# PCI DSS Scope Worksheet

> **Template — adapt before use.** Use this to document your cardholder-data environment before completing an SAQ. Accurate scope is the foundation of a defensible assessment. Not compliance advice.

| | |
|---|---|
| **Company** | [Company Name] |
| **Prepared by** | [Name / Role] |
| **Date** | [YYYY-MM-DD] |
| **Assessment period** | [YYYY] |

## 1. How you accept payments
_Check all that apply and describe each channel._
- [ ] **E-commerce** — website / payment page. Redirect/iframe to PSP? ___ Or page served by you? ___
- [ ] **MOTO** (mail/telephone order)
- [ ] **Card-present** — terminals / POS. P2PE-validated solution? ___
- [ ] **Virtual terminal** — staff key card data into a browser
- [ ] Other: ___

## 2. Cardholder data flows
For each channel, describe how account data enters, moves, and leaves:
| Channel | Where data is entered | Systems it touches | Where it is stored (if any) | Who it is sent to |
|---|---|---|---|---|
| [e.g. e-commerce] | [PSP-hosted page] | [none on our servers] | [none] | [PSP] |

## 3. Storage of account data
- Do you store the Primary Account Number (PAN)? **[Yes/No]**  — If yes, where and how is it protected (encryption, truncation, tokenization)? ___
- Do you store Sensitive Authentication Data (CVV, full track, PIN)? **Must be No after authorization.**

## 4. People, processes, systems in scope
List everything that stores, processes, or transmits cardholder data, **or could affect its security** (e.g. firewalls, admin workstations, the network segment):
- Systems: ___
- Third parties / PSPs: ___
- Personnel with access: ___

## 5. Scope reduction
- Segmentation in place to isolate the cardholder-data environment? **[Yes/No]** — describe: ___
- Using a PCI-listed P2PE solution and/or fully outsourced/redirected e-commerce? **[Yes/No]** — these can reduce your SAQ type.

## 6. Indicated SAQ type
Based on the above, the likely SAQ type is: **[A / A-EP / B / B-IP / C / C-VT / P2PE / D]**
_Confirm with the SentinelPanda SAQ wizard (sentinelpanda.com/self-assessment) and your acquirer._

## 7. Sign-off
Scope reviewed and confirmed accurate by: [Name / Title] · Date: [YYYY-MM-DD]
