Frequently Asked Question
Can SAQ eligibility criteria be used for determining applicability of PCI DSS requirements for assessments documented in a Report on Compliance?
Service providers cannot use SAQ eligibility criteria to determine applicability of PCI DSS requirements for assessments documented in a Report on Compliance (ROC). The only acceptable SAQ for service providers is SAQ D for Service Providers. All other SAQs are intended for merchant use only.
Merchants with environments that fully meet all the eligibility criteria defined in a particular SAQ may use that SAQ as a reference to identify the applicable PCI DSS requirements for that environment. This approach must be clearly documented in "Description of Scope of Work and Approach Taken" section of the ROC.
For PCI DSS v3.2.1, this includes the following:
- Identify the eligibility criteria for the applicable SAQ,
- For each criteria, document how the assessor verified that the merchant environment meets the criteria.
For PCI DSS v4.0, this approach is documented as specified in ROC Section 3.1.
Even if a merchant uses SAQ eligibility criteria to determine applicable PCI DSS requirements for an assessment documented in a ROC, the merchant is still expected to include PCI DSS Requirement 12.5.2 to document and confirm their PCI DSS scope at least once every 12 months. The merchant’s assessor is expected to include an assessment of Requirement 12.5.2 and document results the merchant’s ROC. See PCI DSS v4.x “Annual PCI DSS Scope Confirmation” for more details.
The assessor will need to perform appropriate testing and validation to verify the non-applicability of any PCI DSS requirements. As an example: If an e-commerce merchant has a webserver using a URL redirect to a PCI DSS compliant third-party payment processor, the assessor will need to verify that the merchant environment, including redirection method and the configuration of the webserver, meets all the eligibility criteria for SAQ A before they can consider using that SAQ for guidance. This would include verifying that the merchant accepts only card-not-present transactions, does not electronically store, process, or transmit any account data on its systems or premises, that all processing of account data is entirely outsourced to PCI DSS validated third-party service providers, and that all the other eligibility criteria for SAQ A are met.
Any PCI DSS requirements verified by the assessor to be not applicable should be reported as "Not Applicable" in accordance with instructions in the Report on Compliance (ROC) Template. Assessors should refer to the ROC Template and ROC Template FAQs for the version of the standard being used for relevant guidance.
If an environment meets some but not all eligibility criteria for a particular SAQ, then the SAQ should not be considered a relevant guide for applicability of requirements.
Merchants and service providers should always consult with the organizations that manage compliance programs (for example, payment brands and acquirers) to confirm their PCI DSS validation and reporting method. If a detailed assessment and ROC is the appropriate method, merchants meeting the eligibility criteria from an SAQ should also confirm that the approach outlined above is acceptable. Contact information for the payment brands can be found in FAQ #1142 How do I contact the payment card brands?
Related
-
When should an entity implement PCI DSS requirements noted as best practices until a future date?
-
For PCI DSS, can multi-factor authentication (MFA) implementations indicate the success of a factor prior to presentation of subsequent factors?
-
What is the completion date for PCI DSS assessments documented in a Report on Compliance and its related Attestations of Compliance?
Featured FAQ Articles
Featured
-
Do PCI DSS requirements for keyed cryptographic hashing apply to previously hashed PANs?
-
Is the PCI DSS Attestation of Compliance intended to be shared?
-
How does an entity report the results of a PCI DSS assessment for new requirements that are noted in PCI DSS as best practices until a future date?
-
Where do I direct questions about complying with PCI standards?
-
Can SAQ eligibility criteria be used for determining applicability of PCI DSS requirements for assessments documented in a Report on Compliance?
Most Popular
-
When should an entity implement PCI DSS requirements noted as best practices until a future date?
-
For PCI DSS, can multi-factor authentication (MFA) implementations indicate the success of a factor prior to presentation of subsequent factors?
-
What is the completion date for PCI DSS assessments documented in a Report on Compliance and its related Attestations of Compliance?
-
What is the completion date for PCI DSS assessments documented in a Self-Assessment Questionnaire and its related Attestations of Compliance?
-
How does PCI DSS Requirement 6.4.3 apply to 3DS scripts called from a merchant check-out page as part of 3DS processing?
Most Recently Updated
-
How are third-party service providers (TPSPs) expected to demonstrate PCI DSS compliance for TPSP services that meet customers’ PCI DSS requirements or may impact the security of a customer’s cardholder data and/or sensitive authentication data?
-
Can SAQ eligibility criteria be used for determining applicability of PCI DSS requirements for assessments documented in a Report on Compliance?
-
What should an entity do if its PCI DSS assessment will not be complete prior to that standard's retirement date?
-
Where can I find the current version of PCI DSS?
-
When should an entity implement PCI DSS requirements noted as best practices until a future date?