SAQ A-EP

SAQ A-EP — E-commerce with iframe/redirect

For online merchants whose own checkout page loads a third-party payment iframe or initiates the redirect. Card data goes straight to the processor, but your server is in scope because a compromised page could redirect customers somewhere malicious.

Roughly 70 controls — significantly more than SAQ A because your web infrastructure has to be hardened and monitored.

Prefer a printable workbook?

The free 25-page PDF includes all four SAQ checklists, the decision guide, and the glossary in one printable document.

Download free PDF →

0 / 18 controls complete

0%

Scope & eligibility0 / 2

Build and maintain a secure network0 / 4

Protect cardholder data0 / 1

Vulnerability management0 / 5

Access control0 / 3

Monitoring & testing0 / 3