Payments Basics · 8 min read

PCI SAQ types explained

Not every business fills out the same PCI self-assessment questionnaire. The type that applies depends entirely on how you accept cards, and choosing correctly keeps the process short instead of unnecessarily long.

Why there's more than one type

The PCI Security Standards Council created multiple questionnaire versions because a business using a simple, encrypting terminal has vastly less security exposure than one running custom software that touches raw card numbers. The SAQ type matches the questionnaire's depth to your actual risk.

Common SAQ types for small merchants

Most small businesses land in one of a few common categories based on how they take payments.

  • SAQ B or B-IP: standalone, dial-out or IP-connected terminals not connected to other systems
  • SAQ P2PE: point-to-point encrypted terminal solutions, often the shortest form
  • SAQ A: e-commerce fully outsourced to a validated third-party payment page
  • SAQ D: the most comprehensive, for merchants storing, processing or transmitting card data directly

How your equipment determines your type

A modern, integrated POS terminal that encrypts card data at the point of swipe, tap or dip typically qualifies you for a shorter questionnaire, since the card data never touches your network in a readable form.

What determines the type for online sales

If checkout is fully hosted by a validated third-party payment page, you generally qualify for the shortest e-commerce questionnaire. If you build a custom checkout page that handles card data directly, you take on a much longer, more detailed assessment.

Who fills it out and how often

The business owner or a designated staff member completes the questionnaire annually, typically through the processor's online portal, which walks through the relevant questions based on your setup.

What happens if you pick the wrong type

Filling out a shorter questionnaire than your actual setup warrants doesn't hold up if you're ever audited or breached. It's worth confirming the correct type with your processor rather than guessing based on what seems easiest.

Reducing your scope going forward

Moving from manually keyed entry or legacy terminals to a modern, point-to-point encrypted system is the most effective way to shrink both your actual risk and the length of your annual questionnaire.

How we help with this

Because our setups use modern, encrypting Clover and Square hardware, most clients qualify for one of the shortest questionnaire types. We'll confirm which one applies to you as part of onboarding.

Common questions

How do I know which SAQ type applies to me?

It depends on how you accept cards — your processor's portal typically determines this for you based on your equipment and setup.

Does a modern POS terminal shorten my questionnaire?

Usually yes, since encrypted, point-to-point terminals reduce what your systems are exposed to.

How often do I complete it?

Annually, typically through your processor's online compliance portal.

What if I run both in-person and online sales?

You may need to address both applicable types, or a combined assessment depending on your setup.

Is completing the SAQ enough to guarantee I'm secure?

It's a strong minimum baseline, but ongoing basics like staff training and updated software matter too.

Still not sure?

Two minutes on the phone usually beats another hour of reading. We'll tell you what fits and what doesn't.