SAQ B, B-IP, C-VT and P2PE: the Card-Present SAQ Types Explained
Most PCI guidance is written for online shops. If you take payments over a counter, your questionnaire is one of five card-present types — and the difference between them is the difference between 22 questions and 249.
Almost every guide to PCI self-assessment is written for online businesses, which is unhelpful if your card machine sits on a counter. There are ten Self-Assessment Questionnaires, and five of them exist specifically for merchants who take payments face to face. The gap between them is enormous — the shortest runs to around 22 requirements, the catch-all to roughly 249 — and merchants routinely complete a far harder one than they needed to because nobody checked. This guide explains the card-present types, who qualifies for each, and how to move to a simpler one. For the two questionnaires that dominate online payments, see our comparison of SAQ A and SAQ D.
First: what merchant level are you?
Your level decides whether you can self-assess at all, and it is set by the card brands rather than by the PCI Security Standards Council — which is why the answer differs slightly depending on which scheme you ask. Broadly, above six million transactions a year you are Level 1 and need a formal assessment producing a Report on Compliance; below that, you self-assess with the appropriate questionnaire. Our guide to PCI merchant levels covers the thresholds in full.
One update worth knowing, because a great deal of published guidance has not caught up: Visa now operates three merchant levels rather than four, having merged its old Levels 3 and 4 into a single Level 3 covering everything below a million transactions. Mastercard still uses four. Nothing changes practically for a small business — you self-assess either way — but the level your acquirer quotes may not match the level a website tells you to expect. Your acquirer's answer is the one that counts.
SAQ B — standalone dial-out terminals
SAQ B covers merchants using imprint machines or standalone terminals that dial out over a phone line, with no electronic storage of card data. At around 28 requirements it is one of the shortest questionnaires there is, and — unusually — it contains no network security requirements at all, because there is no network involved. It also contains no vulnerability scanning requirements.
What it does contain is physical security: keeping an inventory of your devices, inspecting them for tampering, training staff who work near them, and handling any paper records properly. If you are still on a dial-up terminal, this is a genuinely light compliance burden. It is not available to e-commerce businesses.
SAQ B-IP — standalone terminals over the internet
SAQ B-IP is the modern equivalent and covers a very large number of UK small businesses: a standalone, PCI-approved terminal connected to the payment processor over an IP connection, again with no electronic storage of card data. It runs to roughly 49 requirements.
The step up from SAQ B is mostly network-related, because now there is a network. You pick up a subset of the network security requirements, and — importantly for your budget — quarterly external vulnerability scanning by an Approved Scanning Vendor. That scanning subscription is a genuine recurring cost and should appear in any honest quote; our guide to what PCI compliance costs in the UK covers what to expect.
SAQ C-VT — virtual terminal, typed by hand
SAQ C-VT is for businesses that key card details manually, one transaction at a time, into a payment provider's web-based virtual terminal — the classic setup for a business taking occasional payments over the phone. At around 54 requirements it is moderate, and it contains no vulnerability scanning requirements at all.
The eligibility conditions are strict and frequently broken in practice. The computer used must be a single, isolated device — not one that also browses the web freely or sits on the general office network — and no card data may be stored electronically. Businesses often qualify on paper and fail in reality because the virtual terminal is open in one browser tab and everything else in another. Our guide to PCI compliance for phone payments covers how to take card details over the phone properly.
SAQ C — payment applications on a network
SAQ C is the heavy one in this group, at roughly 123 requirements. It covers payment application systems connected to the internet — an integrated till system, a booking platform that processes cards, a POS application on your network — where card data is not stored electronically.
The jump in length is not arbitrary. Once a payment application sits on your network, your network is in scope, and you pick up internal vulnerability scanning alongside external ASV scanning, network segmentation testing, and file-integrity monitoring. If you are here, network segmentation is what keeps the assessment survivable — separating the payment systems from everything else stops the rest of your estate joining them in scope.
