PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ B) — Cardholder Data Security Controls for Imprint and Standalone Dial-Out Terminals

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ B) is a compliance assessment tool that supports organizations in evaluating cardholder data security controls specifically for imprint and standalone dial-out payment terminals. The questionnaire is part of the Payment Card Industry Data Security Standard, which establishes requirements for safeguarding payment card data and minimizing risks related to payment card processing environments.
Published by the PCI Security Standards Council, PCI DSS SAQ B is intended for merchants who do not store electronic cardholder data and only process card payments through non-integrated imprint or standalone dial-out terminals. The SAQ covers key areas such as physical security, device protection, and secure handling of cardholder information, ensuring that organizations meet industry-mandated cybersecurity and data protection obligations.
Organizations complete the SAQ B as a self-validation exercise to demonstrate adherence to PCI DSS requirements. This process involves reviewing security practices, documenting evidence of compliance, and addressing any control gaps. Integration with broader compliance programs and risk management initiatives allows organizations to strengthen security posture and ensure ongoing regulatory compliance.
Why it Matters
PCI DSS v4.0.1 SAQ B establishes clear requirements that help organizations protect payment card data processed on imprint and standalone dial-out terminals.
Key benefits include:
- Enhance cardholder data protection
Reduce the risk of unauthorized access and data exposure by implementing targeted security controls for imprint and dial-out terminal environments.
- Simplify compliance scope
Restrict PCI DSS assessment requirements to the specific systems and processes in scope for SAQ B, reducing compliance burden and assessment efforts.
- Improve security oversight
Establish clear accountability and control ownership for physical and logical security of payment terminals and cardholder data.
- Increase audit readiness
Maintain structured documentation and evidence of security controls to support efficient PCI DSS assessments and streamlining compliance reporting.
- Promote operational resilience
Reduce disruption risks by implementing security measures that restrict physical access and protect cardholder data throughout terminal operations.
How it Works
PCI DSS v4.0.1 SAQ B is structured as a targeted self-assessment questionnaire for merchants that process cardholder data using imprint machines or standalone dial-out terminals not connected to broader networks. The SAQ organizes requirements into focused control domains addressing physical security, access controls, and data requirements, tailored to the reduced scope of these terminal environments.
Organizations implement SAQ B by confirming their processing methods qualify for SAQ B scope, applying the required physical and logical security controls to their terminals, and maintaining documentation for compliance validation. Typical activities include restricting physical access to terminals, ensuring secure cardholder data processing, implementing internal governance and policy management, and conducting periodic compliance reviews to demonstrate ongoing adherence to PCI DSS security standards.
With SmartSuite, organizations can operationalize SAQ B compliance by leveraging pre-built control libraries mapped to SAQ B requirements, maintaining risk registers, and managing policy governance for payment terminal security. The platform supports evidence collection, compliance tracking, and reporting dashboards that provide visibility into control status and readiness for PCI DSS assessment efforts.
Key Elements
- Physical Terminal Security Controls
Specifies physical safeguards for protecting imprint machines and standalone terminals from unauthorized access or tampering.
- Cardholder Data Handling Requirements
Describes controls for securing cardholder data processed through imprint or dial-out terminal environments.
- Access Control and User Management
Establishes criteria for restricting physical and logical access to payment terminals and associated cardholder data.
- Security Policy and Governance
Outlines documentation and policy requirements for maintaining internal governance over terminal security practices.
- Incident Response Procedures
Defines processes for identifying and responding to security breaches or suspected compromise of payment terminals.
- Vendor and Service Provider Oversight
Describes responsibilities for managing third-party service providers with access to terminal environments.
Framework Scope
PCI DSS v4.0.1 SAQ B is used by merchants that process cardholder data exclusively through imprint machines or standalone dial-out terminals not connected to any other systems or networks. It governs physical terminal environments and associated security practices, and is typically implemented to simplify PCI DSS compliance scope, protect cardholder data, and support assurance programs for payment terminal security.
Framework Objectives
PCI DSS v4.0.1 SAQ B defines targeted security controls for protecting cardholder data processed on imprint and standalone dial-out terminals.
Protect cardholder data through physical security controls and terminal access restrictions
Simplify PCI DSS compliance scope for merchants using qualifying terminal environments
Strengthen governance and oversight of payment terminal security practices
Enhance data protection and reduce the risk of cardholder data compromise
Support audit readiness through structured documentation and compliance monitoring
Promote operational resilience by securing physical and logical access to payment terminals
Framework in Context
PCI DSS v4.0.1 SAQ B applies a targeted subset of PCI DSS v4.0.1 requirements to merchants using imprint machines or standalone dial-out terminals. Organizations use it to meet PCI DSS obligations within a simplified compliance scope, demonstrating adequate protection for cardholder data in low-complexity terminal environments.
