Establishing secure connection…Loading editor…Preparing document…

PCI-DSS SAQ Compliance Form

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

PCI-DSS SAQ Compliance Attestation

Merchant / Entity Information

Assessment Date:   Assessment Type:

SAQ Selection and Scope

Select applicable SAQ type(s):

Card Acceptance Channels

Indicate channels where cardholder data is accepted (check all that apply):

Third-Party Providers and Outsourcing

Service providers validated by provider attestation or QSA:

Assessment Results — Controls Review

For each applicable PCI requirement, indicate compliance, reference evidence, and provide comments. If a requirement is not applicable, mark "NA" and provide justification.

Requirement 1

Requirement Number:   Description:

Compliance:

Evidence Reference:

Requirement 2

Requirement Number:   Description:

Compliance:

Evidence Reference:

Requirement 3

Requirement Number:   Description:

Compliance:

Evidence Reference:

Requirement 4

Requirement Number:   Description:

Compliance:

Evidence Reference:

Requirement 5

Requirement Number:   Description:

Compliance:

Evidence Reference:

Requirement 6

Requirement Number:   Description:

Compliance:

Evidence Reference:

Non-Compliance Summary and Remediation

Evidence and Supporting Documentation

Retention of Records: Records supporting this attestation will be retained by the Merchant for a minimum period consistent with card brand requirements and made available to acquirers or payment brands upon lawful request. A copy of this attestation and associated evidence will be retained at:

Attestation Statement

The undersigned certifies, under penalty of perjury and corporate responsibility, that the information provided in this Self-Assessment Questionnaire and the associated supporting documentation is true, accurate, and complete to the best of their knowledge. The undersigned further attests that the cardholder data environment described above is a complete and accurate representation of systems and processes in scope for the selected SAQ type(s).

The undersigned acknowledges that deliberate misrepresentation of the state of compliance may expose the Merchant to liability, including but not limited to fines, assessment of forensic costs, suspension of payment acceptance privileges, and other remedies available to card brands and acquirers. The undersigned agrees to notify the acquiring bank and applicable payment brands of material changes to scope or controls that would affect the accuracy of this attestation.

By signing below, the authorized signatory certifies they are expressly authorized to make this attestation on behalf of the Merchant and that they understand the attestations contained herein.

Merchant Representative (Print Name):

Title:

Signature:

Date:

Enter text

What the PCI-DSS SAQ Compliance Form Is and When it Applies

The PCI-DSS SAQ Compliance Form is a merchant self-assessment questionnaire used to document how an organization meets applicable Payment Card Industry Data Security Standard (PCI DSS) requirements. SAQs exist in multiple types (A, A-EP, B, B-IP, C-VT, C, D) to match merchant processing models and scope. Completing the correct SAQ demonstrates control implementation for cardholder data environment scoping, identifies gaps, and creates an attestation of compliance for the acquiring bank or card brands. The SAQ is an attestation tool, not a replacement for required technical remediation or third-party assessments where a QSA is mandated.

Why Completing a Proper PCI-DSS SAQ Matters

A correctly completed SAQ documents control status, reduces breach risk, and supports your acquiring bank relationship while clarifying scope and remediation priorities.

Why Completing a Proper PCI-DSS SAQ Matters

Who Typically Prepares and Reviews the SAQ

Organizations preparing the SAQ usually combine IT, compliance, and business owners to ensure accuracy.

  • Merchant Security Lead: Coordinates evidence collection and maps systems in scope for PCI controls.
  • IT/System Administrator: Provides technical answers about network segmentation, encryption, and logging.
  • Acquiring Bank Representative: Reviews attestation results and may request remediation or additional evidence.

Final review is often consolidated by a compliance owner before submission to the acquirer or retained for audit.

Primary Signatories and Their Roles

Merchant Compliance Officer

The primary signatory often is the merchant compliance officer or a senior executive who can attest to the accuracy of the SAQ. That person signs to confirm organizational responsibility, has access to operational controls details, and can commit to remediation timelines when gaps are identified.

Acquirer Compliance Contact

An acquiring bank compliance contact or delegated officer may countersign or accept the attestation on behalf of the acquirer. Their role is to validate that the SAQ type and scope align with processing model requirements and to escalate to card brands if additional validation is needed.

Required Information Typically Captured on the SAQ

Merchant ID: Acquirer-provided merchant identifier
SAQ Type: Select A, A-EP, B, C, D, etc.
Contact Details: Name, email, phone
Processing Model: Card-present, e-commerce, redirect
Scope Summary: Systems and network segments in-scope
Attestation Date: MM/DD/YYYY

Sequential Checklist: Filling the PCI-DSS SAQ

Follow these steps in order to gather evidence and complete the SAQ accurately.

  • 01
    Choose SAQ Type: Identify the SAQ that matches your card processing method and third-party controls.
  • 02
    Define Scope: List systems, networks, and services that store, process, or transmit cardholder data.
  • 03
    Collect Evidence: Gather logs, configs, policies, and screenshots supporting each affirmative response.
  • 04
    Attest and Retain: Sign the attestation, provide it to your acquirer if requested, and retain records.

Where the Completed SAQ Typically Goes

After completion, the SAQ is either submitted to your acquiring bank, stored for internal audit, or attached to merchant onboarding records.

  • Acquiring Bank Submission: Provide signed SAQ and evidence to your acquirer when requested for merchant validation.
  • Internal Retention: Store attestation and supporting evidence in secure records for audit and remediation tracking.
  • Third-Party Assessors: If required, share SAQ and evidence with a QSA for formal validation and reporting.
  • Card Brand Reporting: If acquirer or card brand requires, forward attestation or follow specific brand submission processes.

