attestation your acquirer will reject, and QSAs flag it immediately.

What is the difference between SAQ A and SAQ A-EP?

SAQ A is for merchants that fully outsource card processing and whose website does not affect payment security. SAQ A-EP is for e-commerce merchants whose site does affect payment-page security (e.g., scripts you control) -- it carries substantially more requirements.

Independent directory note. This guide is educational content, not assessment advice. Confirm requirements with your QSA and acquirer.

Related reading

Get quotes from PCI QSA firms

Tell us about your environment once -- matched assessors reply with scoped quotes. Free, 2 minutes.

Get a free quote