PCI SAQ Types Explained: A, A-EP, B, B-IP, C, C-VT, D, and P2PE
Why the SAQ type matters
Completing the wrong SAQ is one of the most common PCI failures: merchants attest on SAQ A when their checkout actually touches card data, and acquirers reject the attestation. Your SAQ type is determined by how you accept cards -- not by preference. Get it confirmed by your acquirer in writing before you start.
Every SAQ type
| SAQ | Who it's for |
|---|---|
| SAQ A | Card-not-present merchants that fully outsource card processing (e.g., redirect or iframe to a PCI-compliant provider) and never touch card data. |
| SAQ A-EP | E-commerce merchants whose website affects payment-page security (e.g., scripts you control on the checkout page) but that still outsource processing. |
| SAQ B | Merchants using imprint machines or standalone dial-out terminals only -- no electronic cardholder data storage. |
| SAQ B-IP | Merchants using standalone IP-connected PTS-approved terminals only -- no electronic storage. |
| SAQ C-VT | Merchants keying transactions into a virtual terminal on an isolated computer -- web-based, no electronic storage. |
| SAQ C | Merchants with payment application systems connected to the internet but no electronic cardholder data storage. |
| SAQ P2PE | Merchants using a validated point-to-point encryption solution listed by the PCI SSC -- dramatically reduced scope. |
| SAQ D (Merchants) | Everyone else: any merchant not eligible for the above. The full requirement set -- the longest questionnaire. |
The most common picks
Most small e-commerce merchants land on SAQ A (fully hosted checkout) or SAQ A-EP (you control checkout-page scripts -- and under v4.x, those scripts now need inventory and integrity controls per requirements 6.4.3 and 11.6.1). Most single-terminal retailers land on SAQ B-IP. If none of the narrow SAQs fit, you're SAQ D -- budget accordingly.
How to confirm yours
- Ask your acquirer in writing. They decide which validation they accept -- their answer overrides any guide.
- Map your actual card flows. If card data touches your servers, SAQ A is off the table no matter what your checkout vendor claims.
- Re-check after changes. A new checkout integration or terminal type can change your SAQ type mid-year.
- Consider P2PE. A validated P2PE solution can collapse a SAQ D scope into SAQ P2PE -- often the highest-ROI PCI decision a retailer makes.
Questions
Can I choose SAQ A to make PCI easier?
No -- eligibility is determined by your card-acceptance method, not preference. Using the wrong SAQ produces an attestation your acquirer will reject, and QSAs flag it immediately.
What is the difference between SAQ A and SAQ A-EP?
SAQ A is for merchants that fully outsource card processing and whose website does not affect payment security. SAQ A-EP is for e-commerce merchants whose site does affect payment-page security (e.g., scripts you control) -- it carries substantially more requirements.
Related reading
Get quotes from PCI QSA firms
Tell us about your environment once -- matched assessors reply with scoped quotes. Free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.