Payment Security
DETAIL

PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ B) — Cardholder Data Security Controls for Imprint and Standalone Dial-Out Terminals

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

PCI DSS v4.0.1Self-Assessment Questionnaire (SAQ B) is a compliance assessment toolthat supports organizations in evaluating cardholder data securitycontrols specifically for imprint and standalone dial-out paymentterminals. The questionnaire is part of the Payment Card IndustryData Security Standard, which establishes requirements forsafeguarding payment card data and minimizing risks related topayment card processing environments.

Published by thePCI Security Standards Council, PCI DSS SAQ B is intended formerchants who do not store electronic cardholder data and onlyprocess card payments through non-integrated imprint or standalonedial-out terminals. The SAQ covers key areas such as physicalsecurity, device protection, and secure handling of cardholderinformation, ensuring that organizations meet industry-mandatedcybersecurity and data protection obligations.

Organizationscomplete the SAQ B as a self-validation exercise to demonstrateadherence to PCI DSS requirements. This process involves reviewingsecurity practices, documenting evidence of compliance, andaddressing any control gaps. Integration with broader complianceprograms and risk management initiatives allows organizations tostrengthen security posture and ensure ongoing regulatory compliance.

Why it Matters

PCI DSS v4.0.1SAQ B establishes clear requirements that help organizations protectpayment card data processed on imprint and standalone dial-outterminals.

Key benefitsinclude:

•  Enhance cardholder data protection

Reduce the riskof payment card data compromise by applying dedicated securitymeasures to isolated payment terminals.

•  Strengthen compliance support

Facilitatevalidation efforts and simplify reporting by providing targetedrequirements designed for specific payment terminal environments.

•  Improve audit readiness

Document andalign security practices, enabling organizations to respondconfidently during regulatory assessments or third-party audits.

•  Reduce fraud and data breaches

Lower thelikelihood of fraud incidents and breaches by minimizing the storageand transmission of sensitive cardholder data.

•  Increase operational focus

Alloworganizations to concentrate security resources on relevant controls,reducing complexity for environments not connected to broadernetworks.

How it Works

The PCI DSSv4.0.1 Self-Assessment Questionnaire (SAQ B) structures requirementsinto a set of focused security controls specifically fororganizations that process cardholder data exclusively via imprintmachines or standalone, dial-out payment terminals. The frameworkorganizes controls into distinct requirements, covering areas such asdata protection, physical device security, secure payment practices,and ongoing security monitoring. Each requirement addressesregulatory expectations for protecting cardholder information andpreventing unauthorized access, reflecting the broader PCI DSScontrol framework but scoped for environments with limited dataexposure.

In practice,organizations complete the SAQ B by assessing and documenting theirimplementation of required security controls for eligible paymentenvironments. Activities include restricting physical access tostandalone terminals, ensuring device integrity, maintaining secureconfigurations, and enforcing policies for secure cardholder datahandling. Regular self-assessment supports internal governance andrisk management by helping organizations verify the consistentapplication of security practices tailored to their specific paymentprocessing methods.

SmartSuiteenables organizations to operationalize PCI DSS SAQ B requirements byleveraging pre-built control libraries, tracking assessment evidence,and managing compliance documentation in a centralized workspace.Features such as compliance tracking, policy governance, andreporting dashboards streamline ongoing monitoring and support auditreadiness, while remediation workflows help organizations address anyidentified gaps in security or compliance.

Key Elements

•  Scope Definition and Applicability

Specifiesrequirements relevant to merchants using only imprint machines orstandalone dial-out terminals without electronic storage.

•  Cardholder Data Protection Requirements

Outlines dataprotection measures focused on limiting physical and logical accessto cardholder data.

•  Terminal Security Controls

Describescontrols for ensuring security and integrity of standalone dial-outpayment terminals.

•  Physical Security of Devices

Establishessafeguards to prevent unauthorized tampering or removal of paymentprocessing devices.

•  Access Management Procedures

Detailsprocesses for restricting personnel access to cardholder data andrelated devices.

