Frequently Asked Question

Is a merchant website still in scope for PCI DSS if it meets all the criteria for SAQ A?
Yes. The merchant web server must be included in scope so the assessor can examine its configuration and verify the redirection mechanism used. Once verified, the applicable requirements will then need to be implemented. If the merchant environment and web server redirection meet all criteria for SAQ A, then the minimum applicable requirements can be considered as those within that SAQ.
See also FAQ 1331 Can SAQ eligibility criteria be used for determining applicability of PCI DSS requirements for onsite assessments?
July 2015
Article Number: 1332
Related
-
Can SAQ eligibility criteria be used for determining applicability of PCI DSS requirements for assessments documented in a Report on Compliance?
-
How should QSA assistance with completion of Self-Assessment Questionnaire (SAQs) be documented?
-
Why are there multiple PCI DSS Self-assessment Questionnaires (SAQs)?