Secure Payments, PCI DSS, Regulatory Compliance Blog

Self-Assessment Questionnaire (SAQ) v1.1 Released

February 6th, 2008 by admin Posted in Merchant, PCI DSS, PCI SSC

pcico.gifThe PCI SSC released version 1.1 of the Self-Assessment Questionnaire and it shows the migration from the current eight page document to one that is more in-line with the Security Audit Procedures. In addition the SSC released several companion documents including:

This brings all PCI DSS validation documents in-line with a consistent 1.1 version. Though, now there are 4 different SAQ documents that will apply to different merchants depending on their operational environment. The documents: A, B, C, and D will apply in the following manner:

  • SAQ Validation Type 1 / SAQ A: Card-not-present, All Cardholder Data Functions Outsourced
  • SAQ Validation Type 2 / SAQ B: Imprint Merchant Only, No Electronic Cardholder Data Storage
  • SAQ Validation Type 3 / SAQ B: Standalone, Dial-out Terminal Merchant, no Electronic Cardholder Data Storage
  • SAQ Validation Type 4 / SAQ C: Merchants with Payment Application Systems Connected to the Internet
  • SAQ Validation Type 5 / SAQ D: All Other Merchants and All Service Providers Defined by a Payment Brand as Eligible to Complete an SAQ

Seem a bit confusing? That’s why there exists the instructions and guidelines document. There is one interesting thing you will find in here - page 9 states that compensating controls only apply to SAQ D.

The different SAQ documents vary in length with SAQ A having only 11 questions, SAQ B having 21 questions, SAQ C having 38 questions, all the way up to SAQ 4 with 226 questions.

One of the questions in the FAQ asks: What is the sunset date for the Self-Assessment Questionnaire version 1.0?

The PCI Data Security Standard Self-Assessment Questionnaire (SAQ) version 1.1 was released by the Council on February 6, 2008. Any SAQ submissions after April 30, 2008 must be completed using SAQ version 1.1.Please note an entity must be compliant with the PCI Data Security Standard in its entirety. The questions in the SAQ version 1.0 do not cover all of the PCI DSS requirements. As such, an organization that is only compliant with the questions in SAQ version 1.0 in not considered to be compliant with PCI DSS based on the SAQ alone. The organization must verify that it adheres to all of the requirements stipulated in the PCI DSS.

There is a lot of new information so read each of the documents carefully and make sure you understand things before proceeding. As always, you can post and ask questions in our online forum.

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]
  1. 8 Responses to “Self-Assessment Questionnaire (SAQ) v1.1 Released”

  2. By Maciej Lewandowsk on Feb 7, 2008

    This is great stuff -you are doing the community a good service by tracking these developments - you should take a look at a great free software package for PCI DSS 1.1 SAQ - called Practical Threat Analysis PTA for PCI - I think they are an Israeli company at this link here -http://www.opensolutions.co.il/content/blogcategory/18/35/

    Best regards
    Maciej

  3. By Andy Willingham on Feb 7, 2008

    have the actual questionnaires themselves been released or just the prerelease of the release? :) I can’t find the SAQ’s themselves.

  4. By Michael Dahn on Feb 7, 2008

    They are linked from here:
    https://www.pcisecuritystandards.org/tech/instructions.htm

  5. By Mark Lucas on Feb 27, 2008

    Has anyone heard any guidance on how to handle merchants that fall *neatly* into multiple merchant types (except for Type 2 and Type 3)? Is the expectation that if a merchant is of type 1, 2, and 3 then they should answer SAQ D? The official SAQ documentation doesn’t seem to handle this type of situation very well; but then, I can’t imagine such a merchant having to answer all 226 questions within the SAQ D.

  1. 4 Trackback(s)

  2. Feb 6, 2008: PCI Blog - Compliance Demystified » Blog Archive » Downtime at the worst of times
  3. Feb 6, 2008: PCI Blog - Compliance Demystified » Blog Archive » PCI SSC publishes PIN Entry Devices (PED) standards
  4. Feb 7, 2008: PCI Council releases new Guidance & SAQs!! « Payment Card Security & IT Controls Explained
  5. Nov 3, 2008: PCI Blog - Compliance Demystified » Blog Archive » E-Commerce Startups deal with PCI compliance

Sorry, comments for this entry are closed at this time.