Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
PCI SAQ C-VT
PCI DSS Self-Assessment Questionnaire C-VT, for merchants using web-based virtual payment terminals.
SAQ C-VT is for merchants that key transactions manually into a web-based virtual payment terminal supplied by a validated third party, using a single isolated computer that has no other connection to the payment environment. No cardholder data is stored electronically, and the browser and computer are dedicated to that purpose.
SAQ C-VT covers a limited subset of PCI DSS v4.0.1, focused on isolating and protecting the one computer used to reach the virtual terminal rather than on securing a full payment application. It cannot be used where the virtual terminal is accessed from general-purpose or networked machines that touch other systems.
Dedicate a single, isolated computer to the virtual terminal and keep it separate from other systems and business functions.
Harden the device and browser, restrict access to authorised users and enforce strong authentication.
Apply anti-malware and timely patching to the computer used to access the virtual terminal.
Ensure cardholder data entered into the virtual terminal is never stored on the device.
Read more
Anove scans your stack against PCI SAQ C-VT and 260+ other frameworks in minutes.
Confirm the virtual terminal provider's compliance and maintain supporting security policies.