PCI DSS SAQ Selector
Answer a few questions about how your business handles card data and find which PCI DSS self-assessment questionnaire applies, how many requirements it contains, and what would move you to a shorter one.
Last reviewed by the Radiatus Cloud team
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
The questionnaire is chosen by how card data reaches you
Merchants often assume the questionnaire depends on transaction volume. It does not. Volume decides your merchant level and therefore whether you may self-assess at all, but which questionnaire you complete is decided by the channel and by how much of the payment page your systems touch. A shop that redirects the customer to a hosted payment page completes a fraction of the questions that the same shop would face if it collected the card number in its own form and posted it onward.
The difference between the short forms is one design decision
SAQ A covers fully outsourced e-commerce where the payment fields are served by the provider. SAQ A-EP covers the case where your page does not receive card data but does control what loads on it, which is why it is several times longer: a compromised script on your page can capture card data even when your server never sees it. That single architectural decision, an iframe or redirect versus a JavaScript-based form, changes the assessment burden more than anything else available to a small merchant.
Any storage of card numbers changes the answer entirely
Storing the primary account number after authorisation moves the assessment to SAQ D regardless of channel, and SAQ D is not a shortened form. Storing the card verification code after authorisation is prohibited outright and is not something a questionnaire accommodates. This is why the most valuable question in scoping is usually whether anything is retained, including logs, backups, screenshots and customer service notes.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
Does transaction volume decide my questionnaire?
No. Volume decides your merchant level and whether you may self-assess rather than undergo a full assessment. The questionnaire itself is decided by the channel and by how much of the payment flow your systems touch.
What is the difference between SAQ A and SAQ A-EP?
SAQ A is for fully outsourced e-commerce where the payment fields are served by the provider, typically in an iframe or after a redirect. SAQ A-EP applies when your page controls what loads on it even though your server never receives card data, because a compromised script can capture the card regardless.
When does SAQ D apply?
Whenever the shorter forms do not fit, and always if you store the primary account number after authorisation. SAQ D covers the full requirement set rather than a subset.
Can I store the card verification code?
No. Storing the CVV, CVC or CID after authorisation is prohibited outright, and no questionnaire accommodates it. That includes call recordings, screenshots and support tickets.
Is this an official determination?
No. It applies the published eligibility criteria to your answers so you can see which form fits and why. Your acquirer sets the actual reporting requirement and can require more than the criteria suggest.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Answer the questions about how card data reaches your systems.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.