PCI DSS

PCI DSS SAQ Compliance (Levels 2-4)

Self-Assessment Questionnaire completion for merchant Levels 2 to 4 and Level 2 service providers. Scoped to one entity and one cardholder data environment, with the documentation and awareness training a defensible attestation requires.

Overview

The PCI DSS Self-Assessment Questionnaire is the validation route for merchants and service providers who do not require a QSA-signed assessment. The PCI Security Standards Council (PCI SSC) defines the SAQ types: merchants at Levels 2, 3, and 4 use the appropriate merchant SAQ (including SAQ D for merchants where applicable), while Level 2 service providers who store, process, or transmit cardholder data on behalf of third parties use SAQ D for service providers. For PCI compliance, the distinction between a merchant and a service provider is determined by how the entity handles cardholder data (CHD), and whether it does so for its own transactions or on behalf of another organisation. We confirm the correct SAQ type for your payment flows, complete the questionnaire, assemble the supporting evidence, and prepare your Attestation of Compliance.

Each engagement is scoped to one entity and one cardholder data environment (CDE). The PCI DSS scope covers all systems and people that store, process, or transmit payment card data, or that could impact the security of that data electronically, including any systems connected to the internet that interact with your payment application or card processing environment. Multiple payment flows that share the same in-scope people, processes, technologies, and controls are covered within that single scope. Separate legal entities, separate platforms, or materially different systems are scoped individually, so the attestation reflects reality and stands up to acquirer review.

The engagement includes a customised PCI DSS policy and procedure documentation suite, tailored to your organisation and your CDE, and cyber security awareness training delivered to in-scope staff. Both are required components of a defensible PCI attestation, not optional add-ons. We also map your account data flows and document the cardholder data functions performed by your organisation and any third-party service providers involved in your payment processing.

What’s included

  • Determination of the correct SAQ type (SAQ A, SAQ A-EP, SAQ B, SAQ B-IP, SAQ C, SAQ C-VT, SAQ P2PE-HW, SAQ D for merchants, or SAQ D for service providers)
  • SAQ completion scoped to one entity and one cardholder data environment
  • Cardholder data flow mapping, PCI DSS scope definition, and account data inventory
  • Customised PCI DSS policy and procedure documentation suite aligned to pci standards
  • Cyber security awareness training for in-scope staff
  • Evidence collection and an organised audit repository
  • Attestation of Compliance (AoC) preparation and submission support

How we work

  1. 01
    Scope confirmation

    We confirm the correct SAQ type, the in-scope entity and cardholder data environment, your payment channels, and the engagement timeline. We review how your organisation handles card processing, whether payment terminals are involved, and whether any hardware payment terminals or third-party service providers interact with systems or premises where card data flows. Getting scope right at the start is what keeps the attestation defensible at the end.

  2. 02
    Gap analysis

    We map your current security controls to the applicable PCI DSS v4.0.1 requirements and document gaps with clear ownership. We review your payment application, your card processing flows, and the controls your payment processor and any third-party service providers have in place. Findings are prioritised by criticality so your team knows what to address first.

  3. 03
    Documentation and guidance

    We author the customised policy and procedure suite, deliver security awareness training to in-scope staff, and guide remediation. Technical fixes inside your environment, such as firewall configuration, antivirus deployment, server hardening, or code-level changes, are carried out by your team. We document what your payment brand and acquirer will expect to see, including evidence of point-to-point encryption where it applies to your pci dss scope.

  4. 04
    Attestation

    We complete the SAQ, prepare the AoC, and hand over the evidence repository so you can respond to any acquirer request with confidence. If you need to complete an saq on a recurring basis, the evidence repository we build makes each subsequent cycle faster.

What you get

  • Completed SAQ for the in-scope entity and CDE
  • PCI DSS SAQ report
  • Customised PCI DSS policy and procedure suite meeting pci dss standards
  • Cardholder data flow and scope documentation, including account data inventory
  • Cyber security awareness training records
  • Attestation of Compliance (AoC) and supporting evidence repository

Service providers use SAQ D only

If you store, process, or transmit cardholder data on behalf of other organisations, SAQ D for service providers is the only SAQ category that applies. Service providers are not limited to entities providing payment gateway or processing services; organisations that provide hosting services, cloud services, or similar outsourced services and handle cardholder data on behalf of their clients may also fall under SAQ D for service providers. For PCI compliance, the distinction between a merchant and a service provider is determined by how the entity handles cardholder data (CHD), and whether it does so for its own transactions or on behalf of another organisation. We scope and complete it with the security standards council requirements and the controls your customers' acquirers expect.

What sits with the client

Technical remediation is your team's responsibility. This includes antivirus deployment, firewall configuration, server hardening, code-level fixes, and resolving failed scan findings. We identify the gaps, author the documentation, deliver the training, and guide the work. Implementation of technical controls inside your environment is yours to execute or assign.

Frequently asked questions

Which SAQ type applies to us?

It depends on how you accept and handle card data. We confirm the correct SAQ type during scope confirmation. Service providers always use SAQ D for service providers. Merchants use SAQ A, SAQ A-EP, SAQ B, SAQ B-IP, SAQ C, SAQ C-VT, SAQ P2PE-HW, or SAQ D for merchants depending on their integration method, data environment, and segmentation. The pci security standards council publishes the SAQ eligibility criteria for each type.

Does one SAQ engagement cover more than one cardholder data environment?

A standard engagement covers one entity and one cardholder data environment. Multiple payment flows that share the same in-scope people, processes, technologies, and controls can be covered within that single scope. Additional entities, separate platforms, or materially different systems are scoped separately so the attestation is accurate.

Do you carry out the technical fixes you identify?

We identify the gaps, author the required documentation, deliver awareness training, and guide remediation. Technical fixes inside your environment, such as firewall configuration or code-level changes, are carried out by your team.

Does the SAQ engagement include the policy documentation and training PCI requires?

Yes. Every engagement includes a customised PCI DSS policy and procedure documentation suite and security awareness training for in-scope staff. Both are required for a defensible pci dss compliance attestation.

What is the difference between a merchant SAQ and a service provider SAQ?

Merchants process card transactions for their own sales. Service providers handle cardholder data on behalf of other organisations, such as a payment processor, gateway, or managed service provider. SAQ D for service providers applies to service providers and has a broader control scope than any merchant SAQ type. The pci dss requirement set differs between the two.

Credentials held by our team

ISO/IEC 27001 Lead Auditor
CISM
CISA
COBIT 2019
CEH
CRTP
eCPPT
CSA
CCNA
ITIL
Free tool · about 3 minutes · instant score

How ready is your security and compliance?

Answer 15 quick questions across the controls auditors actually check, and get an instant readiness score with tailored next steps. No call required.

Start the free assessment

Ready to simplify security and compliance?

Pick a service, book a scope call, or ask a question. Whatever order works.