Which SAQ applies to a merchant with a standalone payment application connected to the Internet?

Prepare for the PCI Approved Scanning Vendor (ASV) Test. Study with flashcards, multiple choice questions, hints, and explanations. Get exam ready!

Multiple Choice

Which SAQ applies to a merchant with a standalone payment application connected to the Internet?

Explanation:
The main idea tested is how the PCI SAQ categories map to where card data flows and where it’s stored in your environment. A standalone payment application that is connected to the Internet sits in a category that covers payment application systems connected to the Internet, with no electronic storage of cardholder data beyond what the payment app handles. That makes it different from a non‑internet‑connected terminal setup (which would point to the B category), and it’s not an e‑commerce outsourcing scenario (A/A‑EP) or a P2PE scenario (which would require a validated point‑to‑point encryption solution). So the correct SAQ is the one designed for payment application systems connected to the Internet.

The main idea tested is how the PCI SAQ categories map to where card data flows and where it’s stored in your environment. A standalone payment application that is connected to the Internet sits in a category that covers payment application systems connected to the Internet, with no electronic storage of cardholder data beyond what the payment app handles. That makes it different from a non‑internet‑connected terminal setup (which would point to the B category), and it’s not an e‑commerce outsourcing scenario (A/A‑EP) or a P2PE scenario (which would require a validated point‑to‑point encryption solution). So the correct SAQ is the one designed for payment application systems connected to the Internet.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy