PCI DSS v3.2 SAQ B-IP, Rev. 1.1 January 2017
© 2006-2017 PCI Security Standards Council, LLC. All Rights Reserved. Page iii
Before You Begin
SAQ B-IP has been developed to address requirements applicable to merchants who process cardholder
data only via standalone, PTS-approved point-of-interaction (POI) devices with an IP connection to the
payment processor. An exception applies for POI devices classified as Secure Card Readers (SCR);
merchants using SCRs are not eligible for this SAQ.
SAQ B-IP merchants may be either brick-and-mortar (card-present) or mail/telephone-order (card-not-
present) merchants, and do not store cardholder data on any computer system.
SAQ B-IP merchants confirm that, for this payment channel:
Your company uses only standalone, PTS-approved point-of-interaction (POI) devices (excludes
SCRs) connected via IP to your payment processor to take your customers’ payment card
information;
The standalone IP-connected POI devices are validated to the PTS POI program as listed on the
PCI SSC website (excludes SCRs);
The standalone IP-connected POI devices are not connected to any other systems within your
environment (this can be achieved via network segmentation to isolate POI devices from other
systems)
;
The only transmission of cardholder data is from the PTS-approved POI devices to the payment
processor;
The POI device does not rely on any other device (e.g., computer, mobile phone, tablet, etc.) to
connect to the payment processor;
Any cardholder data your company retains is on paper (for example, printed reports or receipts),
and these documents are not received electronically; and
Your company does not store cardholder data in electronic format.
This SAQ is not applicable to e-commerce channels.
This shortened version of the SAQ includes questions that apply to a specific type of small merchant
environment, as defined in the above eligibility criteria. If there are PCI DSS requirements applicable to
your environment that are not covered in this SAQ, it may be an indication that this SAQ is not suitable for
your environment. Additionally, you must still comply with all applicable PCI DSS requirements in order to
be PCI DSS compliant.
PCI DSS Self-Assessment Completion Steps
1. Identify the applicable SAQ for your environment – refer to the Self-Assessment Questionnaire
Instructions and Guidelines document on PCI SSC website for information.
2. Confirm that your environment is properly scoped and meets the eligibility criteria for the SAQ you
are using (as defined in Part 2g of the Attestation of Compliance).
3. Assess your environment for compliance with applicable PCI DSS requirements.
4. Complete all sections of this document:
This criteria is not intended to prohibit more than one of the permitted system type (that is, IP-connected POI
devices) being on the same network zone, as long as the permitted systems are isolated from other types of systems
(e.g. by implementing network segmentation). Additionally, this criteria is not intended to prevent the defined system
type from being able to transmit transaction information to a third party for processing, such as an acquirer or
payment processor, over a network.