SAQ P2PE — the shortest route there is
SAQ P2PE is for merchants using terminals that form part of a validated point-to-point encryption solution listed by the PCI Security Standards Council. Card data is encrypted inside the device before it goes anywhere, so the merchant never has access to it in readable form.
The reward is the shortest questionnaire of all — around 22 requirements, with no vulnerability scanning and no network security requirements. If you take a meaningful volume of card-present payments and your compliance burden feels heavy, asking your provider whether they offer a validated P2PE solution is one of the highest-value questions you can ask. The critical word is 'validated': a provider saying their terminals encrypt is not the same as the solution appearing on the Council's list, and only the latter qualifies you for this questionnaire.
SAQ SPoC — taking payments on a phone or tablet
SPoC — Software-based PIN entry on COTS, where COTS means commercial off-the-shelf — is the newest questionnaire, added in the version 4 family. It covers merchants who accept payments using a standard phone or tablet paired with a secure card reader, where the solution appears on the Council's list of validated SPoC solutions.
This is the questionnaire for the growing number of market traders, mobile therapists, tradespeople and pop-up businesses taking cards on a phone. As with P2PE, it only applies where the specific solution is validated and listed — so check before assuming it covers the reader you bought online. It is not available for unattended, mail order, telephone order or e-commerce payments.
How do you choose — and can you move to a simpler one?
The questionnaire is decided by how card data moves through your business, not by preference. Three questions settle it for most merchants: does card data ever get stored electronically anywhere in your business; is the terminal standalone or connected to a system of yours; and is your solution validated for P2PE or SPoC?
If any card data is stored electronically, you are into SAQ D and its roughly 249 requirements regardless of everything else — which is why 'we keep the card number in the booking record in case they cancel' is such an expensive habit. Eliminating stored card data is usually the single change that moves a business from the longest questionnaire to one of the shortest.
Moving to a simpler questionnaire is legitimate and often straightforward: stop storing card data, isolate the machine used for a virtual terminal, or switch to a validated P2PE or SPoC solution at your next terminal refresh. The change takes effect at your next annual validation. What you must not do is complete a simpler questionnaire you do not qualify for — an invalid assessment can be rejected later, and takes your compliant status with it. Our PCI DSS compliance checklist is a practical way to check where you stand before you commit to one.
Key takeaways
- Five questionnaires cover card-present merchants: B, B-IP, C-VT, C and P2PE — plus SPoC for phone-based readers.
- The range is enormous: roughly 22 requirements for P2PE against about 249 for SAQ D, decided entirely by how you take payments.
- SAQ B, C-VT and P2PE require no vulnerability scanning; B-IP and C both require quarterly ASV scans.
- Visa now has three merchant levels rather than four — but your acquirer's answer is the one that governs.
- Storing card data electronically forces you into SAQ D. Stopping is usually the cheapest compliance improvement available.
If you are not certain which of these applies to you, that is the question worth answering before anything else — it determines your workload, your scanning costs and your risk. Fraud Defence First's fully managed PCI compliance service establishes the right questionnaire from how you actually take payments, completes it with you and files it with your acquirer, for a flat £100 + VAT a year. For the full background on the standard, see our complete PCI DSS compliance guide.
Related Guides
'My Provider Handles PCI for Me' — What Your Acquirer Actually Does (and Doesn't)
Your payment provider secures its systems — but PCI validation, your premises and your staff stay your responsibility. Here is where the line really sits, and how to stop paying for the misunderstanding.
Read ArticleWhy Your Card Machine Provider Charges a PCI Fee — and How to Stop It
That PCI charge on your card machine statement is usually two different fees in disguise — and the larger one can normally be removed. Here is why providers charge it and how to stop paying.
Read ArticleSAQ A vs SAQ A-EP: What's the Difference and Which Do You Need?
SAQ A and SAQ A-EP sound alike but are worlds apart: around 30 questions against roughly 190, decided entirely by how your checkout is built. Here is how to tell which one your website needs — and how to move to the simpler one.
Read Article