Frequently Asked Question
Is a merchant website still in scope for PCI DSS if it meets all the criteria for SAQ A?
Yes. The merchant web server must be included in scope so the assessor can examine its configuration and verify the redirection mechanism used. Once verified, the applicable requirements will then need to be implemented. If the merchant environment and web server redirection meet all criteria for SAQ A, then the minimum applicable requirements can be considered as those within that SAQ.
See also FAQ 1331 Can SAQ eligibility criteria be used for determining applicability of PCI DSS requirements for onsite assessments?