Free Tool

Which SAQ are you?

Three questions. One answer.

Your PCI DSS validation type is an architecture fact, not a choice. Answer three questions and get the SAQ (or ROC) your payment flow implies — and what it actually costs you in requirements.

Your Validation Type

Frequently Asked
Is this selector authoritative?

It implements the standard SAQ-type logic for e-commerce merchants, but your acquirer or processor has the final word — confirm the result with them before self-assessing. Stripe, Adyen, and peers publish integration-to-SAQ mappings that should match this output.

Why does the capture method matter so much?

Because PCI scope follows cardholder data. A full redirect or processor-hosted iframe keeps card data off your systems entirely (SAQ A); a form your site serves puts your code in the attack path (SAQ A-EP); touching or storing data yourself invokes most of the standard (SAQ D). Same business, order-of-magnitude different obligations.

What if we process over six million transactions a year?

Level 1 merchants validate with a QSA-led Report on Compliance instead of any SAQ, regardless of integration type. The selector flags this — at that volume, architecture still matters, but self-assessment is off the table.