PCI DSS SAQ Assurance made simple

Are you doing the right SAQ? Are you doing your SAQ correctly?

Don’t wait until a regulator scrutinises it. Get assurance from Stratica’s PCI DSS compliance experts.

Speak to a QSA

Self-assessment doesn’t mean self-verified

That’s what a lot of organisations get wrong.

You determine your own scope, select your own SAQ type, answer your own questions and sign your own Attestation of Compliance. Nobody checks your working at the time you submit it.

The checking happens later: after a card data incident, during an acquirer review, in a customer’s due diligence process, or when a regulator asks how you were protecting payment data at the time.

An SAQ is a security assessment questionnaire attesting to your organisation’s security controls. If it doesn’t match your environment, you’re accountable for any potential consequences.

Where SAQs go wrong

When we look over an organisation’s SAQ, these are the most common errors we find.

  • You’ve used the wrong SAQ type. SAQ A is the simplest questionnaire, so it’s the one organisations gravitate towards. Eligibility is narrower than most assume, and it changed under PCI DSS v4.x.
  • Your scope’s too narrow. Call recordings, CRM notes, email inboxes, reception taking a card over the phone, back-office systems that touch the payment page. Scope is defined by where account data goes, not where you intended it to go.
  • Eligibility criteria not actually met. Every SAQ opens with eligibility statements. Signing them without testing them sets you up for failure.
  • No ASV scans. Requirement 11.3.2 brought SAQ A e-commerce merchants into scope for quarterly external scans where the checkout redirects to, or embeds a payment page from, a third-party provider. A scan only passes with no findings scored 4.0 or above on CVSS, confirmed by rescan.
  • You assume your third parties are compliant. Requirement 12.8 expects you to know who your service providers are, what they’re responsible for and to hold their current AoC. “They’re PCI compliant” isn’t evidence.
  • Yes answers without evidence. Every affirmative response needs a policy, a configuration, a log, a network diagram or a training record behind it.
  • A single questionnaire for multiple channels. A retail store plus an online store plus phone orders means a consolidated set of requirements, not the easiest SAQ of the three.

What SAQ assurance from Stratica looks like

We work with you at every stage of the SAQ process to make sure you’re attesting to the right answers.

1. Scope validation. We map where account data is stored, processed and transmitted, including the systems people forget. This step determines everything after it.

2. SAQ selection. We confirm which SAQ your environment qualifies for and test you against the eligibility criteria rather than assuming them.

3. Gap analysis. We work through the applicable requirements, identify where you don’t meet them and tell you plainly what the gap is.

4. Evidence review. We check the evidence behind each response would stand up if someone independent asked to see it.

5. Remediation guidance. A prioritised, practical plan. Not a list of controls copied out of the standard.

6. ASV scanning. Quarterly Approved Scanning Vendor scans, plus remediation and rescan support where findings block a passing result.

7. Attestation and submission. Support completing your AoC and submitting to your acquiring bank, including the documentation they’re likely to ask for.

8. Ongoing compliance. Validation is annual. Compliance isn’t. We help you keep scope and evidence current as your environment changes.

We streamline the process through StraticaOne, our proprietary compliance portal. StraticaOne allows you to load all compliance evidence in one place with an intuitive traffic light model that shows your progress towards compliance.

Which SAQ applies to your organisation?

SAQ Applies to Approx. requirements
A E-commerce and MOTO merchants who fully outsource payment processing to compliant third parties 24 to 27
A-EP Merchants who outsource processing but control the page collecting account data 190
B Merchants using imprint machines or standalone dial-out terminals with no internet connection 41
B-IP Merchants using PCI-approved PTS POI devices connecting over IP 83
C Merchants using internet-connected payment applications such as POS systems 160
C-VT Merchants using a hosted virtual terminal on an isolated device 79
P2PE Merchants using a PCI-approved point-to-point encryption solution 33
D Merchants who store, process or transmit account data electronically, or who don’t qualify for any other SAQ 329
D-SP Service providers handling account data on behalf of other organisations 360

Not sure which one you fall under? Take the SAQ quiz and get your answer.

Want the detail behind each type? Read our full guide to choosing the right SAQ for your business.

Why bring in a QSA for a self-assessment?

You don’t need a QSA to complete an SAQ. it’s a self-assessment, after all. However, SAQs can be a challenging, consequential undertaking – both from an operational and risk management perspective.

Here’s when it makes sense to bring in a QSA:

  • Independence. An external review gives your board, your acquirer, and your customers something more than your word.
  • Interpretation. PCI DSS requirements are written to cover every environment, so applying them to yours takes expert judgement. That’s what QSAs are for.
  • Efficiency. Most organisations spend more time working out what a requirement means than they spend meeting it.
  • Demonstrable answers. If your compliance position is questioned, you’ll need to show how you reached it. A QSA review ensures your SAQ answers can be easily verified, so they stand up to scrutiny.

Stratica is an Australian PCI DSS Qualified Security Assessor firm working with merchants and service providers across all PCI DSS-applicable sectors, including: retail, financial services, travel and hospitality, health, government and not-for-profit.

Make sure your SAQ Survives an Audit or Breach Attempt?

Get independent assurance from our PCI DSS experts.

Stratica’s PCI DSS specialists will review where you stand and tell you whether your current approach holds up. If there are any gaps, we’ll help you close them.

Contact Us

Take the SAQ quiz

Frequently Asked Questions

Annually, along with quarterly ASV scans where your SAQ type requires them. Reassess after any significant change to your payment environment.

A formal document attesting to your PCI DSS compliance, completed once you’ve finished your SAQ. Signed by your organisation, or by a QSA firm where one has performed the assessment.

You complete a single consolidated assessment covering all relevant requirements rather than multiple separate SAQs.

Yes. Outsourcing reduces your scope. It doesn’t remove your obligation to validate, to manage provider relationships under Requirement 12.8, or to hold their current AoC.

Yes, we can help you with every aspect of your SAQ. We validate your scope, confirm the correct SAQ, assess your position against the applicable requirements and make sure you can back up every answer.

Ready to get started?

    Stratica

    STRATICA is an independent advisory practice of over thirty years, specialising in PCI consulting, PCI compliance, and PCI related cyber security service requirements.