RSI Security

What are the PCI 3.2 Self-Assessment Questionnaire Types?

computer

If your company processes credit or debit card payments, you likely need to comply with the Payment Card Industry (PCI) Data Security Standards (DSS). The Security Standards Council (SSC), headed by the five Founding Members (Visa, Mastercard, Discover, American Express, and JCB International), enforces compliance by requiring eligible companies to submit annual documentation verifying their implementation of PCI controls. The most basic of these is the Self Assessment Questionnaire (SAQ)—read on to learn about the different PCI DSS SAQ types.

 

Breaking Down the PCI 3.2 SAQ Types for All Companies

The SSC provides a list of all SAQ variants, with links to corresponding forms available for free download from the SSC document library (pending agreement to licensing conditions). There are nine total PCI compliance SAQ types, which fall into three primary categories of applicability:

After exploring each SAQ type, we’ll provide additional information about the required PCI compliance documentation and implementation of DSS Requirements.

 

PCI SAQ Types Applicable to e-Commerce Channels

The first two PCI SAQ types provided by the SSC apply primarily to e-commerce channels:

Note that SAQ-A-EP is the only SAQ variant that applies exclusively to e-commerce channels. On the other hand, the SAQ-A variant is more flexible, applying across all channels except for face-to-face channels.

 

Request a Free Consultation

 

PCI SAQ Types Not Applicable e-Commerce Channels

The next five PCI SAQ types provided by the SSC apply to channels that are not e-commerce:

Note that SAQ applicability relates to channels. Companies that operate e-commerce and traditional channels may need to report on them separately, with a distinct SAQ for each one, respectively.

PCI SAQ Types Applicable to All Other Company Types

The final two PCI SAQ types provided by the SSC apply to all other DSS-eligible companies:

Note that SAQ-D-SP is the only SAQ type available for companies identified as service providers rather than merchants. All other PCI SAQ types apply specifically to merchants, not providers.

 

Compliance Considerations Beyond PCI DSS SAQ Types

The PCI SAQ types listed above are not the only compliance reporting documentation companies may need to submit. In total, there are three primary report types (including SAQs) that may apply:

For the ROC form, in particular, companies need to contract the services of an official Qualified Security Assessor (QSA), vetted by the PCI SSC. RSI Security carries QSA status and can assist in any element of the PCI compliance process—implementation through verification.

 

How Merchant Level Impacts the PCI Documentation Needed

A company’s PCI Merchant level is defined by the individual SSC stakeholder whose cards it primarily processes. For example, Visa’s PCI compliance guide categorizes merchants into their Levels based on the following criteria:

Individual stakeholders within the SSC Founding Members define merchant Levels differently, but the differences are negligible. Regardless of Level, documentation must account for all controls.

PCI DSS Requirements Reported Across All Documentation

The last critical consideration about SAQs and PCI documentation more broadly is what each form reports. Companies submit SAQs, AOCs, or ROCs to verify their implementation of:

 

Rethink Your PCI DSS Implementation and Compliance

Since most companies process credit card payments, PCI DSS compliance is widely applicable. And, since so many different types of companies need to comply, there are many different PCI DSS SAQ types to accommodate their wide-ranging payment technologies.

RSI Security helps companies of all industries and sizes with the entire PCI compliance processcontact us today to get started!

 

 

Exit mobile version