The short checklist
- Establish how card data reaches the processor before choosing a questionnaire.
- A full redirect or a processor-owned iframe can point toward SAQ A if every other criterion is met.
- Fields served by your own page point away from SAQ A.
- The SAQ A script-security criterion applies to embedded processor forms, not redirects.
Start with where the card number is typed
If the customer is redirected to the provider, or types into an iframe the provider serves and controls, your page does not receive the data. If any field is served by your own page — including a hosted-field library that your page loads and lays out — more of the standard applies to you.
Then separate an embedded form from a redirect
Since 31 March 2025, a merchant page with an embedded processor payment form has an additional SAQ A eligibility criterion: confirm the site is not susceptible to script attacks that could affect its e-commerce systems. PCI SSC FAQ 1588 says the criterion does not apply to a processor redirect or a fully outsourced payment flow. For an embedded form, use protective techniques or processor confirmation and resolve any eligibility doubt with the acquirer.
- Is the processor payment form embedded in a merchant-controlled page?
- Or does the customer leave for a processor redirect or hosted payment link?
- For an embedded form, which scripts can affect the e-commerce system?
- Can you retain the evidence or processor confirmation supporting the criterion?
Your acquirer has the final say
Reporting obligations are set by your acquiring bank or the payment brands, not by a website. Use this to prepare the conversation, then confirm the questionnaire with them.
Primary source
Read the source rather than a summary of it, including this one: PCI Security Standards Council — FAQ 1588 — https://www.pcisecuritystandards.org/faqs/1588/.
What the free check can and cannot tell you
Reviewed August 2026. The standard and the questionnaires change; confirm against the current text before relying on anything here.
Inventory the third-party scripts on your page
Preview the synthetic 6.4.3 remediation pack before deciding whether the paid artifact fits your review.