Payment Security
DETAIL

PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ B-IP) — Cardholder Data Security Controls for Standalone IP-Connected Terminals

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

PCI DSS v4.0.1Self-Assessment Questionnaire (SAQ B-IP) is a cybersecurity andcompliance assessment tool that enables merchants with standaloneIP-connected payment terminals to validate their handling ofcardholder data and adherence to critical security controls. The SAQB-IP specifically addresses the unique requirements for securing carddata in environments with minimal payment processing systemsconnected via IP.

Developed andpublished by the PCI Security Standards Council, the PCI DSS SAQ B-IPis used by merchants, compliance teams, and assessors to evaluatetechnical and procedural safeguards related to data protection,network security, and compliance oversight. Its focus areas includesecuring payment terminals, managing network access, protectingstored cardholder data, and enabling compliance with the broader PCIDSS ecosystem.

Organizationscomplete the SAQ B-IP by self-attesting to their implementation ofrequired security controls, documenting compliance measures, andmitigating risk through regular assessments. The tool supports riskmanagement, audit readiness, and alignment with industry card paymentstandards, helping organizations demonstrate compliance to acquirersand regulatory bodies.

Why it Matters

PCI DSS v4.0.1SAQ B-IP establishes essential security controls to protectcardholder data in organizations using standalone IP-connectedpayment terminals.

Key benefitsinclude:

•  Strengthen cardholder data protection

Reduce thelikelihood of data compromise by requiring controls tailoredspecifically to terminals processing payment card information.

•  Improve security oversight

Enhancevisibility into payment terminal environments, promoting regularmonitoring and effective security policy enforcement.

•  Enhance regulatory alignment

Supportcompliance with global payment card industry mandates and facilitateadherence to broader financial data protection requirements.

•  Increase audit readiness

Enableorganizations to efficiently document and demonstrate their securitypractices during compliance assessments and external audits.

•  Reduce operational risk

Lower the riskof business disruption and reputational harm resulting from securitybreaches affecting payment processing systems.

How it Works

PCI DSS v4.0.1Self-Assessment Questionnaire (SAQ B-IP) structures its requirementsaround specific security controls and regulatory requirementsnecessary for organizations handling cardholder data throughstandalone IP-connected payment terminals. The SAQ B-IP encompasses afocused subset of PCI DSS control objectives related to physical andlogical security, network segmentation, regular vulnerabilitymanagement, and secure transmission of cardholder data. Theserequirements are outlined in a checklist format, guidingorganizations through each critical safeguard and complianceobligation.

Organizationsimplement PCI DSS SAQ B-IP by validating that only eligible paymentterminals are in use, applying required security controls, anddocumenting adherence to each requirement. Typical implementationactivities include isolating cardholder data environments,configuring firewalls, maintaining secure configurations forterminals, and documenting procedures for incident response andongoing monitoring. Organizations periodically review controls,perform self-assessments for compliance, and ensure personnel aretrained in secure payment processing and threat mitigation practices.

SmartSuiteenables organizations to operationalize PCI DSS SAQ B-IP byleveraging integrated control libraries and configurable compliancetracking. Risk registers within the platform help document potentialexposures related to payment environments, while policy governanceand evidence collection tools facilitate ongoing documentation andaudit readiness. Reporting dashboards and remediation workflowssupport continuous monitoring, enabling organizations to trackcompliance status, manage corrective actions, and maintain governanceover payment security controls.

Key Elements

•  Network Segmentation Requirements

Describesstructural measures for isolating cardholder data environments fromother networks.

•  Terminal Security Controls

Specifiesprotections for standalone IP-connected payment terminals againstunauthorized access and threats.

•  Data Transmission Safeguards

Outlinesrequirements for encrypting and securing cardholder data duringtransmission over open networks.

•  Access Management Practices

Establishesprocesses for granting, restricting, and monitoring access tosensitive data and systems.

