Recent Update to FAQ Regarding SAQ Eligibility Criteria Could Affect Your PCI DSS Compliance

BLOG

What Happened

On August 31, 2026, the PCI Security Standards Council (PCI SSC) updated FAQ 1331 on its website. This FAQ governs the use of Self-Assessment Questionnaire (SAQ) eligibility criteria as a guide for determining applicability of PCI DSS requirements for Report on Compliance (ROC) assessments.  

The previous version directed merchants to work with their Qualified Security Assessors (QSAs) to determine whether SAQ eligibility criteria could be applied to reduce the scope of a ROC assessment. Many merchants and PCI QSAs relied on this FAQ as justification for reducing the number of requirements applicable to their in-scope environments, which in turn reduces both compliance burden and cost. 

The prior version of the FAQ directed merchants to work with their QSA to determine if those criteria could be used. The updated FAQ effectively negates this guidance; most of the FAQ has been replaced with a single, significantly more restrictive statement:

SAQs should not be used as a “guide” for determining the applicability of PCI DSS requirements unless explicitly reviewed, discussed and agreed upon with the merchant’s compliance accepting entity (e.g., payment brands and acquirers).

In practice, this means that, if your ROC assessment leverages (or will leverage) SAQ eligibility criteria, your acquirer(s) must now be involved in and approve the use of same. 

This means that you will most likely need to provide to your QSA Company that approval in writing from your acquirer(s).  

What You Need to Do

There are two potential paths to obtaining the required acquirer approval:

  1. A blanket approval. Well before starting your next assessment, request written authorization from your acquirer(s) approving the use of SAQ eligibility criteria in all PCI ROC assessments going forward.
  2. Per-assessment approval based on the acquirer’s review. Provide your acquirer with whatever information they require up front from you or your QSA Company just prior to each assessment cycle.     

What Happens if You Do Nothing

Without this approval, additional time and effort will be required to validate whether or not individual requirements are applicable in a given environment and it may not be possible to justify exclusion of some requirements previously excluded due to exclusion on a corresponding SAQ. Waiting for in-assessment approval will likely result in significant delays in completing the assessment.

We are expecting further guidance from the PCI SSC on this subject but wanted to proactively make you aware of this important change and its potential impact on your future PCI ROC assessments.

Next Steps

If you are unsure how this FAQ update affects your current or upcoming ROC assessment, our team can help you evaluate your exposure, determine the right approval pathway and engage your acquirer with the documentation needed to maintain your current scope position.

Practice Director, Compliance
GuidePoint Security

Dan Mengel, Practice Director at GuidePoint Security, began his career in the security industry in 2000. He has delivered high-quality consulting services, directly and by leading others, in the areas of information security program architecture, security policy development and security vulnerability, risk and compliance assessments. He has developed sales and delivery processes and documentation templates for all of these engagement types. Dan is currently leading GuidePoint’s Compliance team in delivering assessment and advisory services for multiple information security standards. He also has significant prior experience designing and integrating security technology solutions from Cisco, Check Point, Websense, RSA and others. Dan earned a Bachelor of Science degree in Computer Information Systems from Goldey-Beacom College and holds several recognized information security industry certifications.