Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
PCI SAQ D Merch
PCI DSS Self-Assessment Questionnaire D for merchants not covered by other SAQ types.
SAQ D for Merchants is the most comprehensive self-assessment questionnaire. It applies to any merchant that is not eligible for one of the more narrowly scoped SAQ types, including those that store cardholder data electronically or have payment environments that do not fit the other categories. Because such an environment can touch account data at many stages, the questionnaire is not limited to a reduced control subset.
SAQ D for Merchants reflects essentially the full breadth of PCI DSS v4.0.1, spanning network security, data protection, access control, vulnerability management, monitoring and security governance. Merchants complete it when their acceptance channels and data handling require the complete standard rather than a tailored subset.
Where account data is stored, minimise it, render it unreadable (for example through strong cryptography) and manage keys securely.
Maintain firewalls, segmentation, secure configurations and protection of data in transit across the cardholder data environment.
Enforce least-privilege access, unique IDs and strong multi-factor authentication for access to systems and data.
Run anti-malware, patching, secure development and regular internal and external testing to manage vulnerabilities.
Read more
Anove scans your stack against PCI SAQ D Merch and 260+ other frameworks in minutes.
Log and monitor access, maintain security policies and a risk-based programme, and keep an incident response capability.