•  Policy and Training Expectations

Definesexpectations for merchant security policies and mandatory staffsecurity awareness training.

Framework Scope

PCI DSS v4.0.1Self-Assessment Questionnaire (SAQ B) is adopted by merchantsutilizing standalone dial-out or imprint cardholder data terminals.The framework governs payment card processing environments withlimited connectivity, specifically where electronic cardholder datastorage is absent, and is commonly implemented when supportingcompliance assessments and adhering to data protection requirementsfor payment transactions.

Framework Objectives

PCI DSS v4.0.1Self-Assessment Questionnaire (SAQ B) guides organizations insecuring cardholder data processed by imprint and standalone dial-outterminals.

•  Safeguard cardholder data through effective security controlsand data protection measures

•  Strengthen cybersecurity governance for payment processingenvironments to reduce risk

•  Support compliance with regulatory and industry payment carddata requirements

•  Promote operational resilience by minimizing data breach andfraud risks

•  Enable ongoing audit readiness through documented evidence ofsecurity control effectiveness

•  Maintain robust risk management practices aligned with evolvingthreat landscapes PCI DSS v4.0.1 SAQ B is a targeted subset of PCIDSS requirements designed for merchants using imprint or standalonedial-out terminals. It aligns with broader cardholder data securitystandards such as PCI DSS, ISO 27001, and NIST CybersecurityFramework. Organizations use SAQ B for regulatory compliance whenminimizing cardholder data handling and streamlining assessmentefforts.

Common Framework Mappings

PCI DSS SAQ Brequirements are often mapped to other industry-recognized securityand privacy frameworks to ensure comprehensive protection ofcardholder data and to streamline regulatory compliance effortsacross multiple standards.

Mappedframeworks include:

CIS CriticalSecurity Controls

COBIT

GLBA SafeguardsRule

HIPAA SecurityRule

ISO/IEC 27001

ISO/IEC 27002

NISTCybersecurity Framework

NIST SP 800-53

SOC 2

At a Glance
PCI DSS v4.0.1 – SAQ B
  • checklist
    Classicifation
    Category
    info
    Payment Security
    Domain
    info
    Cybersecurity
    Framework Family
    info
    PCI Security Standards
  • info
    Regulatory Context
    Type
    info
    Assessment / Maturity Model
    Legal Instrument
    info
    Standard
    Sector
    info
    Financial Sector
    Industry
    info
    Payment & FinTech
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    Global
    Region Detail
    info
    Payment Card Industry Data Security Standard (PCI DSS), including its Self‑Assessment Questionnaire (SAQ) B—used for imprint machines and standalone dial‑out terminals—is developed and managed by the PCI Security Standards Council (PCI SSC). The PCI SSC is an international, industry-driven body founded by major payment card brands (Visa, MasterCard, American Express, Discover, and JCB). It operates on a global basis and is not tied to any specific country or governmental jurisdiction ([en.wikipedia.org](https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard?utm_source=openai)). Therefore, the Region Detail for PCI DSS v4.0.1 SAQ B reflects its nature as a globally applicable standard. The appropriate jurisdiction to record in the Region Detail field is: Global
    Publisher
    info
    Payment Card Industry Security Standards Council (PCI SSC)
  • published_with_changes
    Versioning
    Version
    info
    v4.0.1
    Effective Date
    info
    January 1, 2025
    Issue Date
    info
    June 11, 2024
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

The PCI DSS SAQ B (v4.0.1) is published by the PCI Security Standards Council and is publicly available for free download from the Council's website.License included with platform

Official Resources
PCI DSS v4.0.1 Standard
Defines the requirements for payment card security standards and related assessment procedures.
chevron_forward
PCI DSS v4.0.1 Self-Assessment Questionnaire Instructions and Guidelines
Provides detailed guidance on completing the self-assessment questionnaire.
chevron_forward
PCI DSS v4.0.1 Summary of Changes
Outlines the major updates and changes from previous versions.
chevron_forward
SMARTSUITE

How SmartSuite Supports PCI DSS v4.0.1 SAQ B

Manage PCI DSS compliance for merchants using standalone payment terminals by organizing SAQ B requirements, tracking security controls, and maintaining documentation supporting cardholder data protection.

