Skip to content
PCI DSS SAQ

Run your PCI DSS Self-Assessment Questionnaire with AI assistance

Describe your payment environment, upload evidence, and let SentinelPanda pre-fill your SAQ requirement answers — your team confirms or overrides. A guided workflow for all nine SAQ types, with the signed AOC your acquirer expects.

Free to start, no card · see pricing

9 SAQ typesscope-derivedsigned AOC

What PCI DSS SAQ requires

The PCI DSS Self-Assessment Questionnaire (SAQ) is how merchants and most service providers below the Level 1 threshold validate compliance every year. Nine SAQ variants cover different payment-acceptance models, from fully-outsourced e-commerce (SAQ A) to merchants that store cardholder data (SAQ D-Merchant). The wrong SAQ type is an expensive mistake; the right one still means walking dozens to hundreds of requirements, attaching evidence to each, and producing a signed Attestation of Compliance for your acquirer portal.

How it works

Answer in the browser. Walk away with the report.

Deliverable · PDF SAQ A Self-Assessment Report
Every requirement, answered + dated Compliance summary by requirement Cross-references the official AOC Emailed to you + re-downloadable
Generated from your answers · PCI DSS v4.0

Describe the environment once, get an AI-assisted SAQ draft

Most SAQ work is mechanical: read the requirement, decide if it applies, write a one-sentence answer, attach evidence. SentinelPanda takes the description of your payment environment plus your evidence files and asks Claude to propose a per-requirement answer — status (applicable, not applicable, needs attention), narrative, and a self-rated confidence — so your team starts from a draft instead of a blank workbook. Every AI suggestion is clearly marked; nothing reaches your AOC until a human confirms it.

Two stat cards your team actually needs: how much is pre-filled, and how much is human-confirmed

The SAQ portal surfaces four counters that match how the work actually moves: total requirements in scope, how many the AI has suggested an answer for, how many a human has confirmed, and how many need attention. Progress is real progress (the human-confirmed share), not "rows touched." Re-running the AI is incremental — it skips anything already confirmed or marked needs-attention, so you can spread the work across multiple sessions without losing ground.

Evidence files map themselves to the right requirements

Drop a firewall configuration PDF, a network diagram, an ASV scan report, or a policy document, and the AI categorises the file and proposes which PCI DSS requirements it satisfies. Your team accepts or overrides the mapping. The same file can support multiple requirements — typical for policies and architecture documents — so you stop attaching the same PDF in ten different places.

Confirmation is the bar, not generation

AI-suggested answers carry a clearly-visible "AI suggested" badge and a confidence score. The workflow never advances anything from AI-suggested to confirmed automatically — your team explicitly reviews each one and either confirms, edits, or flags for follow-up. Once confirmed, the requirement is counted toward signed-off progress and the AOC. Auditors looking at the audit log can tell exactly which answers came from AI and which a human authored.

All nine SAQ types from one workflow

The portal works for SAQ A, A-EP, B, B-IP, C, C-VT, P2PE, D-Merchant, and D-Service Provider. Pick the type during setup; the wizard surfaces only the requirements that actually apply to your scope. Switching SAQ types preserves answers for shared requirements — no rework if your scope expands or contracts between cycles.

One source of truth across the SAQ, your ASV scans, and next year's revalidation

The SAQ portal lives in the same workspace as your ASV scan tracker, your scope statement, your evidence library, and your three-role review workflow. The four quarterly ASV attestations attach to the SAQ at signing time; the scope statement is the input to SAQ type selection; the evidence library feeds the AI categoriser. Next year's revalidation starts from this year's confirmed answers, so each cycle is a smaller delta — not a fresh start.

How SentinelPanda helps

01AI-assisted SAQ draft from your payment-environment description + uploaded evidence
02Per-requirement suggestions with status, narrative, confidence score, and a clear "AI suggested" badge
03Incremental re-runs that skip confirmed and needs-attention rows
04All nine SAQ types — applicability auto-detected from your scope answers
05AI auto-categorisation of evidence files against PCI DSS sub-requirements
06Human confirmation gate before anything reaches the signed AOC
07Same workspace as the scope statement, ASV scan tracker, and evidence library
08Three-role review workflow — invite your QSA or external auditor in as auditor-layer seats
09Signed AOC export for the acquirer portal — for merchants and service providers

PCI DSS SAQ — frequently asked questions

Does the AI ever sign off on a requirement by itself?

No. Every AI-suggested answer requires a human to explicitly confirm, edit, or override before it counts toward signed-off progress. The four stat cards make the human-confirmed share visible as a separate counter — that is what your progress bar tracks.

Which SAQ types does this support?

All nine: A, A-EP, B, B-IP, C, C-VT, P2PE, D-Merchant, and D-Service Provider. The wizard surfaces only the requirements that apply to the SAQ type your scope answers selected.

What about my QSA — can they see the work in progress?

Yes. Your QSA can join the workspace as an auditor-layer seat on the Growth and Enterprise tiers. They get read access to the SAQ answers and the linked evidence, can approve or request more info on individual requirements, and every action is recorded to the HMAC-signed audit log.

Is there a free SAQ wizard I can try first?

The SAQ portal is currently in early-access inside the SentinelPanda app — book a demo and we will spin up a workspace for your team. A standalone, no-account-required SAQ-A wizard with paid PDF download is on the roadmap.

How does this handle the four quarterly ASV scans?

ASV engagements live alongside the SAQ in the same workspace. The latest passing attestation per quarter is tracked automatically; when the SAQ is finalised the four quarterly attestations are already attached as supporting evidence. Nothing has to be hunted down at signing time.

Can I use existing PCI evidence for ISO 27001 or SOC 2?

Yes — cross-framework mapping means an implemented PCI control automatically credits its equivalents in ISO 27001, SOC 2, NIST CSF, and HIPAA. You collect the evidence once and it advances multiple programmes.

What about the AI sending my data somewhere I do not control?

The portal calls the Anthropic API (Claude Haiku) only for the requirement-classification step, and only with the payment-environment description and PCI control text you provide — never with raw cardholder data. Anthropic does not train on API inputs by default. If you need fully on-prem AI inference, that is on the roadmap and worth discussing on a demo call.

Start your PCI DSS SAQ program today.