[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-167510-en":3,"doc-seo-167510-105":30,"detail-sidebar-cat-1-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":11,"category_id":12,"category_name":13,"doc_title":14,"doc_description":15,"doc_content":16,"file_id":17,"file_url":18,"file_type":19,"file_size":20,"view_count":4,"is_deleted":4,"is_public":11,"is_downloadable":11,"audit_status":11,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":15,"update_tm":28,"read_time":29},167510,1099523885336,"Taylor Morgan","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",1,17,"Forms","Payment Card Industry Data Security Standard - SAQ A - Self-Assessment Questionnaire and Attestation of Compliance","Payment Card Industry Data Security Standard (PCI DSS) Self-Assessment Questionnaire A and Attestation of Compliance for PCI DSS Version 4.0, published in April 2022, provides guidance to complete SAQ A for eligible merchants. It defines eligibility criteria, including merchants with account data functions fully outsourced to PCI DSS validated third parties, no electronic storage or transmission of account data, and no face-to-face channel scope. The questionnaire covers assessment information, requirement responses across relevant PCI DSS areas, and validation/attestation details.","Payment Card Industry \u000bData Security Standard\nSelf-Assessment Questionnaire A and \u000bAttestation of Compliance\nFor use with PCI DSS Version 4.0\nPublication Date: April 2022\nDocument Changes\n\u000f\nContents\n\u0013 TOC \\o \"1-3\" \\h \\z \u0014\u0013 HYPERLINK \\l \"_Toc100754522\" \u0014Document Changes\t\u0013 PAGEREF _Toc100754522 \\h \u0014i\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754523\" \u0014Completing the Self-Assessment Questionnaire\t\u0013 PAGEREF _Toc100754523 \\h \u0014iii\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754524\" \u0014Merchant Eligibility Criteria for Self-Assessment Questionnaire A\t\u0013 PAGEREF _Toc100754524 \\h \u0014iii\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754525\" \u0014Defining Account Data, Cardholder Data, and Sensitive Authentication Data\t\u0013 PAGEREF _Toc100754525 \\h \u0014iv\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754526\" \u0014PCI DSS Self-Assessment Completion Steps\t\u0013 PAGEREF _Toc100754526 \\h \u0014iv\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754527\" \u0014Expected Testing\t\t\u0013 PAGEREF _Toc100754527 \\h \u0014iv\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754528\" \u0014Requirement Responses\t\u0013 PAGEREF _Toc100754528 \\h \u0014v\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754529\" \u0014Additional PCI SSC Resources\t\u0013 PAGEREF _Toc100754529 \\h \u0014vii\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754530\" \u0014Section 1:\tAssessment Information\t\u0013 PAGEREF _Toc100754530 \\h \u00141\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754531\" \u0014Section 2:\tSelf-Assessment Questionnaire A\t\u0013 PAGEREF _Toc100754531 \\h \u00142\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754532\" \u0014Build and Maintain a Secure Network and Systems\t\u0013 PAGEREF _Toc100754532 \\h \u00142\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754533\" \u0014Requirement 2: Apply Secure Configurations to All System Components\t\u0013 PAGEREF _Toc100754533 \\h \u00142\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754534\" \u0014Protect Account Data\t\u0013 PAGEREF _Toc100754534 \\h \u00143\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754535\" \u0014Requirement 3: Protect Stored Account Data\t\u0013 PAGEREF _Toc100754535 \\h \u00143\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754536\" \u0014Maintain a Vulnerability Management Program\t\u0013 PAGEREF _Toc100754536 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754537\" \u0014Requirement 6: Develop and Maintain Secure Systems and Software\t\u0013 PAGEREF _Toc100754537 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754538\" \u0014Implement Strong Access Control Measures\t\u0013 PAGEREF _Toc100754538 \\h \u00148\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754539\" \u0014Requirement 8: Identify Users