Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
PCI SAQ A-EP
PCI DSS Self-Assessment Questionnaire A-EP, for e-commerce merchants that partially outsource payment processing.
SAQ A-EP applies to e-commerce merchants that outsource payment processing to a validated third party but keep a website that can affect the security of the transaction, for example a page that creates, redirects or embeds a payment form served from the merchant's own environment. Cardholder data is not stored electronically, yet the merchant's web infrastructure sits in a position where it could be attacked to compromise payments.
Because of that residual exposure, SAQ A-EP covers a substantially larger portion of PCI DSS v4.0.1 than SAQ A. It addresses the security of the merchant's own web servers and supporting systems in addition to oversight of the payment provider, sitting between the minimal SAQ A and the comprehensive SAQ D in scope.
Monitor the integrity of payment pages and the scripts they load so injected code cannot capture cardholder data in the browser.
Secure the merchant-controlled web servers and supporting systems that influence the payment page, including configuration, patching and vulnerability management.
Restrict administrative access to in-scope systems and enforce strong, individually attributable authentication.
Track the outsourced payment providers, confirm their compliance and document responsibility boundaries.
Read more
Anove scans your stack against PCI SAQ A-EP and 260+ other frameworks in minutes.
Record and review security events across in-scope systems to detect tampering or intrusion.