Validation Levels
A company’s validation level is essential to know and is determined by how financial information is stored, processed and handled. The validation level determines which Self-Assessment Questionnaire (SAQ) you must fill out to document compliance. Currently, there are five SAQ Validation levels. The table below provides a brief description of each.
|
|
A |
Card-not-present (e-commerce or mail/telephone-order) merchants, all cardholder data functions outsourced. This would never apply to face-to-face merchants. |
B |
Imprint-only merchants with no electronic cardholder data storage, or standalone, dialout terminal merchants with no electronic cardholder data storage. |
C |
Merchants with payment application systems connected to the Internet, no electronic cardholder data storage. |
C-VT |
Merchants using only web-based virtual terminals, no electronic cardholder data storage. |
D |
All other merchants not included in descriptions for SAQ types A through C above, and all service providers defined by a payment brand as eligible to complete an SAQ. |
For more information, please visit the PCI Council SAQ Instructions and Guidelines.