SAQ B Requirement Library

Structure PCI DSS SAQ B requirements with mapped controls, ownership, and compliance activities.

Payment Terminal Asset Management

Maintain inventory of payment terminals and associated systems within the cardholder data environment.

Physical and Device Security Governance

Track physical security controls protecting payment terminals from tampering or unauthorized access.

Terminal Configuration and Security Monitoring

Manage terminal configuration standards, maintenance procedures, and device security monitoring.

Vendor and Service Provider Oversight

Track payment processor and service provider compliance documentation and responsibilities.

Self-Assessment and Compliance Reporting

Provide dashboards showing SAQ B completion status, requirement coverage, and outstanding compliance tasks.

Related frameworks

CIS Controls v8.1

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
ISO 27002:2022

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

Learn More
arrow_forward
NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

Learn More
arrow_forward
NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

Learn More
arrow_forward
SOC 2

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.

Learn More
arrow_forward
SWIFT CSCF

SWIFT Customer Security Framework establishes baseline cybersecurity controls for organizations using the SWIFT network to secure financial transactions.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ B) — Cardholder Data Security Controls for Imprint and Standalone Dial-Out Terminals

What is PCI DSS SAQ B used for?

PCI DSS SAQ B is designed for merchants who process cardholder data exclusively via imprint machines or standalone dial-out terminals with no electronic cardholder data storage. It helps organizations demonstrate compliance with the Payment Card Industry Data Security Standard (PCI DSS) requirements tailored to these environments, ensuring cardholder data is protected during processing.

Is completing PCI DSS SAQ B mandatory?

Yes, completion of PCI DSS SAQ B is typically required for eligible merchants by payment brands and acquiring banks. Compliance is not optional and is a prerequisite for accepting payment cards in the specified manner.

What environments are in scope for PCI DSS SAQ B?

SAQ B applies only to merchants that process card transactions using either manual imprint machines or standalone, dial-out payment terminals that connect directly to a payment processor and do not store cardholder data electronically. It excludes any environments with integrated point-of-sale systems, network connectivity, or electronic storage of cardholder data.

What are the key security controls required by PCI DSS SAQ B?

Key controls include restricting physical access to cardholder data, maintaining policies for device security, protecting devices from tampering, and ensuring that cardholder data is not stored electronically. Additionally, merchants must establish processes for incident response and periodically inspect devices.

How is PCI DSS SAQ B implemented in a merchant environment?

Implementation involves identifying all devices and processes in scope, applying the controls outlined in the SAQ, ensuring staff are trained on device security, and documenting procedures. Merchants should also regularly review compliance, inspect devices for tampering, and ensure no cardholder data is stored electronically.

How does PCI DSS SAQ B relate to other PCI DSS SAQs?

SAQ B is one of several assessment questionnaires, each designed for a specific merchant environment. SAQ B is the most restrictive, with the narrowest scope, while other SAQs apply to merchants with more complex or integrated payment processing environments. Choosing the correct SAQ is critical for accurate attestation.

What ongoing compliance activities are required for PCI DSS SAQ B?

Ongoing activities include periodic inspections of payment terminals, maintaining updated device lists, staff training, regular reviews of physical and procedural controls, and annual SAQ completion and attestation. Merchants must also promptly address any identified security risks or device tampering incidents.

How would SmartSuite support PCI DSS SAQ B?

SmartSuite can support PCI DSS SAQ B compliance by providing tools for risk tracking, managing required controls, and tracking device inventories. It enables evidence collection for compliance activities, helps maintain audit readiness by documenting inspections and training, and streamlines reporting for annual attestation and ongoing monitoring.

NEXT STEP

Put CRI Profile into action with SmartSuite

Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.

Explore in SmartSuite
chevron_forward
View all Frameworks
chevron_forward