and Authenticate Access to System Components\t\u0013 PAGEREF _Toc100754539 \\h \u00148\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754540\" \u0014Requirement 9: Restrict Physical Access to Cardholder Data\t\u0013 PAGEREF _Toc100754540 \\h \u001412\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754541\" \u0014Requirement 11: Test Security of Systems and Networks Regularly\t\u0013 PAGEREF _Toc100754541 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754542\" \u0014Maintain an Information Security Policy\t\u0013 PAGEREF _Toc100754542 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754543\" \u0014Requirement 12: Support Information Security with Organizational Policies and Programs\t\u0013 PAGEREF _Toc100754543 \\h \u001417\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754544\" \u0014Appendix A:\tAdditional PCI DSS Requirements\t\u0013 PAGEREF _Toc100754544 \\h \u001421\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754545\" \u0014Appendix A1: \tAdditional PCI DSS Requirements for Multi-Tenant Service Providers\t\u0013 PAGEREF _Toc100754545 \\h \u001421\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754546\" \u0014Appendix A2: \tAdditional PCI DSS Requirements for Entities using SSL/early TLS \u000bfor Card-Present POS POI Terminal Connections\t\u0013 PAGEREF _Toc100754546 \\h \u001421\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754547\" \u0014Appendix A3: \tDesignated Entities Supplemental Validation (DESV)\t\u0013 PAGEREF _Toc100754547 \\h \u001421\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754548\" \u0014Appendix B:\tCompensating Controls Worksheet\t\u0013 PAGEREF _Toc100754548 \\h \u001422\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754549\" \u0014Appendix C:\tExplanation of Requirements Noted as In Place with Remediation\t\u0013 PAGEREF _Toc100754549 \\h \u001423\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754550\" \u0014Appendix D:\tExplanation of Requirements Noted as Not Applicable\t\u0013 PAGEREF _Toc100754550 \\h \u001424\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754551\" \u0014Appendix E:\tExplanation of Requirements Noted as Not Tested\t\u0013 PAGEREF _Toc100754551 \\h \u001425\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc100754552\" \u0014Section 3:\tValidation and Attestation Details\t\u0013 PAGEREF _Toc100754552 \\h \u001426\u0015\u0015\n\u0015\nCompleting the Self-Assessment Questionnaire\nMerchant Eligibility Criteria for Self-Assessment Questionnaire A\nSelf-Assessm","cbCaiaV3OshrtHMk","https://ap.wps.com/l/cbCaiaV3OshrtHMk","docx",430061,40,"English","en",105,"# Document Changes\n# Completing the Self-Assessment Questionnaire\n## Merchant Eligibility Criteria for Self-Assessment Questionnaire A\n## Defining Account Data and Sensitive Authentication Data\n## PCI DSS Self-Assessment Completion Steps\n## Expected Testing\n## Requirement Responses\n## Additional PCI SSC Resources\n# Section 1: Assessment Information\n# Section 2: Self-Assessment Questionnaire A\n## Build and Maintain a Secure Network and Systems\n## Requirement 2: Apply Secure Configurations to All System Components\n## Protect Account Data\n## Requirement 3: Protect Stored Account Data\n## Maintain a Vulnerability Management Program\n## Requirement 6: Develop and Maintain Secure Systems and Software\n## Implement Strong Access Control Measures\n## Requirement 8: Identify Users and Authenticate Access to System Components\n## Requirement 9: Restrict Physical Access to Cardholder Data\n## Requirement 11: Test Security of Systems and Networks Regularly\n## Maintain an Information Security Policy\n## Requirement 12: Support Information Security with Organizational Policies and Programs\n# Appendix A: Additional PCI DSS Requirements\n# Appendix B: Compensating Controls Worksheet\n# Appendix C: Explanation of Requirements Noted as In Place with Remediation\n# Appendix D: Explanation of Requirements Noted as Not Applicable\n# Appendix E: Explanation of Requirements Noted as Not Tested\n# Section 3: Validation and Attestation Details","[{\"question\":\"What type of merchant is eligible to use SAQ A?