Knowledge center
Am I a merchant or a service provider for PCI DSS?
A merchant accepts payment for goods or services. A service provider may store, process or transmit account data for another entity, or affect the security of its environment.
Why it matters
The classification changes the validation route and the applicable SAQ D document.
What to confirm
- Whose payments are processed
- Services that affect third-party data or systems
- How the acquirer or customer classifies the entity
Official PCI DSS documentation · PCI DSS v4.0.1 · reviewed 2026-07-31
This content is informational and is not legal advice. The applicable route and validation method depend on the operation and requesting party.