Payment Security
DETAIL

PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ B) — Cardholder Data Security Controls for Imprint and Standalone Dial-Out Terminals

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

arrow_back
arrow_forward

Overview

PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ B) is a compliance assessment tool that supports organizations in evaluating cardholder data security controls specifically for imprint and standalone dial-out payment terminals. The questionnaire is part of the Payment Card Industry Data Security Standard, which establishes requirements for safeguarding payment card data and minimizing risks related to payment card processing environments.

Published by the PCI Security Standards Council, PCI DSS SAQ B is intended for merchants who do not store electronic cardholder data and only process card payments through non-integrated imprint or standalone dial-out terminals. The SAQ covers key areas such as physical security, device protection, and secure handling of cardholder information, ensuring that organizations meet industry-mandated cybersecurity and data protection obligations.

Organizations complete the SAQ B as a self-validation exercise to demonstrate adherence to PCI DSS requirements. This process involves reviewing security practices, documenting evidence of compliance, and addressing any control gaps. Integration with broader compliance programs and risk management initiatives allows organizations to strengthen security posture and ensure ongoing regulatory compliance.

Why it Matters

PCI DSS v4.0.1 SAQ B establishes clear requirements that help organizations protect payment card data processed on imprint and standalone dial-out terminals.

Key benefits include:

  • Enhance cardholder data protection

Reduce the risk of unauthorized access and data exposure by implementing targeted security controls for imprint and dial-out terminal environments.

  • Simplify compliance scope

Restrict PCI DSS assessment requirements to the specific systems and processes in scope for SAQ B, reducing compliance burden and assessment efforts.

  • Improve security oversight

Establish clear accountability and control ownership for physical and logical security of payment terminals and cardholder data.

  • Increase audit readiness

Maintain structured documentation and evidence of security controls to support efficient PCI DSS assessments and streamlining compliance reporting.

  • Promote operational resilience

Reduce disruption risks by implementing security measures that restrict physical access and protect cardholder data throughout terminal operations.

How it Works

PCI DSS v4.0.1 SAQ B is structured as a targeted self-assessment questionnaire for merchants that process cardholder data using imprint machines or standalone dial-out terminals not connected to broader networks. The SAQ organizes requirements into focused control domains addressing physical security, access controls, and data requirements, tailored to the reduced scope of these terminal environments.

Organizations implement SAQ B by confirming their processing methods qualify for SAQ B scope, applying the required physical and logical security controls to their terminals, and maintaining documentation for compliance validation. Typical activities include restricting physical access to terminals, ensuring secure cardholder data processing, implementing internal governance and policy management, and conducting periodic compliance reviews to demonstrate ongoing adherence to PCI DSS security standards.

With SmartSuite, organizations can operationalize SAQ B compliance by leveraging pre-built control libraries mapped to SAQ B requirements, maintaining risk registers, and managing policy governance for payment terminal security. The platform supports evidence collection, compliance tracking, and reporting dashboards that provide visibility into control status and readiness for PCI DSS assessment efforts.

Key Elements

  • Physical Terminal Security Controls

Specifies physical safeguards for protecting imprint machines and standalone terminals from unauthorized access or tampering.

  • Cardholder Data Handling Requirements

Describes controls for securing cardholder data processed through imprint or dial-out terminal environments.

  • Access Control and User Management

Establishes criteria for restricting physical and logical access to payment terminals and associated cardholder data.

  • Security Policy and Governance

Outlines documentation and policy requirements for maintaining internal governance over terminal security practices.

  • Incident Response Procedures

Defines processes for identifying and responding to security breaches or suspected compromise of payment terminals.

  • Vendor and Service Provider Oversight

Describes responsibilities for managing third-party service providers with access to terminal environments.

Framework Scope

PCI DSS v4.0.1 SAQ B is used by merchants that process cardholder data exclusively through imprint machines or standalone dial-out terminals not connected to any other systems or networks. It governs physical terminal environments and associated security practices, and is typically implemented to simplify PCI DSS compliance scope, protect cardholder data, and support assurance programs for payment terminal security.

Framework Objectives

PCI DSS v4.0.1 SAQ B defines targeted security controls for protecting cardholder data processed on imprint and standalone dial-out terminals.

Protect cardholder data through physical security controls and terminal access restrictions

Simplify PCI DSS compliance scope for merchants using qualifying terminal environments

Strengthen governance and oversight of payment terminal security practices

Enhance data protection and reduce the risk of cardholder data compromise

Support audit readiness through structured documentation and compliance monitoring

Promote operational resilience by securing physical and logical access to payment terminals

Framework in Context

PCI DSS v4.0.1 SAQ B applies a targeted subset of PCI DSS v4.0.1 requirements to merchants using imprint machines or standalone dial-out terminals. Organizations use it to meet PCI DSS obligations within a simplified compliance scope, demonstrating adequate protection for cardholder data in low-complexity terminal environments.

Common Framework Mappings

PCI DSS v4.0.1 SAQ B is commonly mapped to broader payment security and information security frameworks to demonstrate control coverage and align security practices across payment environments.