Common Framework Mappings
PCI DSS v4.0.1 SAQ B is commonly mapped to broader payment security and information security frameworks to demonstrate control coverage and align security practices across payment environments.
Mapped frameworks include:
ISO/IEC 27001
ISO/IEC 27002
NIST Cybersecurity Framework
NIST SP 800-53
PCI DSS v4.0.1
SOC 2
- ClassificationCategoryPayment SecurityDomainCybersecurityFramework FamilyPCI Security Standards
- Regulatory ContextTypeAssessment / Maturity ModelLegal InstrumentStandardSectorFinancial SectorIndustryPayment & FinTech
- Region / PublisherRegionGlobalRegion DetailPayment Card Industry Data Security Standard (PCI DSS), including its Self‑Assessment Questionnaire (SAQ) B—used for imprint machines and standalone dial‑out terminals—is developed and managed by the PCI Security Standards Council (PCI SSC). The PCI SSC is an international, industry-driven body founded by major payment card brands (Visa, MasterCard, American Express, Discover, and JCB). It operates on a global basis and is not tied to any specific country or governmental jurisdiction ([en.wikipedia.org](https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard?utm_source=openai)). Therefore, the Region Detail for PCI DSS v4.0.1 SAQ B reflects its nature as a globally applicable standard. The appropriate jurisdiction to record in the Region Detail field is: GlobalPublisherPayment Card Industry Security Standards Council (PCI SSC)
- VersioningVersionv4.0.1Effective DateJanuary 1, 2025Issue DateJune 11, 2024
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
The PCI DSS SAQ B (v4.0.1) is published by the PCI Security Standards Council and is publicly available for free download from the Council's website.License included with platform
How SmartSuite Supports PCI DSS v4.0.1 SAQ B
Manage PCI DSS compliance for merchants using standalone payment terminals by organizing SAQ B requirements, tracking security controls, and maintaining documentation supporting cardholder data protection.
SAQ B Requirement Library
Structure PCI DSS SAQ B requirements with mapped controls, ownership, and compliance activities.
Payment Terminal Asset Management
Maintain inventory of payment terminals and associated systems within the cardholder data environment.
Physical and Device Security Governance
Track physical security controls protecting payment terminals from tampering or unauthorized access.
Terminal Configuration and Security Monitoring
Manage terminal configuration standards, maintenance procedures, and device security monitoring.
Vendor and Service Provider Oversight
Track payment processor and service provider compliance documentation and responsibilities.
Self-Assessment and Compliance Reporting
Provide dashboards showing SAQ B completion status, requirement coverage, and outstanding compliance tasks.
Related frameworks

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.
Frequently Asked Questions For PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ B) — Cardholder Data Security Controls for Imprint and Standalone Dial-Out Terminals
PCI DSS SAQ B is designed for merchants who process cardholder data exclusively via imprint machines or standalone dial-out terminals with no electronic cardholder data storage. It helps organizations demonstrate compliance with the Payment Card Industry Data Security Standard (PCI DSS) requirements tailored to these environments, ensuring cardholder data is protected during processing.
Yes, completion of PCI DSS SAQ B is typically required for eligible merchants by payment brands and acquiring banks. Compliance is not optional and is a prerequisite for accepting payment cards in the specified manner.
SAQ B applies only to merchants that process card transactions using either manual imprint machines or standalone, dial-out payment terminals that connect directly to a payment processor and do not store cardholder data electronically. It excludes any environments with integrated point-of-sale systems, network connectivity, or electronic storage of cardholder data.
Key controls include restricting physical access to cardholder data, maintaining policies for device security, protecting devices from tampering, and ensuring that cardholder data is not stored electronically. Additionally, merchants must establish processes for incident response and periodically inspect devices.
Implementation involves identifying all devices and processes in scope, applying the controls outlined in the SAQ, ensuring staff are trained on device security, and documenting procedures. Merchants should also regularly review compliance, inspect devices for tampering, and ensure no cardholder data is stored electronically.
SAQ B is one of several assessment questionnaires, each designed for a specific merchant environment. SAQ B is the most restrictive, with the narrowest scope, while other SAQs apply to merchants with more complex or integrated payment processing environments. Choosing the correct SAQ is critical for accurate attestation.
Ongoing activities include periodic inspections of payment terminals, maintaining updated device lists, staff training, regular reviews of physical and procedural controls, and annual SAQ completion and attestation. Merchants must also promptly address any identified security risks or device tampering incidents.
SmartSuite can support PCI DSS SAQ B compliance by providing tools for risk tracking, managing required controls, and tracking device inventories. It enables evidence collection for compliance activities, helps maintain audit readiness by documenting inspections and training, and streamlines reporting for annual attestation and ongoing monitoring.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

