PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ B) — Cardholder Data Security Controls for Imprint and Standalone Dial-Out Terminals

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
PCI DSS v4.0.1Self-Assessment Questionnaire (SAQ B) is a compliance assessment toolthat supports organizations in evaluating cardholder data securitycontrols specifically for imprint and standalone dial-out paymentterminals. The questionnaire is part of the Payment Card IndustryData Security Standard, which establishes requirements forsafeguarding payment card data and minimizing risks related topayment card processing environments.
Published by thePCI Security Standards Council, PCI DSS SAQ B is intended formerchants who do not store electronic cardholder data and onlyprocess card payments through non-integrated imprint or standalonedial-out terminals. The SAQ covers key areas such as physicalsecurity, device protection, and secure handling of cardholderinformation, ensuring that organizations meet industry-mandatedcybersecurity and data protection obligations.
Organizationscomplete the SAQ B as a self-validation exercise to demonstrateadherence to PCI DSS requirements. This process involves reviewingsecurity practices, documenting evidence of compliance, andaddressing any control gaps. Integration with broader complianceprograms and risk management initiatives allows organizations tostrengthen security posture and ensure ongoing regulatory compliance.
Why it Matters
PCI DSS v4.0.1SAQ B establishes clear requirements that help organizations protectpayment card data processed on imprint and standalone dial-outterminals.
Key benefitsinclude:
• Enhance cardholder data protection
Reduce the riskof payment card data compromise by applying dedicated securitymeasures to isolated payment terminals.
• Strengthen compliance support
Facilitatevalidation efforts and simplify reporting by providing targetedrequirements designed for specific payment terminal environments.
• Improve audit readiness
Document andalign security practices, enabling organizations to respondconfidently during regulatory assessments or third-party audits.
• Reduce fraud and data breaches
Lower thelikelihood of fraud incidents and breaches by minimizing the storageand transmission of sensitive cardholder data.
• Increase operational focus
Alloworganizations to concentrate security resources on relevant controls,reducing complexity for environments not connected to broadernetworks.
How it Works
The PCI DSSv4.0.1 Self-Assessment Questionnaire (SAQ B) structures requirementsinto a set of focused security controls specifically fororganizations that process cardholder data exclusively via imprintmachines or standalone, dial-out payment terminals. The frameworkorganizes controls into distinct requirements, covering areas such asdata protection, physical device security, secure payment practices,and ongoing security monitoring. Each requirement addressesregulatory expectations for protecting cardholder information andpreventing unauthorized access, reflecting the broader PCI DSScontrol framework but scoped for environments with limited dataexposure.
In practice,organizations complete the SAQ B by assessing and documenting theirimplementation of required security controls for eligible paymentenvironments. Activities include restricting physical access tostandalone terminals, ensuring device integrity, maintaining secureconfigurations, and enforcing policies for secure cardholder datahandling. Regular self-assessment supports internal governance andrisk management by helping organizations verify the consistentapplication of security practices tailored to their specific paymentprocessing methods.
SmartSuiteenables organizations to operationalize PCI DSS SAQ B requirements byleveraging pre-built control libraries, tracking assessment evidence,and managing compliance documentation in a centralized workspace.Features such as compliance tracking, policy governance, andreporting dashboards streamline ongoing monitoring and support auditreadiness, while remediation workflows help organizations address anyidentified gaps in security or compliance.
Key Elements
• Scope Definition and Applicability
Specifiesrequirements relevant to merchants using only imprint machines orstandalone dial-out terminals without electronic storage.
• Cardholder Data Protection Requirements
Outlines dataprotection measures focused on limiting physical and logical accessto cardholder data.
• Terminal Security Controls
Describescontrols for ensuring security and integrity of standalone dial-outpayment terminals.
• Physical Security of Devices
Establishessafeguards to prevent unauthorized tampering or removal of paymentprocessing devices.
• Access Management Procedures
Detailsprocesses for restricting personnel access to cardholder data andrelated devices.
• Policy and Training Expectations
Definesexpectations for merchant security policies and mandatory staffsecurity awareness training.
Framework Scope
PCI DSS v4.0.1Self-Assessment Questionnaire (SAQ B) is adopted by merchantsutilizing standalone dial-out or imprint cardholder data terminals.The framework governs payment card processing environments withlimited connectivity, specifically where electronic cardholder datastorage is absent, and is commonly implemented when supportingcompliance assessments and adhering to data protection requirementsfor payment transactions.
Framework Objectives
PCI DSS v4.0.1Self-Assessment Questionnaire (SAQ B) guides organizations insecuring cardholder data processed by imprint and standalone dial-outterminals.
• Safeguard cardholder data through effective security controlsand data protection measures
• Strengthen cybersecurity governance for payment processingenvironments to reduce risk
• Support compliance with regulatory and industry payment carddata requirements
• Promote operational resilience by minimizing data breach andfraud risks
• Enable ongoing audit readiness through documented evidence ofsecurity control effectiveness
• Maintain robust risk management practices aligned with evolvingthreat landscapes PCI DSS v4.0.1 SAQ B is a targeted subset of PCIDSS requirements designed for merchants using imprint or standalonedial-out terminals. It aligns with broader cardholder data securitystandards such as PCI DSS, ISO 27001, and NIST CybersecurityFramework. Organizations use SAQ B for regulatory compliance whenminimizing cardholder data handling and streamlining assessmentefforts.