Mapped frameworks include:

ISO/IEC 27001

ISO/IEC 27002

NIST Cybersecurity Framework

NIST SP 800-53

PCI DSS v4.0.1

SOC 2

At a Glance
PCI DSS v4.0.1 – SAQ B
  • checklist
    Classification
    Category
    info
    Payment Security
    Domain
    info
    Cybersecurity
    Framework Family
    info
    PCI Security Standards
  • info
    Regulatory Context
    Type
    info
    Assessment / Maturity Model
    Legal Instrument
    info
    Standard
    Sector
    info
    Financial Sector
    Industry
    info
    Payment & FinTech
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    Global
    Region Detail
    info
    Payment Card Industry Data Security Standard (PCI DSS), including its Self‑Assessment Questionnaire (SAQ) B—used for imprint machines and standalone dial‑out terminals—is developed and managed by the PCI Security Standards Council (PCI SSC). The PCI SSC is an international, industry-driven body founded by major payment card brands (Visa, MasterCard, American Express, Discover, and JCB). It operates on a global basis and is not tied to any specific country or governmental jurisdiction ([en.wikipedia.org](https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard?utm_source=openai)). Therefore, the Region Detail for PCI DSS v4.0.1 SAQ B reflects its nature as a globally applicable standard. The appropriate jurisdiction to record in the Region Detail field is: Global
    Publisher
    info
    Payment Card Industry Security Standards Council (PCI SSC)
  • published_with_changes
    Versioning
    Version
    info
    v4.0.1
    Effective Date
    info
    January 1, 2025
    Issue Date
    info
    June 11, 2024
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

The PCI DSS SAQ B (v4.0.1) is published by the PCI Security Standards Council and is publicly available for free download from the Council's website.License included with platform

Official Resources
PCI DSS v4.0.1 Standard
Defines the requirements for payment card security standards and related assessment procedures.
chevron_forward
PCI DSS v4.0.1 Self-Assessment Questionnaire Instructions and Guidelines
Provides detailed guidance on completing the self-assessment questionnaire.
chevron_forward
PCI DSS v4.0.1 Summary of Changes
Outlines the major updates and changes from previous versions.
chevron_forward
SMARTSUITE

How SmartSuite Supports PCI DSS v4.0.1 SAQ B

Manage PCI DSS compliance for merchants using standalone payment terminals by organizing SAQ B requirements, tracking security controls, and maintaining documentation supporting cardholder data protection.

SAQ B Requirement Library

Structure PCI DSS SAQ B requirements with mapped controls, ownership, and compliance activities.

Payment Terminal Asset Management

Maintain inventory of payment terminals and associated systems within the cardholder data environment.

Physical and Device Security Governance

Track physical security controls protecting payment terminals from tampering or unauthorized access.

Terminal Configuration and Security Monitoring

Manage terminal configuration standards, maintenance procedures, and device security monitoring.

Vendor and Service Provider Oversight

Track payment processor and service provider compliance documentation and responsibilities.

Self-Assessment and Compliance Reporting

Provide dashboards showing SAQ B completion status, requirement coverage, and outstanding compliance tasks.

Related frameworks

CIS Controls v8.1

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
ISO 27002:2022

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

Learn More
arrow_forward
NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

Learn More
arrow_forward
NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

Learn More
arrow_forward
SOC 2

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.

Learn More
arrow_forward
SWIFT CSCF

SWIFT Customer Security Framework establishes baseline cybersecurity controls for organizations using the SWIFT network to secure financial transactions.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ B) — Cardholder Data Security Controls for Imprint and Standalone Dial-Out Terminals

What is PCI DSS SAQ B used for?

PCI DSS SAQ B is designed for merchants who process cardholder data exclusively via imprint machines or standalone dial-out terminals with no electronic cardholder data storage. It helps organizations demonstrate compliance with the Payment Card Industry Data Security Standard (PCI DSS) requirements tailored to these environments, ensuring cardholder data is protected during processing.

Is completing PCI DSS SAQ B mandatory?

Yes, completion of PCI DSS SAQ B is typically required for eligible merchants by payment brands and acquiring banks. Compliance is not optional and is a prerequisite for accepting payment cards in the specified manner.

What environments are in scope for PCI DSS SAQ B?

SAQ B applies only to merchants that process card transactions using either manual imprint machines or standalone, dial-out payment terminals that connect directly to a payment processor and do not store cardholder data electronically. It excludes any environments with integrated point-of-sale systems, network connectivity, or electronic storage of cardholder data.

What are the key security controls required by PCI DSS SAQ B?

Key controls include restricting physical access to cardholder data, maintaining policies for device security, protecting devices from tampering, and ensuring that cardholder data is not stored electronically. Additionally, merchants must establish processes for incident response and periodically inspect devices.

How is PCI DSS SAQ B implemented in a merchant environment?

Implementation involves identifying all devices and processes in scope, applying the controls outlined in the SAQ, ensuring staff are trained on device security, and documenting procedures. Merchants should also regularly review compliance, inspect devices for tampering, and ensure no cardholder data is stored electronically.

How does PCI DSS SAQ B relate to other PCI DSS SAQs?

SAQ B is one of several assessment questionnaires, each designed for a specific merchant environment. SAQ B is the most restrictive, with the narrowest scope, while other SAQs apply to merchants with more complex or integrated payment processing environments. Choosing the correct SAQ is critical for accurate attestation.

What ongoing compliance activities are required for PCI DSS SAQ B?

Ongoing activities include periodic inspections of payment terminals, maintaining updated device lists, staff training, regular reviews of physical and procedural controls, and annual SAQ completion and attestation. Merchants must also promptly address any identified security risks or device tampering incidents.

How would SmartSuite support PCI DSS SAQ B?

SmartSuite can support PCI DSS SAQ B compliance by providing tools for risk tracking, managing required controls, and tracking device inventories. It enables evidence collection for compliance activities, helps maintain audit readiness by documenting inspections and training, and streamlines reporting for annual attestation and ongoing monitoring.

Operationalize PCI DSS 4.0.1 SAQ B with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

Schedule a Demo
chevron_forward
Demo Library
chevron_forward