•  Vulnerability Management Procedures

Defines periodicassessment activities for identifying and addressing securityweaknesses in the environment.

•  Physical Security Measures

Describesprotocols for securing areas and devices handling cardholder datafrom physical threats.

•  Security Policy Governance

Organizes thedocumentation and oversight mechanisms for maintaining consistentcompliance and enforcement.

Framework Scope

PCI DSS v4.0.1SAQ B-IP is adopted by merchants processing card payments solelythrough standalone IP-connected payment terminals. This frameworkgoverns payment card data environments restricted to these terminalsand networking components, and is typically implemented forsupporting compliance with payment card industry requirements,reducing payment data risk, and demonstrating security controleffectiveness.

Framework Objectives

PCI DSS v4.0.1SAQ B-IP defines essential cybersecurity and data protectionobjectives for standalone IP-connected payment terminals.

•  Safeguard cardholder data through robust security controls andrisk management practices

•  Ensure compliance with regulatory and industry requirements forpayment environments

•  Strengthen governance and oversight of payment terminalcybersecurity

•  Enhance operational resilience by reducing vulnerabilities instandalone payment terminals

•  Improve audit readiness and demonstrate effective controlimplementation

•  Support ongoing data protection and privacy for cardholderinformation PCI DSS SAQ B-IP aligns with data security requirementssimilar to those in NIST SP 800-53 and ISO 27001, focusingspecifically on standalone IP-connected payment terminals.Organizations typically complete SAQ B-IP for self-attestation of PCIDSS compliance, especially when seeking to simplify compliance forcard-present transaction environments using such terminals.

Common Framework Mappings

Organizationsoften map PCI DSS SAQ B-IP to other widely accepted securityframeworks to streamline compliance efforts and ensure acomprehensive approach to cardholder data protection and regulatoryrequirements.

Mappedframeworks include:

CIS Controls

COBIT

HIPAA SecurityRule

ISO/IEC 27001

ISO/IEC 27017

ISO/IEC 27701

NISTCybersecurity Framework

NIST SP 800-53

SOC 2

At a Glance
PCI DSS v4.0.1 – SAQ B‑IP
  • checklist
    Classicifation
    Category
    info
    Payment Security
    Domain
    info
    Cybersecurity
    Framework Family
    info
    PCI Security Standards
  • info
    Regulatory Context
    Type
    info
    Assessment / Maturity Model
    Legal Instrument
    info
    Standard
    Sector
    info
    Financial Sector
    Industry
    info
    Payment & FinTech
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    Global
    Region Detail
    info
    The specific jurisdiction associated with the **PCI DSS v4.0.1 Self‑Assessment Questionnaire (SAQ B‑IP)**—namely, the issuing “region” of this regulation or framework—is: United States
    Publisher
    info
    Payment Card Industry Security Standards Council (PCI SSC)
  • published_with_changes
    Versioning
    Version
    info
    v4.0.1
    Effective Date
    info
    June 11, 2024
    Issue Date
    info
    June 11, 2024
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

The PCI DSS v4.0.1 SAQ B-IP is published by the PCI Security Standards Council and is freely available for download from the PCI SSC website.License included with platform

Official Resources
PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ B-IP)
Provides guidance for assessing cardholder data security controls for standalone IP-connected terminals.
chevron_forward
PCI Data Security Standard Requirements and Testing Procedures v4.0
Defines comprehensive security requirements for protecting cardholder data in payment environments.
chevron_forward
PCI DSS Quick Reference Guide
Describes key concepts and security requirements of PCI DSS v4.0.
chevron_forward
SMARTSUITE

How SmartSuite Supports PCI DSS SAQ B-IP

Manage PCI DSS v4.0.1 SAQ B-IP requirements by tracking controls for IP-connected payment terminals, maintaining evidence, and ensuring compliance for merchants with standalone payment environments.

SAQ B-IP Control Library

Organize PCI DSS controls specific to standalone IP-connected terminal environments.

