Loading...
Loading...
Copyright © 2026 Anove International B.V.
All product names, logos, and brands are property of their respective owners. Use of these names does not imply affiliation, endorsement, or partnership.
PCI SAQ D SP
PCI DSS Self-Assessment Questionnaire D for service providers eligible to complete an SAQ.
SAQ D for Service Providers is the comprehensive questionnaire used by service providers that a card brand has deemed eligible to validate through a self-assessment rather than a full Report on Compliance. Service providers store, process or transmit cardholder data, or can affect its security, on behalf of other organisations, so their responsibilities extend to the clients they serve.
The questionnaire covers essentially the full breadth of PCI DSS v4.0.1 and additionally reflects the requirements that apply specifically to service providers, such as broader governance, reporting to customers and clear allocation of responsibilities. It is more demanding than any merchant SAQ.
Secure all stored, processed or transmitted account data handled for clients, rendering stored data unreadable and managing keys rigorously.
Maintain segmentation, secure configuration, encryption in transit and hardened systems across the entire cardholder data environment.
Enforce least privilege, unique identities and multi-factor authentication for personnel and administrative access.
Operate formal security governance, allocate PCI DSS responsibilities with customers in writing and support customer due diligence.
Read more
Anove scans your stack against PCI SAQ D SP and 260+ other frameworks in minutes.
Perform regular testing, continuous logging and monitoring, and maintain an incident response programme.