01 / 05
What kind of entity are you?
This is a general PCI DSS orientation. Your acquirer, payment brand, or compliance-accepting entity may impose additional validation requirements.
Merchant I accept payment cards for my own business or customers.
Service provider I process, store or transmit cardholder data on behalf of other organisations.
02 / 05
How many card transactions do you process?
Use the annual total. For the merchant path, the thresholds below follow the payment provider guide and can differ by card brand.
transactions / year
Relevant PCI DSS resources
03 / 05
How many are online?
This helps distinguish transaction-volume categories used by payment brands. If all your transactions are online, enter the same number as above.
online / year
Relevant PCI DSS resources
04 / 05
Have you had a data breach in the past?
A confirmed payment-data breach can affect your PCI DSS validation requirements regardless of transaction volume.
Yes We have experienced a confirmed payment-data breach.
No No known payment-data breach.
Relevant PCI DSS resources
05 / 05
How does card data enter your system?
Choose the closest payment provider integration model. This helps identify the likely SAQ family when an SAQ is available. You still need to satisfy every eligibility criterion.
Hosted payment page / embedded fields Hosted or embedded third-party card collection using Checkout, payment provider.js/Elements as described by payment provider.
Platform-managed payment Card collection is exclusively through a Connect platform.
Payment mobile SDK Only an approved payment-provider mobile SDK UI are used for card entry.
Direct-post / hosted JavaScript form Your site hosts the form and Direct-post / hosted JavaScript form passes the card data to payment provider.
Payment terminal Card data is collected exclusively through payment provider Terminal.
Virtual terminal / manual entry Manual card payments through the a provider's web-based virtual terminal.
Raw card data / custom form My own application or server receives card numbers before sending them to a processor.
Other / multiple methods My integration does not fit one of the above, or I use several methods.
Relevant PCI DSS resources
Relevant PCI DSS resources
Back
Continue