Common Framework Mappings
PCI DSS SAQ Brequirements are often mapped to other industry-recognized securityand privacy frameworks to ensure comprehensive protection ofcardholder data and to streamline regulatory compliance effortsacross multiple standards.
Mappedframeworks include:
CIS CriticalSecurity Controls
COBIT
GLBA SafeguardsRule
HIPAA SecurityRule
ISO/IEC 27001
ISO/IEC 27002
NISTCybersecurity Framework
NIST SP 800-53
SOC 2
- ClassicifationCategoryPayment SecurityDomainCybersecurityFramework FamilyPCI Security Standards
- Regulatory ContextTypeAssessment / Maturity ModelLegal InstrumentStandardSectorFinancial SectorIndustryPayment & FinTech
- Region / PublisherRegionGlobalRegion DetailPayment Card Industry Data Security Standard (PCI DSS), including its Self‑Assessment Questionnaire (SAQ) B—used for imprint machines and standalone dial‑out terminals—is developed and managed by the PCI Security Standards Council (PCI SSC). The PCI SSC is an international, industry-driven body founded by major payment card brands (Visa, MasterCard, American Express, Discover, and JCB). It operates on a global basis and is not tied to any specific country or governmental jurisdiction ([en.wikipedia.org](https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard?utm_source=openai)). Therefore, the Region Detail for PCI DSS v4.0.1 SAQ B reflects its nature as a globally applicable standard. The appropriate jurisdiction to record in the Region Detail field is: GlobalPublisherPayment Card Industry Security Standards Council (PCI SSC)
- VersioningVersionv4.0.1Effective DateJanuary 1, 2025Issue DateJune 11, 2024
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
The PCI DSS SAQ B (v4.0.1) is published by the PCI Security Standards Council and is publicly available for free download from the Council's website.License included with platform
How SmartSuite Supports PCI DSS v4.0.1 SAQ B
Manage PCI DSS compliance for merchants using standalone payment terminals by organizing SAQ B requirements, tracking security controls, and maintaining documentation supporting cardholder data protection.
SAQ B Requirement Library
Structure PCI DSS SAQ B requirements with mapped controls, ownership, and compliance activities.
Payment Terminal Asset Management
Maintain inventory of payment terminals and associated systems within the cardholder data environment.
Physical and Device Security Governance
Track physical security controls protecting payment terminals from tampering or unauthorized access.
Terminal Configuration and Security Monitoring
Manage terminal configuration standards, maintenance procedures, and device security monitoring.
Vendor and Service Provider Oversight
Track payment processor and service provider compliance documentation and responsibilities.
Self-Assessment and Compliance Reporting
Provide dashboards showing SAQ B completion status, requirement coverage, and outstanding compliance tasks.
Related frameworks

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.
Frequently Asked Questions For PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ B) — Cardholder Data Security Controls for Imprint and Standalone Dial-Out Terminals
PCI DSS SAQ B is designed for merchants who process cardholder data exclusively via imprint machines or standalone dial-out terminals with no electronic cardholder data storage. It helps organizations demonstrate compliance with the Payment Card Industry Data Security Standard (PCI DSS) requirements tailored to these environments, ensuring cardholder data is protected during processing.
Yes, completion of PCI DSS SAQ B is typically required for eligible merchants by payment brands and acquiring banks. Compliance is not optional and is a prerequisite for accepting payment cards in the specified manner.
SAQ B applies only to merchants that process card transactions using either manual imprint machines or standalone, dial-out payment terminals that connect directly to a payment processor and do not store cardholder data electronically. It excludes any environments with integrated point-of-sale systems, network connectivity, or electronic storage of cardholder data.
Key controls include restricting physical access to cardholder data, maintaining policies for device security, protecting devices from tampering, and ensuring that cardholder data is not stored electronically. Additionally, merchants must establish processes for incident response and periodically inspect devices.
Implementation involves identifying all devices and processes in scope, applying the controls outlined in the SAQ, ensuring staff are trained on device security, and documenting procedures. Merchants should also regularly review compliance, inspect devices for tampering, and ensure no cardholder data is stored electronically.
SAQ B is one of several assessment questionnaires, each designed for a specific merchant environment. SAQ B is the most restrictive, with the narrowest scope, while other SAQs apply to merchants with more complex or integrated payment processing environments. Choosing the correct SAQ is critical for accurate attestation.
Ongoing activities include periodic inspections of payment terminals, maintaining updated device lists, staff training, regular reviews of physical and procedural controls, and annual SAQ completion and attestation. Merchants must also promptly address any identified security risks or device tampering incidents.
SmartSuite can support PCI DSS SAQ B compliance by providing tools for risk tracking, managing required controls, and tracking device inventories. It enables evidence collection for compliance activities, helps maintain audit readiness by documenting inspections and training, and streamlines reporting for annual attestation and ongoing monitoring.
Put CRI Profile into action with SmartSuite
Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.

