PCI DSS v3.2 SAQ A, Rev. 1.1 January 2017
© 2006-2017 PCI Security Standards Council, LLC. All Rights Reserved. Page iii
Before You Begin
SAQ A has been developed to address requirements applicable to merchants whose cardholder data
functions are completely outsourced to validated third parties, where the merchant retains only paper
reports or receipts with cardholder data.
SAQ A merchants may be either e-commerce or mail/telephone-order merchants (card-not-present), and
do not store, process, or transmit any cardholder data in electronic format on their systems or premises.
SAQ A merchants confirm that, for this payment channel:
Your company accepts only card-not-present (e-commerce or mail/telephone-order) transactions;
All processing of cardholder data is entirely outsourced to PCI DSS validated third-party service
providers;
Your company does not electronically store, process, or transmit any cardholder data on your
systems or premises, but relies entirely on a third party(s) to handle all these functions;
Your company has confirmed that all third party(s) handling storage, processing, and/or
transmission of cardholder data are PCI DSS compliant; and
Any cardholder data your company retains is on paper (for example, printed reports or receipts),
and these documents are not received electronically.
Additionally, for e-commerce channels:
All elements of the payment page(s) delivered to the consumer’s browser originate only and directly
from a PCI DSS validated third-party service provider(s).
This SAQ is not applicable to face-to-face channels.
This shortened version of the SAQ includes questions that apply to a specific type of small merchant
environment, as defined in the above eligibility criteria. If there are PCI DSS requirements applicable to
your environment that are not covered in this SAQ, it may be an indication that this SAQ is not suitable for
your environment. Additionally, you must still comply with all applicable PCI DSS requirements in order to
be PCI DSS compliant.
Note: For this SAQ, PCI DSS Requirements that address the protection of computer systems (for
example, Requirements 2 and 8) apply to e-commerce merchants that redirect customers from their
website to a third party for payment processing, and specifically to the merchant webserver upon which
the redirection mechanism is located. Mail order/telephone order (MOTO) or e-commerce merchants that
have completely outsourced all operations (where there is no redirection mechanism from the merchant
to the third party) and therefore do not have any systems in scope for this SAQ, would consider these
requirements to be “not applicable.” Refer to guidance on the following pages for how to report
requirements that are not applicable.