PCI Compliance and Payment Security
SAQ A-EP Guide
Understanding SAQ A-EP for PCI Compliance
The Self-Assessment Questionnaire A-EP (SAQ A-EP) is a crucial tool for e-commerce merchants who handle payment card data but do not store it electronically. This guide helps you understand the requirements of SAQ A-EP, how it fits into PCI compliance, and practical steps to maintain payment security.
Who Should Use SAQ A-EP?
SAQ A-EP is designed for merchants with e-commerce websites that outsource payment processing to third-party service providers but still have a website that impacts the security of the payment transaction. If your site does not store cardholder data but controls how payment data is transmitted, SAQ A-EP applies.
Key Requirements of SAQ A-EP
- Maintain a secure network and systems to protect cardholder data.
- Implement strong access control measures and authentication.
- Regularly monitor and test networks for vulnerabilities.
- Ensure your e-commerce website does not store cardholder data.
- Use secure coding practices to prevent common web vulnerabilities.
Meeting these requirements helps reduce the risk of data breaches and ensures your business complies with PCI DSS standards.
Next Steps to Achieve SAQ A-EP Compliance
Start by evaluating your website and payment processes to confirm if SAQ A-EP applies. Use tools like Merchant Statement Scanner to analyze your merchant processing fees and identify any potential compliance gaps. Optionally, you can scan a PDF copy of your merchant statement to gain deeper insights into your payment processing costs.
Work with your payment processor and IT team to implement the necessary security controls. Regularly review and update your security measures to stay compliant and protect your customers’ payment data.
Related guides in this hub
Verify this against your real statement
Upload a PDF merchant statement to see fees, categories, and effective rate.

