Scope Statement
A concise scope explanation listing networks, servers, and services in scope for PCI DSS, including any segmentation controls used to reduce scope.
A correctly completed SAQ documents control status, reduces breach risk, and supports your acquiring bank relationship while clarifying scope and remediation priorities.
Organizations preparing the SAQ usually combine IT, compliance, and business owners to ensure accuracy.
Final review is often consolidated by a compliance owner before submission to the acquirer or retained for audit.
The primary signatory often is the merchant compliance officer or a senior executive who can attest to the accuracy of the SAQ. That person signs to confirm organizational responsibility, has access to operational controls details, and can commit to remediation timelines when gaps are identified.
An acquiring bank compliance contact or delegated officer may countersign or accept the attestation on behalf of the acquirer. Their role is to validate that the SAQ type and scope align with processing model requirements and to escalate to card brands if additional validation is needed.
A concise scope explanation listing networks, servers, and services in scope for PCI DSS, including any segmentation controls used to reduce scope.
A mapping of applicable PCI DSS requirements to evidence items, showing which controls are implemented, partially implemented, or not applicable, with references to logs or configuration files.
An organized list of attachments and supporting documents such as firewall configs, vulnerability scan reports, and access control lists referenced by control item for rapid verification.
Where controls are incomplete, include an executive summary of remediation actions, owners, and target completion dates to show management oversight and risk reduction steps.
A signed attestation confirming the accuracy of the SAQ responses, the person responsible, and the date of the statement for legal and audit traceability.
Document version number, change history, and an audit trail showing who edited or signed the form to support forensic review and regulatory inquiries.
| Role Assignment | Assign preparer, reviewer, and approver roles |
|---|---|
| Field Requirements | Mark merchant ID, SAQ type, and signature fields mandatory |
| Conditional Logic | Show remediation fields only when controls are marked incomplete |
| Signer Authentication | Use email link plus optional SMS code or SSO |
| Evidence Attachment | Require file uploads with filename validation |
Ensure the chosen solution retains tamper-evident signed copies, provides searchable audit logs, and integrates with your document repository for retention and incident response.
Complete and attest annually or as required by acquirer
Reassess and update SAQ when processing model changes
Submit SAQ immediately if requested during onboarding or audit
Update SAQ and evidence as part of incident response
Attestation date begins the retention clock
Identify assets and boundaries included in the SAQ.
Gather system screenshots, logs, and reports supporting responses.
Implement fixes for gaps before final attestation.
Sign and deliver the SAQ to the acquirer or retain for audit.
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | Varies |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | Varies | Varies |
Tech Data centralized SAQ workflows using an integrated platform to reduce manual handoffs.
A healthcare provider combined PCI and HIPAA considerations when collecting payment data and patient consents.