home / frameworks / pci-dss / merchant-levels-and-saqs

// PCI DSS hub

PCI DSS merchant levels and SAQ types

Who sets merchant levels, which Self-Assessment Questionnaire fits which payment setup, and what changed for SAQ A in 2025.

Who sets merchant levels

The PCI Security Standards Council writes the standard but does not decide who must validate compliance or how. Each payment brand runs its own compliance program, and acquirers apply those programs to the merchants they sign. The Council's merchant page says it plainly. Questions about validation and reporting requirements go to the acquirer, which is the merchant's bank, or to the payment brand the merchant does business with.

Visa, for example, sets a merchant's level by its total Visa transaction volume over 12 months, counting credit, debit, and prepaid. Acquirers must make sure their merchants validate at the right level and collect the required documents. Brands usually define 4 merchant levels. The highest-volume merchants generally need an annual assessment by a QSA and a Report on Compliance, while smaller merchants usually complete a Self-Assessment Questionnaire.

Service providers

Service providers, such as processors, gateways, hosting companies, and managed security providers, have their own levels, which the brands set separately from merchant levels. Larger ones need a Report on Compliance. SAQ D for Service Providers is the only questionnaire available to service providers that are eligible to self-assess.

The SAQ types

Each SAQ covers a particular way of accepting cards, and each has eligibility criteria that must all be true for the merchant to use it.

  • SAQ A: card-not-present merchants that fully outsource account data functions to validated providers
  • SAQ A-EP: e-commerce merchants whose website can affect the security of the payment transaction
  • SAQ B: merchants using imprint machines or standalone dial-out terminals
  • SAQ B-IP: merchants using standalone PCI-approved terminals with an IP connection
  • SAQ C-VT: merchants keying transactions into a virtual terminal on a standalone computer
  • SAQ C: merchants with payment application systems connected to the internet
  • SAQ P2PE: merchants using a validated point-to-point encryption solution
  • SAQ SPoC: merchants using a commercial mobile device with a secure card reader in a validated SPoC solution
  • SAQ D for Merchants and SAQ D for Service Providers: everyone else

SAQ A changes in 2025

PCI DSS v4 added Requirements 6.4.3 and 11.6.1 to protect payment pages from malicious scripts, and they were due to apply to SAQ A merchants from March 31, 2025. The Council then changed course. On January 30, 2025, after feedback about how hard they were to implement, the Council published a revised SAQ A. It removed Requirements 6.4.3 and 11.6.1, and the related targeted risk analysis in 12.3.1, from SAQ A.

SAQ A gained an eligibility criterion instead. E-commerce merchants must confirm that their site is not susceptible to attacks from scripts that could affect their e-commerce systems. The revised SAQ A took effect on March 31, 2025, which is also the date the October 2024 version of the questionnaire retired. The requirements still apply in full to merchants validating with other SAQs or a Report on Compliance.

A Council FAQ published in February 2025 explains 2 ways to meet the new criterion. Either works. The merchant can use script protection techniques itself, such as those described in 6.4.3 and 11.6.1. Or it can get confirmation from its PCI DSS compliant payment provider that the embedded payment form includes such protection when implemented as instructed.

Picking the right form

Read every eligibility criterion before choosing. A merchant that takes card numbers over the phone and also runs an e-commerce site with an embedded payment form may need more than one SAQ, or SAQ D. Ask the acquirer and the payment provider to confirm the choice in writing. Whichever SAQ applies, the merchant signs an Attestation of Compliance and sends it to the acquirer, along with ASV scan reports when the SAQ requires them.

Resources

All PCI DSS resources

References

  1. Merchant Resources, PCI Security Standards Council
  2. PCI DSS v4: What's New with Self-Assessment Questionnaires, PCI Security Standards Council
  3. Important Updates Announced for Merchants Validating to Self-Assessment Questionnaire A, PCI Security Standards Council
  4. Account information security program and PCI, Visa