Choosing the Right Self-Assessment Questionnaire (SAQ) for Your Environment

self assessment questionnaire saq n.w
1 / 13
Embed
Share

Explore different types of Self-Assessment Questionnaires (SAQs) such as P2PE, Card Present, and Mail/Telephone Order (MOTO) to determine which one suits your unique business environment best. Understand the requirements and applicability of each SAQ variant to ensure PCI compliance and secure payment processing. Find the perfect SAQ for your specific setup and operations.

  • SAQ
  • PCI compliance
  • Payment security
  • Self-assessment
  • Choosing SAQ

Uploaded on | 0 Views


Download Presentation

Please find below an Image/Link to download the presentation.

The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author. If you encounter any issues during the download, it is possible that the publisher has removed the file from their server.

You are allowed to download the files provided on this website for personal or commercial use, subject to the condition that they are used lawfully. All files are the property of their respective owners.

The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author.

E N D

Presentation Transcript


  1. Self-Assessment Questionnaire (SAQ) Which one is right for my environment?

  2. Which SAQ??

  3. Point-to-Point Encrypted (P2PE) P2PE: Merchants using only hardware payment terminals that are included in and managed via a validated, PCI SSC-listed P2PE solution, with no electronic cardholder data storage Not applicable to e-commerce channels Find PCI DSS validated Point-to-Point Encryption Solutions at www.pcisecuritystandards.org

  4. Card Present

  5. Card Present SAQ B: Standalone dial out terminals with no electronic cardholder data storage (NO INTERNET) Not applicable to e-commerce channels SAQ B-IP: Merchants using only standalone, PTS-approved payment terminals with an IP connection to the payment processor, with no electronic cardholder data storage Not applicable to e-commerce channels

  6. Card Present SAQ C: Merchants with payment application systems connected to the Internet, no electronic cardholder data storage Not applicable to e-commerce channels SAQ C-VT: Merchants who manually enter a single transaction at a time via a keyboard into an Internet-based virtual terminal solution that is provided and hosted by a PCI-DSS validated third-party service provider, no electronic cardholder data storage Not applicable to e-commerce channels

  7. Mail/Telephone Order (MOTO)

  8. Mail/Telephone Order (MOTO) SAQ A: Card-Not-Present merchants that have fully outsourced all cardholder data functions to PCI DSS validated third-party service providers, with no electronic storage, processing, or transmission of any cardholder data on the merchant s systems or premises Not applicable to face-to-face channels SAQ B: Standalone dial out terminals with no electronic cardholder data storage (NO INTERNET) Not applicable to e-commerce channels

  9. Mail/Telephone Order (MOTO) SAQ C: Merchants with payment application systems connected to the Internet, no electronic cardholder data storage Not applicable to e-commerce channels SAQ C-VT: Merchants who manually enter a single transaction at a time via a keyboard into an Internet-based virtual terminal solution that is provided and hosted by a PCI-DSS validated third-party service provider, no electronic cardholder data storage Not applicable to e-commerce channels

  10. E-commerce

  11. E-commerce SAQ A: Card-Not-Present merchants that have fully outsourced all cardholder data functions to PCI DSS validated third-party service providers, with no electronic storage, processing, or transmission of any cardholder data on the merchant s systems or premises Not applicable to face-to-face channels

  12. E-commerce SAQ A-EP: E-commerce merchants who outsource all payment processing to PCI DSS validated third parties, and who have a website(s) that doesn t directly receive cardholder data but that can impact the security of the payment transaction. No electronic storage, processing, or transmission of any cardholder data on the merchant s systems or premises Applicable only to e-commerce channels SAQ D: All merchants not included in descriptions for the above SAQ types

  13. Questions If you have any questions or need assistance verifying the appropriate SAQ(s) for your payment card environment, please contact Cash and Credit Management Services (CCMS). Phone: 806-742-3271 Email: cash.credit.services@ttu.edu Information obtained from PCI DSS Self Assessment Questionnaire Instructions and Guidelines, v3.2 SAQ-InstrGuidelines-v3_2.pdf (pcisecuritystandards.org)

More Related Content