Core Components of a Professional PCI-DSS SAQ Compliance Form

A professional SAQ package organizes attestations, evidence, and signatory details so reviewers can verify control implementation efficiently.

Scope Statement

A concise scope explanation listing networks, servers, and services in scope for PCI DSS, including any segmentation controls used to reduce scope.

Control Checklist

A mapping of applicable PCI DSS requirements to evidence items, showing which controls are implemented, partially implemented, or not applicable, with references to logs or configuration files.

Evidence Index

An organized list of attachments and supporting documents such as firewall configs, vulnerability scan reports, and access control lists referenced by control item for rapid verification.

Remediation Plan

Where controls are incomplete, include an executive summary of remediation actions, owners, and target completion dates to show management oversight and risk reduction steps.

Attestation Statement

A signed attestation confirming the accuracy of the SAQ responses, the person responsible, and the date of the statement for legal and audit traceability.

Versioning and Audit Trail

Document version number, change history, and an audit trail showing who edited or signed the form to support forensic review and regulatory inquiries.

Configuring an Online SAQ Workflow

Set up roles, required fields, and authentication to preserve auditability and reduce signer friction.

Role Assignment Assign preparer, reviewer, and approver roles
Field Requirements Mark merchant ID, SAQ type, and signature fields mandatory
Conditional Logic Show remediation fields only when controls are marked incomplete
Signer Authentication Use email link plus optional SMS code or SSO
Evidence Attachment Require file uploads with filename validation

Technical Considerations for Digital Signing and Evidence Storage

Ensure the chosen solution retains tamper-evident signed copies, provides searchable audit logs, and integrates with your document repository for retention and incident response.

  • File Formats: PDF, DOCX, or image attachments supported
  • Integrations: Connectors for NetSuite, Salesforce, and Google Workspace
  • Authentication: Email link with optional SMS or SSO

Timing and Submission Expectations for the SAQ

SAQ completion cadence is determined by your acquirer and card brand; many merchants complete SAQs annually or upon material changes.

Annual Attestation:

Complete and attest annually or as required by acquirer

After System Changes:

Reassess and update SAQ when processing model changes

On Acquirer Request:

Submit SAQ immediately if requested during onboarding or audit

Following a Breach:

Update SAQ and evidence as part of incident response

Retention Start Date:

Attestation date begins the retention clock

Key Milestones in the SAQ Process

Track these sequential milestones from scoping through final attestation to ensure compliance deadlines are met.

01

Scope Determination

Identify assets and boundaries included in the SAQ.

02

Evidence Collection

Gather system screenshots, logs, and reports supporting responses.

03

Remediation Actions

Implement fixes for gaps before final attestation.

04

Final Attestation

Sign and deliver the SAQ to the acquirer or retain for audit.

Common Pitfalls to Avoid When Preparing the SAQ

  • Selecting the wrong SAQ type and failing to include all in-scope systems leads to incomplete attestations and follow-up validation.
  • Providing affirmative answers without linking verifiable evidence such as logs or scans creates audit findings and delays acceptance.
  • Assuming third-party PCI compliance covers your scope; you must document how the third party isolates or processes cardholder data for your environment.
  • Using inconsistent naming for assets or merchant IDs across evidence and the SAQ complicates review and may trigger requests for clarification.

Consequences of an Incorrect or Incomplete SAQ

Acquirer Sanctions: Fines or increased monitoring by the acquiring bank
Card Brand Fines: Card brands can impose penalties for noncompliance
Expanded Scope: Failed attestations may force full-scope assessments
Breach Exposure: Incomplete controls increase breach risk
Higher Fees: Insurance or reserve requirements may rise
Reputational Harm: Customer trust erosion after publicized incidents

eSignature Pricing and Feature Comparison for SAQ Workflows

Compare starting prices and essential capabilities across vendors commonly used to collect signed SAQs and supporting evidence.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes Varies
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes Varies Varies

Real-World Examples of SAQ Usage and Outcomes

These brief examples illustrate how organizations used digital workflows to complete SAQs and document controls.

Tech Data — Enterprise Integration

Tech Data centralized SAQ workflows using an integrated platform to reduce manual handoffs.

  • The integration cut approval cycles.
  • The result was improved internal control visibility and faster acceptance by the acquirer, helping the company scale merchant onboarding without adding headcount.

Fertility Centers of Illinois — Healthcare Context

A healthcare provider combined PCI and HIPAA considerations when collecting payment data and patient consents.

  • They implemented a BAA for eSignature services.
  • This approach preserved patient privacy, ensured evidence retention under HIPAA, and simplified annual attestations for the finance and compliance teams.

Practical Tips for Efficient and Accurate SAQ Completion

Apply these practices to reduce errors, speed reviews, and maintain reliable records.

Standardize Evidence Names
Use consistent file naming conventions and an evidence index that references each SAQ question; this reduces reviewer confusion and prevents repeated requests for the same artifact during a compliance check.
Use Conditional Fields
Configure conditional fields to show remediation inputs only when controls are marked incomplete, reducing form noise and focusing reviewer attention on outstanding issues.
Authenticate Signers Appropriately
Match signer authentication strength to risk: use basic email links for internal attestations, and add SMS or SSO for external or legally sensitive signers to strengthen attribution.
Map Third-Party Attestations
When third-party providers process cardholder data, attach their AOC or attestation and explicitly document how the provider reduces your scope to avoid gaps in your SAQ responses.

Frequently Asked Questions About the PCI-DSS SAQ Compliance Form

Answers to common questions about SAQ selection, e-signing, evidence retention, and legal validity.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users