PCI DSS SAQ Validation and Support

What is a self-assessment questionnaire (SAQ)?
For some organisations, the appropriate questionnaire is short and simple, while for others it can be long and technical.
If you are struggling with your SAQ give our PCI consultants a call. They can help advise you on which SAQ to complete and offer support and advice to reduce effort and cost.
What is SAQ validation and support?
This will involve:
- Identifying the appropriate SAQ to complete; and
- Making suggestions to improve compliance and help to fully populate the SAQ ready for your submission.
Our consultants will help you validate your cardholder data environment, reduce gaps and help you answer technical components of the SAQ enabling you to submit your SAQ with ease.
Did you know?
Each SAQ has a different subset of the PCI DSS requirements that are relevant to the payment channel in question, and all of the questions on each SAQ must be answered.
It is possible to mark requirements as ‘not applicable’ (not all can be marked N/A; there are a few that are always applicable), as long as the organisation can justify the non-applicability. It is also possible to use what is called a ‘compensating control’ – a process or technology to reduce risks – but this must be fully risk justified and documented within the SAQ.

Benefits of SAQ validation and support

Is an SAQ validation and support service right for you?
Our engagement process
- Pre-assessment information gathering: Our consultant will discuss your SAQ requirements with key stakeholders and conduct a review of the existing SAQ documentation.
- Assessment and analysis: During this step, we will review the processing and flow of cardholder data through systems and processes, assess any third-party or service provider dependencies and document any evidence to demonstrate compliance.
- Post-assessment: We will provide a report of findings, and make suggestions to lower your validation level, such as scope reduction, and submit an attested SAQ, signed off by a QSA.