PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ C-VT) — Cardholder Data Security Controls for Virtual Terminal Merchants

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ C-VT) is a compliance tool within the Payment Card Industry Data Security Standard (PCI DSS) framework that assists organizations in validating security controls for virtual terminal merchants that manually enter cardholder data. This questionnaire helps businesses confirm their adherence to industry requirements for protecting payment card information and managing payment card risks.
Published by the PCI Security Standards Council (PCI SSC), SAQ C-VT is intended for organizations that process cardholder data solely via virtual payment terminals on devices isolated from other payment processing environments. It focuses on cybersecurity controls related to data protection, secure network configuration, and the mitigation of payment card fraud in accordance with PCI DSS requirements.
Organizations typically complete and submit the SAQ C-VT as part of their PCI compliance program, documenting security practices, performing risk assessments, and establishing internal controls. The self-assessment supports regulatory compliance efforts, audit readiness, and helps maintain customer trust within the payment ecosystem.
Why it Matters
PCI DSS v4.0.1 SAQ C-VT establishes essential security requirementsto protect cardholder data processed through virtual terminals inmerchant environments.
Key benefits include:
- Strengthen data protection measures
Reduce risk ofunauthorized access and compromise by enforcing strict controls forhandling cardholder data through virtual terminals.
- Enhance compliance support
Aid organizationsin demonstrating adherence to payment card industry requirements,simplifying the process of regulatory and third-party validation.
- Increase audit readiness
Promotesystematic recordkeeping and documentation that enables smoother andfaster responses to audit or compliance review processes.
- Improve risk management practices
Enableorganizations to identify vulnerabilities in their paymentenvironments and implement controls to proactively mitigate threats.
- Promote operational resilience
Supportcontinuity of business operations by helping detect, prevent, andrespond to payment security incidents more effectively.
How it Works
The PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ C-VT)structures its requirements around a defined set of security controlsthat safeguard cardholder data processed through virtual terminals.The framework categorizes requirements into control objectivescovering areas such as data protection, access management,vulnerability management, and ongoing monitoring. Each requirementmaps to broader PCI DSS control families, ensuring all aspects ofpayment card security and regulatory compliance are systematicallyaddressed.
In practice, organizations assess their virtual terminal environmentsagainst the SAQ C-VT requirements, implementing necessary safeguardssuch as secure user authentication, encrypted data transmissions, andperiodic vulnerability scans. They conduct self-assessments, evaluaterisk exposure, and maintain documentation to demonstrate compliance.Regular monitoring and review of controls support ongoing governanceefforts and help organizations identify areas for improvement insecurity practices.
When operationalizing PCI DSS SAQ C-VT within SmartSuite,organizations leverage control libraries to align security controlswith framework requirements, maintain a risk register for trackingidentified risks, and utilize compliance tracking features to monitoradherence. Policy governance, evidence collection, remediationworkflows, and reporting dashboards support a continuous compliancecycle, audit readiness, and effective risk management for cardholderdata environments.
Key Elements
- Scope and Applicability Requirements
Specifiesboundaries for PCI DSS compliance, identifying in-scope systems,personnel, and data handling processes.
- Authentication and Access Control Measures
Describesrequirements for verifying user identities and controlling logicalaccess to cardholder data environments.
- Cardholder Data Protection Practices
Outlines methodsto safeguard stored and transmitted payment card information withinvirtual terminal environments.
- Network and System Security Controls
Establishestechnical and procedural mechanisms to secure network infrastructureand connected systems.
- Monitoring and Testing Procedures
Definesexpectations for regularly tracking security events and periodicallyvalidating control effectiveness.
- Policy and Process Documentation
Organizesrequired documentation of security policies, operational procedures,and evidence for assessment purposes.
Framework Scope
PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ C-VT) is used bymerchants processing cardholder data solely via virtual terminalswith no electronic cardholder data storage. This framework governspayment environments and internet-connected systems, typically duringcompliance reviews or when supporting assurance programs focused ondata protection, security controls, and regulatory standards.
Framework Objectives
PCI DSS v4.0.1 SAQ C-VT defines essential security controls andgovernance practices to protect cardholder data for virtual terminalmerchants.
Safeguard cardholder data through robust data protection andcybersecurity controls
Strengthen risk management and governance over payment processingenvironments
Ensure compliance with regulatory and industry data securityrequirements
Enhance operational resilience by reducing the likelihood of databreaches
Promote audit readiness through systematic documentation and controlvalidation
Support ongoing improvement in cybersecurity posture and oversightPCI DSS v4.0.1 SAQ C-VT aligns with overarching PCI DSS requirementsand relates to frameworks like ISO 27001 and NIST SP 800-53 regardingpayment card data protection. Merchants using virtual terminals,without electronic cardholder data storage, typically implement thisSAQ to validate regulatory compliance and assure secure handling ofcardholder information.
