Self-Assessment Questionnaire (SAQ)

A self-assessment questionnaire (SAQ) is a structured set of questions organizations use to evaluate their compliance practices, identify gaps, and prepare for an upcoming audit or assessment.

What Is a Self-Assessment Questionnaire?

A self-assessment questionnaire helps an organization compare its current controls, processes, and security practices against the requirements of a specific compliance framework. It provides a structured way to understand where the organization meets requirements and where additional work may be needed. 

The SAQ should be aligned with the framework the organization is preparing for, as requirements differ between standards. For example, an organization preparing for SOC 2 may assess its practices against the applicable Trust Services Criteria: Security, Availability, Confidentiality, Processing Integrity, and Privacy. The results provide a clearer picture of the organization’s current compliance posture and help teams address gaps before the formal assessment begins.

How Does a Self-Assessment Questionnaire Work?

The self-assessment process helps organizations compare their existing controls and practices against the requirements of a compliance framework. While the exact questions and requirements vary by framework, most SAQs follow a similar process from defining scope through remediation.

1. Determine the scope

Start by identifying which systems, processes, data, teams, and locations fall within the scope of the assessment. This establishes the boundaries of the assessment and helps prevent unnecessary systems or processes from being included. 

2. Review applicable requirements

Determine which requirements or controls apply to the organization. This could include PCI DSS requirements for protecting cardholder data or the applicable Trust Services Criteria when preparing for SOC 2.

3. Complete the questionnaire

Review each question and assess whether the organization currently meets the requirement. Teams may need input from security, IT, engineering, HR, legal, and other departments to accurately evaluate existing processes and controls.

4. Collect supporting evidence

Gather documentation and evidence that demonstrates how requirements are being met. This may include policies, access records, security configurations, training records, risk assessments, and other compliance documentation.

5. Identify and remediate gaps

Any requirements that are not fully met should be documented and addressed. Remediation may involve implementing new controls, updating policies, improving processes, or collecting missing evidence before moving forward with a formal assessment or audit.

What Is a PCI SAQ?

A PCI Self-Assessment Questionnaire (SAQ) is a validation tool that eligible merchants and service providers use to assess and report their compliance with the PCI Data Security Standard (PCI DSS). It helps organizations evaluate how effectively they protect cardholder data and identify areas where their payment environment may not meet applicable PCI DSS requirements.

There are different PCI SAQs based on how an organization accepts payments and stores, processes, or transmits cardholder data. Selecting the correct questionnaire is important because each SAQ has specific eligibility criteria for different payment environments. Merchants should confirm the appropriate SAQ with their acquiring bank or payment brand.

What Are the Different PCI SAQ Types?

PCI DSS includes several SAQ types for different payment environments, each covering the relevant PCI DSS controls and requirements. The right SAQ depends on how an organization accepts payments, handles cardholder data, and connects its payment systems. Here are the different PCI SAQ types: 

SAQ A

SAQ A is for eligible card-not-present merchants, such as e-commerce or mail/telephone-order businesses, that outsource cardholder data functions to PCI DSS-compliant third-party service providers and do not electronically store, process, or transmit cardholder data on their own systems or premises.

SAQ A-EP

SAQ A-EP applies to eligible e-commerce merchants that outsource payment processing but operate a website that can affect payment security. This type of security questionnaire covers the PCI DSS requirements relevant to that environment, even though cardholder data is not stored, processed, or transmitted on the merchant’s systems. 

SAQ B and B-IP

SAQ B is intended for eligible merchants using imprint machines or standalone dial-out terminals without electronic cardholder data storage. SAQ B-IP covers eligible merchants using standalone, approved payment terminals with an IP connection to the payment processor and no electronic cardholder data storage.

SAQ C and C-VT

SAQ C applies to eligible merchants with internet-connected payment application systems that do not electronically store cardholder data. SAQ C-VT is designed for eligible merchants that manually enter individual transactions into a hosted, internet-based virtual terminal and do not electronically store cardholder data.

SAQ P2PE

SAQ P2PE is for eligible merchants using hardware payment terminals that are part of a validated, PCI SSC-listed Point-to-Point Encryption (P2PE) solution, without electronic cardholder data storage.

SAQ D

SAQ D for merchants applies to organizations that do not meet the eligibility criteria for the other merchant SAQ types. There is also a separate SAQ D for eligible service providers, which PCI SSC identifies as the only SAQ available to service providers.

Types of PCI SAQ

SAQ typePayment environmentKey requirement
SAQ AOutsourced e-commerce / card-not-presentNo electronic card data storage
SAQ A-EPE-commerce with outsourced paymentsWebsite can impact payment security
SAQ BImprint or dial-out terminalsNo electronic card data storage
SAQ B-IPIP-connected terminalsStandalone approved terminals
SAQ CInternet-connected payment applicationsNo electronic card data storage
SAQ C-VTHosted virtual terminalsTransactions entered manually
SAQ P2PEValidated P2PE solutionsUses PCI-listed P2PE solution
SAQ DOther merchants / service providersDoes not qualify for another SAQ
PCI SAQ types

AI-native GRC for how teams work today.

Scytale G2 badge

What Is a SOC 2 SAQ?

A SOC 2 self-assessment questionnaire (SAQ) helps organizations evaluate their controls against the applicable Trust Services Criteria (TSC) and identify gaps before beginning a formal SOC 2 audit. The process starts by defining the scope, including whether the organization is pursuing a Type I or Type II SOC 2 report and which Trust Services Criteria apply. Security is required for every SOC 2 audit, while Availability, Confidentiality, Processing Integrity, and Privacy are included based on the organization’s services, risks, and customer requirements.

A Type I report evaluates controls at a specific point in time, while a Type II evaluates their operating effectiveness over a defined period. Once the scope is established, the organization can create a relevant SOC 2 control list and assess each control against its existing processes, documentation, and evidence.

The assessment shows which requirements are already being met and where remediation is needed. These issues can then be addressed during the readiness phase, giving the organization a clearer understanding of its SOC 2 readiness and the work required before the formal audit begins. 

Streamline Self-Assessments With Scytale

Scytale brings controls, evidence, and compliance requirements into one platform, making it easier to assess readiness and identify gaps. Automated evidence collection and continuous monitoring help teams address those gaps, track remediation, and maintain audit readiness with less manual work, while dedicated GRC experts provide guidance throughout the process.