On August 31, 2026, the PCI Security Standards Council (PCI SSC) updated FAQ 1331 on its website. This FAQ governs the use of Self-Assessment Questionnaire (SAQ) eligibility criteria as a guide for determining applicability of PCI DSS requirements for Report on Compliance (ROC) assessments.
The previous version directed merchants to work with their Qualified Security Assessors (QSAs) to determine whether SAQ eligibility criteria could be applied to reduce the scope of a ROC assessment. Many merchants and PCI QSAs relied on this FAQ as justification for reducing the number of requirements applicable to their in-scope environments, which in turn reduces both compliance burden and cost.
The prior version of the FAQ directed merchants to work with their QSA to determine if those criteria could be used. The updated FAQ effectively negates this guidance; most of the FAQ has been replaced with a single, significantly more restrictive statement:
SAQs should not be used as a “guide” for determining the applicability of PCI DSS requirements unless explicitly reviewed, discussed and agreed upon with the merchant’s compliance accepting entity (e.g., payment brands and acquirers).
In practice, this means that, if your ROC assessment leverages (or will leverage) SAQ eligibility criteria, your acquirer(s) must now be involved in and approve the use of same.
This means that you will most likely need to provide to your QSA Company that approval in writing from your acquirer(s).
There are two potential paths to obtaining the required acquirer approval:
Without this approval, additional time and effort will be required to validate whether or not individual requirements are applicable in a given environment and it may not be possible to justify exclusion of some requirements previously excluded due to exclusion on a corresponding SAQ. Waiting for in-assessment approval will likely result in significant delays in completing the assessment.
We are expecting further guidance from the PCI SSC on this subject but wanted to proactively make you aware of this important change and its potential impact on your future PCI ROC assessments.
If you are unsure how this FAQ update affects your current or upcoming ROC assessment, our team can help you evaluate your exposure, determine the right approval pathway and engage your acquirer with the documentation needed to maintain your current scope position.
Practice Director, Compliance
GuidePoint Security