Payment Environment Scoping and Segmentation

Define cardholder data environment (CDE) boundaries and track network segmentation controls.

Terminal Security and Configuration Management

Track secure configurations, device hardening, and approved payment terminal controls.

Vulnerability and Patch Management for Payment Systems

Monitor vulnerabilities, patch status, and remediation activities for connected payment systems.

Evidence Collection and SAQ Documentation

Capture required evidence and responses supporting SAQ B-IP self-assessment submissions.

Compliance Reporting and Attestation Readiness

Provide dashboards showing control status, gaps, and readiness for PCI attestation.

Related frameworks

CIS Controls v8.1

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
ISO 27002:2022

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

Learn More
arrow_forward
NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

Learn More
arrow_forward
NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

Learn More
arrow_forward
SOC 2

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.

Learn More
arrow_forward
SWIFT CSCF

SWIFT Customer Security Framework establishes baseline cybersecurity controls for organizations using the SWIFT network to secure financial transactions.

Learn More
arrow_forward
Cyber Essentials

Cyber Essentials is a UK government-backed certification specifying basic controls to protect organizations against common cyber threats.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For PCI DSS v4.0.1 SAQ B-IP (Cardholder Data Security Controls for Standalone IP-Connected Terminals)

What is PCI DSS v4.0.1 SAQ B-IP used for?

PCI DSS v4.0.1 SAQ B-IP is used by merchants that process cardholder data solely via standalone IP-connected payment terminals. Its primary purpose is to establish the security controls necessary to protect cardholder data during payment transactions and maintain PCI DSS compliance.

Is PCI DSS SAQ B-IP mandatory or certifiable?

PCI DSS compliance, including SAQ B-IP, is mandatory for all organizations that store, process, or transmit cardholder data. Merchants use SAQ B-IP to self-assess their compliance, but a formal certification may still require validation and submission to acquiring banks or card brands as prescribed.

Who is eligible to use SAQ B-IP?

SAQ B-IP is applicable to merchants who use only standalone, PIN Transaction Security (PTS)-approved payment terminals with IP connectivity, and that have no electronic storage of cardholder data. Merchants with more complex environments or additional payment channels must use other appropriate SAQs.

What are the key security controls required by PCI DSS SAQ B-IP?

Key controls required by SAQ B-IP include secure configuration and management of payment terminals, strong network segmentation, firewall protection, encrypted communications, strong passwords, and maintaining updated anti-malware solutions. Physical security measures and restricted access to terminals are also essential.

How should an organization implement PCI DSS SAQ B-IP controls?

Implementation involves performing an environment review, ensuring only eligible devices are in use, segmenting payment systems from other networks, configuring firewalls, and establishing security policies and procedures. Ongoing employee training and regular system monitoring are critical for sustained compliance.

How does SAQ B-IP relate to other PCI DSS SAQs or validation types?

SAQ B-IP is one of several PCI DSS Self-Assessment Questionnaires, each tailored for different merchant environments. Organizations should review all SAQ eligibility criteria to select the correct form; using the wrong SAQ may result in non-compliance.

What ongoing activities are required to maintain PCI DSS SAQ B-IP compliance?

Maintaining compliance requires annual completion of the SAQ, regular network and control monitoring, periodic vulnerability scans, staff security awareness training, and prompt remediation of identified issues. Documentation and evidence of ongoing compliance activities must be retained for review.

How would SmartSuite support PCI DSS v4.0.1 SAQ B-IP?

SmartSuite can help organizations manage PCI DSS SAQ B-IP requirements by tracking risks, assigning and monitoring control ownership, collecting compliance evidence, and maintaining audit trails. The platform supports audit readiness with centralized documentation, workflow automation, and compliance reporting to streamline assessment and validation processes.

NEXT STEP

Put CRI Profile into action with SmartSuite

Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.

Explore in SmartSuite
chevron_forward
View all Frameworks
chevron_forward