PCI Compliance and Payment Security
SAQ A Guide
Understanding SAQ A for PCI Compliance
The Self-Assessment Questionnaire A (SAQ A) is a key component for merchants seeking PCI compliance, especially those who outsource all cardholder data functions to validated third-party service providers. This guide will help you understand what SAQ A entails, who should complete it, and how it fits into your overall payment security strategy.
What is SAQ A?
SAQ A is designed for e-commerce or mail/telephone order merchants that do not electronically store, process, or transmit any cardholder data on their systems or premises. Instead, all payment processing is handled by PCI DSS compliant third parties. Completing SAQ A helps ensure that your business meets the necessary security requirements without managing sensitive data directly.
Who Should Complete SAQ A?
Merchants eligible for SAQ A typically meet these criteria:
- Outsource all cardholder data functions to PCI DSS validated third-party service providers
- Do not electronically store, process, or transmit cardholder data on their systems or premises
- Use only web-based payment portals or mail/telephone order channels for transactions
- Have no electronic cardholder data storage
Practical Next Steps for SAQ A Compliance
To maintain PCI compliance with SAQ A, start by reviewing your payment processing setup to confirm eligibility. Ensure your third-party providers are PCI DSS compliant and document your security policies accordingly. Consider scanning your merchant processing fee statements in PDF format with Merchant Statement Scanner to analyze fees and identify potential savings, complementing your compliance efforts with cost optimization.
Filing the SAQ A annually and staying updated on PCI DSS requirements will help protect your business and your customers’ payment data effectively.
Related guides in this hub
Verify this against your real statement
Upload a PDF merchant statement to see fees, categories, and effective rate.

