Knowledge center
What is SAQ A?
SAQ A is intended for merchants with account-data functions fully outsourced to validated providers and no electronic storage, processing or transmission of that data in their own systems or premises, subject to every criterion.
Why it matters
Using a third party alone is not enough.
What to confirm
- Who hosts and captures payment
- Whether your systems receive account data
- Provider validation and responsibilities
Official PCI DSS documentation · PCI DSS v4.0.1 · reviewed 2026-07-31
This content is informational and is not legal advice. The applicable route and validation method depend on the operation and requesting party.