\",\"answer\":\"SAQ A applies to merchants whose account data functions are completely outsourced to PCI DSS validated and compliant third parties, where the merchant retains only paper reports or receipts with account data.\"},{\"question\":\"Which payment channels are excluded from SAQ A?\",\"answer\":\"SAQ A is not applicable to face-to-face channels, and it is not applicable to service providers.\"},{\"question\":\"What responsibilities does the merchant confirm for its payment channel in SAQ A?\",\"answer\":\"The merchant confirms it accepts only card-not-present transactions, that all account data processing is outsourced to a PCI DSS compliant TPSP/payment processor, that no account data is electronically stored/processed/transmitted on merchant systems, and that any retained account data is paper-based.\"}]","Payment Card Industry Data Security Standard - SAQ A - Self-Assessment Questionnaire and Attestation of Compliance | DOCX",1788215148,14,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":14,"keywords":34,"description":15,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"payment-card-industry-data-security-standard-saq-a-self-assessment-questionnaire-and-attestation-of-compliance","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":11},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/template/","Template",2,{"item":49,"name":13,"@type":43,"position":50},"https://docshare.wps.com/template/forms/",3,{"item":52,"name":14,"@type":43,"position":53},"https://docshare.wps.com/template/payment-card-industry-data-security-standard-saq-a-self-assessment-questionnaire-and-attestation-of-compliance/167510/",4,{"url":52,"name":14,"@type":55,"author":56,"headline":14,"publisher":58,"fileFormat":61,"inLanguage":23,"description":15,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-04","2026-08-31",true,{"@type":66,"interactionType":67,"userInteractionCount":47},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What type of merchant is eligible to use SAQ A?","Question",{"text":76,"@type":77},"SAQ A applies to merchants whose account data functions are completely outsourced to PCI DSS validated and compliant third parties, where the merchant retains only paper reports or receipts with account data.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"Which payment channels are excluded from SAQ A?",{"text":81,"@type":77},"SAQ A is not applicable to face-to-face channels, and it is not applicable to service providers.",{"name":83,"@type":74,"acceptedAnswer":84},"What responsibilities does the merchant confirm for its payment channel in SAQ A?",{"text":85,"@type":77},"The merchant confirms it accepts only card-not-present transactions, that all account data processing is outsourced to a PCI DSS compliant TPSP/payment processor, that no account data is electronically stored/processed/transmitted on merchant systems, and that any retained account data is paper-based.","https://schema.org",{"og:url":52,"og:type":88,"og:title":14,"og:site_name":59,"og:description":15},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,99,104,108,113,118,120,125,130],{"id":95,"doc_module":11,"doc_module_name":46,"category_name":96,"show_sort_weight":97,"slug":98},11,"Presentations",90,"presentations",{"id":100,"doc_module":11,"doc_module_name":46,"category_name":101,"show_sort_weight":102,"slug":103},12,"Resumes",80,"resumes",{"id":29,"doc_module":11,"doc_module_name":46,"category_name":105,"show_sort_weight":106,"slug":107},"Invoices",70,"invoices",{"id":109,"doc_module":11,"doc_module_name":46,"category_name":110,"show_sort_weight":111,"slug":112},15,"Posters",60,"posters",{"id":114,"doc_module":11,"doc_module_name":46,"category_name":115,"show_sort_weight":116,"slug":117},16,"Social Media",50,"social-media",{"id":12,"doc_module":11,"doc_module_name":46,"category_name":13,"show_sort_weight":21,"slug":119},"forms",{"id":121,"doc_module":11,"doc_module_name":46,"category_name":122,"show_sort_weight":123,"slug":124},18,"Letters",30,"letters",{"id":126,"doc_module":11,"doc_module_name":46,"category_name":127,"show_sort_weight":128,"slug":129},21,"Paper Templates",5,"papers-templates",{"id":131,"doc_module":11,"doc_module_name":46,"category_name":132,"show_sort_weight":4,"slug":133},158,"General","general-158"]