Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
PCI SAQ C
PCI DSS Self-Assessment Questionnaire C, for merchants with payment application systems connected to the internet.
SAQ C is for merchants that operate payment application systems (for example a point-of-sale system or payment software on a till or computer) that are connected to the internet, provided no cardholder data is stored electronically. The payment application and its host sit within the merchant's own environment and connect outward, so the environment is larger and more exposed than in the standalone-terminal questionnaires.
SAQ C covers a broad subset of PCI DSS v4.0.1, addressing the security of the payment application, the systems it runs on and the network connecting them to the internet, while excluding the storage-related controls that do not apply when no account data is kept.
Keep the payment application securely configured, patched and free of default settings and unnecessary functions.
Isolate the payment environment from other networks and the internet using firewalls and controlled connections.
Restrict access to the payment system to authorised users and enforce strong, individual authentication.
Protect systems against malware and known vulnerabilities through anti-malware controls and timely updates.
Read more
Anove scans your stack against PCI SAQ C and 260+ other frameworks in minutes.
Record and review activity on in-scope systems to detect and respond to security events.