Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
All Tools

PCI DSS SAQ Finder

Answer a few questions about how your business handles payment card data and find out which PCI DSS v4.0.1 Self-Assessment Questionnaire applies to you, and what it requires.

What this SAQ generally requires

    This is a directional guide, not a final determination. The correct SAQ depends on the exact way cardholder data is stored, processed, and transmitted across every channel you use, and your acquiring bank has the final say. Merchant level, set by annual transaction volume, also determines whether an SAQ is sufficient or whether a Report on Compliance by a Qualified Security Assessor is required. If you use more than one acceptance channel, you may need to cover multiple SAQs or complete SAQ D. Always confirm with your acquirer or a QSA before validating. For SaaS businesses reducing PCI scope end to end, see our PCI DSS compliance for SaaS page.

    Questions

    What is a PCI DSS SAQ?

    A Self-Assessment Questionnaire is a validation tool that eligible merchants and service providers use to self-assess PCI DSS compliance. Which SAQ you complete depends on how you accept and handle cardholder data. The main types are A, A-EP, B, B-IP, C, C-VT, P2PE, and D.

    Which SAQ is the shortest?

    SAQ A is the shortest and applies to card-not-present merchants who fully outsource all cardholder data handling to PCI DSS compliant third parties. SAQ D is the most extensive and covers nearly all PCI DSS requirements; it applies to merchants who store cardholder data or do not qualify for any other SAQ.

    Does storing card data change my SAQ?

    Yes. If you electronically store cardholder data on systems you control, you generally must complete SAQ D regardless of channel, and you take on the full scope of protecting that stored data. Avoiding storage is the single biggest way to reduce PCI scope.

    Do transaction volumes matter too?

    Yes. Your merchant level, set by your acquirer based on annual transaction volume, determines whether an SAQ is sufficient or whether a full Report on Compliance by a Qualified Security Assessor is required. Always confirm the exact SAQ and level with your acquiring bank.

    Is this tool free?

    Yes, it is free with no signup and nothing you select is sent anywhere. It gives a directional read; your acquiring bank or a QSA confirms the final SAQ. If you want help scoping and completing it, our team can guide the process.

    Not ready for a call yet?

    Get the compliance playbook

    A few short notes from Jacob on cutting PCI scope and validating without the pain. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.

    From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

    Want it done for you?

    PCI DSS Readiness

    We scope your card data environment and get you validated on the right SAQ.

    Explore PCI DSS Readiness →

    Need to validate PCI DSS?

    We scope your cardholder data environment, cut it down where we can, pick the right SAQ, and get you validated, coordinating with your acquirer or QSA. Turn this answer into a plan.

    See PCI DSS Readiness Book a call

    Want the full picture on PCI DSS v4.0.1?

    This gives you the shape of the problem. The full picture is all 143 requirements of PCI DSS v4.0.1, each one explained in plain English, with somewhere to attach the evidence and a readiness score that moves as you close gaps. Start a free assessment and walk every control.

    Start your free PCI DSS v4.0.1 assessment See what is in the Workspace

    No credit card, no trial clock, no locked features. Traztech makes money when someone wants help closing the gaps, not from the Workspace itself.

    Track record

    Who is actually doing the work

    5
    Published CVEs, including a CVSS 9.1
    76
    Controls taken from nothing to a passed SOC 2 Type II
    Zero
    Exceptions on that Type II report
    20+
    Penetration testing engagements delivered

    Published vulnerability research

    Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

    A SOC 2 Type II built from nothing

    At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.