Framework in Context
PCI DSS v4.0.1 SAQC-VT aligns with overarching PCI DSS requirements and relates toframeworks like ISO 27001 and NIST SP 800-53 regarding payment carddata protection. Merchants using virtual terminals, withoutelectronic cardholder data storage, typically implement this SAQ tovalidate regulatory compliance and assure secure handling ofcardholder information.
Common Framework Mappings
PCI DSS SAQ C-VT is often mapped to other leading cybersecurityframeworks to streamline compliance efforts, demonstrate robustcardholder data protection, and support broader security andregulatory obligations across industries.
Mapped frameworks include:
CIS Critical Security Controls
COBIT
CSA Cloud Controls Matrix
HIPAA
ISO/IEC 27001
ISO/IEC 27002
NIST Cybersecurity Framework
NIST SP 800-53
SOC 2
SWIFT Customer Security Programme
- ClassificationCategoryPayment SecurityDomainCybersecurityFramework FamilyPCI Security Standards
- Regulatory ContextTypeAssessment / Maturity ModelLegal InstrumentStandardSectorFinancial SectorIndustryPayment & FinTech
- Region / PublisherRegionGlobalRegion DetailPCI DSS (Payment Card Industry Data Security Standard), including version 4.0.1 and its associated Self‑Assessment Questionnaires such as SAQ C‑VT, is developed and managed by the PCI Security Standards Council. The Council is an international consortium established by major payment card brands—but it is headquartered and incorporated in the United States ([en.wikipedia.org](https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard?utm_source=openai)).PublisherPayment Card Industry Security Standards Council (PCI SSC)
- VersioningVersionv4.0.1Effective DateJune 2024Issue DateJune 11, 2024
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
PCI DSS v4.0.1 SAQ C-VT is freely available for download from the PCI SSC website. License included with platform
How SmartSuite Supports PCI DSS v4.0.1 SAQ C-VT
Manage compliance for merchants using virtual terminals by organizing SAQ C-VT requirements, governing access to payment systems, and maintaining documentation supporting PCI DSS v4.0.1 compliance.
SAQ C-VT Requirement Library
Structure SAQ C-VT requirements with mapped controls, assigned owners, and compliance tasks.
Virtual Terminal Access Governance
Track authorized users, authentication policies, and approved devices accessing virtual payment terminals.
Endpoint Security and Configuration Management
Manage security controls for systems used to access payment terminals, including patching and malware protection.
Logging and Monitoring Evidence
Capture logs and monitoring data supporting detection of unauthorized payment system activity.
Service Provider and Processor Oversight
Track payment processors, contracts, and compliance documentation supporting PCI requirements.
SAQ Completion and Compliance Reporting
Provide dashboards showing SAQ completion status, control coverage, and outstanding compliance actions.
Related frameworks

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.
Frequently Asked Questions For PCI DSS v4.0.1 SAQ C-VT (Cardholder Data Security Controls for Virtual Terminal Merchants)
PCI DSS v4.0.1 SAQ C-VT is designed for merchants who process cardholder data solely via virtual terminals on personal computers connected to the internet. It provides a tailored set of security requirements to ensure that cardholder data is protected during payment transactions, specifically when no electronic storage of cardholder data occurs.
Yes, compliance with PCI DSS SAQ C-VT is mandatory for merchants who meet the eligibility criteria defined by the Payment Card Industry Security Standards Council (PCI SSC). Acquirers and payment brands may require proof of compliance through annual self-assessment and periodic vulnerability scans.
SAQ C-VT applies to merchants that process card payments solely through validated virtual terminals (not storing cardholder data electronically) and do not transmit cardholder data via other channels. It is not applicable to merchants using POS systems or any systems that store, process, or transmit cardholder data outside the virtual terminal environment.
Key controls include maintaining secure configurations for computers, strong access controls, regular system monitoring, and ensuring encrypted transmission of cardholder data. Merchants must also implement anti-virus software, restrict physical access, and ensure no cardholder data is stored electronically.
Implementation involves assessing the environment for eligibility, configuring systems to support only virtual terminal transactions, restricting access to systems processing card data, and documenting compliance using the SAQ C-VT questionnaire. Regular employee training and policy enforcement are also essential.
PCI DSS SAQ C-VT is one of several self-assessment options within PCI DSS, each tailored to a specific merchant environment. It is more limited in scope compared to SAQ D (for service providers and larger merchants) and is specifically for those using virtual terminals exclusively.
Ongoing requirements include annual completion of the SAQ C-VT, continued adherence to the outlined controls, regular review of system configurations, and ongoing security awareness training for staff. Merchants must also remain vigilant for any environment changes that could affect their eligibility or compliance status.
SmartSuite can help organizations manage PCI DSS SAQ C-VT by tracking compliance risks, managing security control implementation, collecting and organizing compliance evidence, and ensuring readiness for internal or external audits. The platform also provides robust reporting capabilities and supports workflow management to help teams maintain continuous compliance.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

