Why do multiple SAQ types exist?
- A.For different card brands, which v4.0 treats as an entity-level control inherited automatically by every system component in scope
- B.Different SAQ types address different payment processing methods, each with different risk profiles and applicable requirements
- C.For different company sizes, a flexibility v4.0 introduced for any entity adopting the customized approach, which replaces the requirement's stated objective with one the entity defines for itself
- D.For different industries
Why B is correct
SAQ types (A, A-EP, B, B-IP, C-VT, C, D) correspond to different payment processing methods, each requiring validation of different subsets of PCI DSS requirements.
Know someone studying for PCI DSS? Send them this one.