SAQ Guidance
How the PCI Self-Assessment Questionnaires relate to Cresora's integration surfaces; which one applies is your QSA's determination.
A PCI SAQ (Self-Assessment Questionnaire) documents your compliance with the PCI DSS standard. The right SAQ depends on how your integration handles cardholder data.
SAQ types and Cresora's surfaces
The PCI SSC publishes several Self-Assessment Questionnaires. Two are commonly relevant to a card-not-present integration built on Cresora:
SAQ A
For merchants whose cardholder data functions are fully outsourced to a validated third party, with no electronic storage, processing or transmission of card data on their own systems. The Cresora hosted page is built for this shape: the payer enters card data on a Cresora-served page, and any later charge references a cvt_ vault token rather than a card number.
SAQ D
The full questionnaire, for a merchant environment that does not fit a narrower SAQ — for example because card data is handled elsewhere in your business, outside Cresora.
Which SAQ applies is determined by your QSA or compliance advisor from your entire environment. Cresora's surfaces keep card data off your systems; they do not, on their own, decide your questionnaire.
Completing your SAQ
- Download the appropriate SAQ from the PCI Security Standards Council website (pcisecuritystandards.org)
- Answer each question honestly and accurately
- Sign the Attestation of Compliance (AoC)
- Submit a copy to Cresora during certification
Annual renewal
SAQs must be completed annually. Track your own renewal date.
Selecting the wrong SAQ (e.g., SAQ A when you should file SAQ D) creates liability for your business. If unsure, consult a Qualified Security Assessor (QSA) or contact Cresora.