Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
PCI SAQ A
PCI DSS Self-Assessment Questionnaire A, for card-not-present merchants that fully outsource cardholder data functions.
SAQ A is the shortest PCI DSS self-assessment questionnaire. It is intended for card-not-present merchants (e-commerce or mail and telephone order) that have outsourced every cardholder data function to third parties whose PCI DSS compliance has been validated. These merchants never store, process or transmit account data on their own systems and keep only records that contain no electronic cardholder data.
Because the merchant's exposure is minimal, SAQ A covers the smallest subset of PCI DSS v4.0.1 controls. It focuses mainly on oversight of the providers that handle payments and, for e-commerce, on protecting the web pages that hand customers off to those providers. Completing SAQ A attests to compliance with that reduced set rather than with the full standard.
Maintain a list of service providers that handle cardholder data, confirm their PCI DSS status and define in writing which party is responsible for each control.
For redirect or hosted-payment setups, monitor and manage the scripts and content of payment pages so they cannot be tampered with to skim card data.
Keep basic security policies, restrict access to any retained records and ensure staff understand their handling responsibilities.
Limit any paper or report records to what is needed and dispose of them securely, since no electronic account data should be stored.
Read more
Anove scans your stack against PCI SAQ A and 260+ other frameworks in minutes.