Skip to content

SAQ D-Service Provider walkthrough

By Sam Rivera, Founder, SentinelPanda · June 3, 2026 · 3 min read · PCI DSS

Service providers carry obligations merchants do not. SAQ D-Service Provider is the eligible self-assessment route for service providers below the Level 1 threshold.

Who SAQ D-Service Provider is for

A service provider is an organisation that stores, processes, or transmits cardholder data on behalf of another entity, or that could impact the security of the customer's cardholder data. The category includes managed service providers, hosting providers running customer-payment environments, gateway operators, tokenisation providers, fraud-screening services, and many SaaS products that touch payment data.

SAQ D-Service Provider is the validation route for service providers below the Level 1 threshold. Visa's Level 1 service provider threshold is 300,000 transactions a year (storing, processing, or transmitting); other brands have similar levels. Level 1 service providers typically require a QSA-led ROC.

The eligibility checklist

  • You are a service provider, not a merchant.
  • Your transaction volumes are below the Level 1 threshold for every card brand you serve.
  • You have not been designated by a card brand or your customers for QSA-led assessment.
  • You confirm scope and the customer obligations matrix in a Scope Statement.

The requirement subset

SAQ D-Service Provider covers all 12 requirements like D-Merchant, plus a set of service-provider-specific clauses. Notable additions: Req 12.4.2 (executive committee involvement in PCI), Req 12.4.2.1 (executive accountability), Req 12.9 (acknowledgement of responsibility for customer cardholder data in writing), Req 12.8 (customer-side written acknowledgement of shared responsibility), Req 11.4.6 (additional segmentation testing every 6 months for service providers, vs annual for merchants under Req 11.4.5).

The customer-facing artefacts matter operationally. The written responsibility matrix — which controls you cover, which the customer covers, which are shared — is the document your customers will request every year.

Service providers running enterprise sales often engage a QSA for advisory or to issue a QSA-signed attestation that lands harder in procurement than a self-attested AOC. SentinelPanda hosts both modes in the same workspace: your team works the SAQ-D-SP path day-to-day, and when the QSA is brought in (annual review, customer-driven request, or a contractual commitment) they get auditor-layer seats inside your tenant — no second toolchain, no exported evidence, no re-keying.

Common SAQ D-Service Provider pitfalls

  • Skipping the written customer responsibility matrix — a hard fail at customer review even if technical controls are sound.
  • Service provider segmentation testing cadence: six months for service providers, not annual. Easy to miss.
  • Executive accountability (Req 12.4.2) treated as a checkbox without a named executive owner.
  • No bridge-letter process between revalidations — customers waiting for new attestations get stuck.
  • Not refreshing the AOC quickly after assessment — customers chase you for it; faster turnaround is a procurement advantage.

A worked example

A SaaS company offers a payments-adjacent fraud-detection service. They process limited cardholder data, segregated into a dedicated AWS account with PCI DSS-applicable services. A versioned Scope Statement documents what is in CDE, what is connected-to, and what is out-of-scope. A customer responsibility matrix is published with every contract. Six-monthly segmentation tests run and are documented. The PCI executive owner is named in the SAQ; the AOC is refreshed within two weeks of the assessment and made available in the customer portal.

Total: 10-14 weeks first cycle, 4-5 weeks revalidation. Ongoing customer-facing operations (responsibility matrix updates, AOC distribution, bridge letters between cycles) carry weight in the year.

SAQ D-Merchant walkthrough The complete PCI SAQ walkthrough PCI DSS service provider levels and what SaaS owes

Run your compliance program in one workspace.