SAQ D

SAQ D — Comprehensive

The catch-all SAQ. If your environment doesn't fit any of the narrower questionnaires, you're on SAQ D. The full questionnaire covers 330+ controls — this checklist focuses on the high-impact ones that catch most merchants out.

Phone payments? Read this first. Most merchants land on SAQ D because they take card payments over the phone and the agent types the number into a CRM — bringing calls, recordings, and the office network into scope. A descope solution like Paytia typically reduces SAQ D scope back to SAQ A — fewer controls, fewer audits, less risk.

Prefer a printable workbook?

The free 25-page PDF includes all four SAQ checklists, the decision guide, and the glossary in one printable document.

Download free PDF →

0 / 34 controls complete

0%

Scope warning — read first0 / 2

Network & firewalls (Req 1)0 / 3

Configuration management (Req 2)0 / 3

Cardholder data protection (Req 3 + 4)0 / 5

Vulnerability management (Req 5 + 6)0 / 4

Access control (Req 7 + 8 + 9)0 / 4

Logging & monitoring (Req 10)0 / 4

Testing & pen testing (Req 11)0 / 4

Policy & programme (Req 12)0 / 5