PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ C-VT) — Cardholder Data Security Controls for Virtual Terminal Merchants

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
PCI DSS v4.0.1Self-Assessment Questionnaire (SAQ C-VT) is a compliance tool withinthe Payment Card Industry Data Security Standard (PCI DSS) frameworkthat assists organizations in validating security controls forvirtual terminal merchants that manually enter cardholder data. Thisquestionnaire helps businesses confirm their adherence to industryrequirements for protecting payment card information and managingpayment card risks.
Published by thePCI Security Standards Council (PCI SSC), SAQ C-VT is intended fororganizations that process cardholder data solely via virtual paymentterminals on devices isolated from other payment processingenvironments. It focuses on cybersecurity controls related to dataprotection, secure network configuration, and the mitigation ofpayment card fraud in accordance with PCI DSS requirements.
Organizationstypically complete and submit the SAQ C-VT as part of their PCIcompliance program, documenting security practices, performing riskassessments, and establishing internal controls. The self-assessmentsupports regulatory compliance efforts, audit readiness, and helpsmaintain customer trust within the payment ecosystem.
Why it Matters
PCI DSS v4.0.1SAQ C-VT establishes essential security requirements to protectcardholder data processed through virtual terminals in merchantenvironments.
Key benefitsinclude:
• Strengthen data protection measures
Reduce risk ofunauthorized access and compromise by enforcing strict controls forhandling cardholder data through virtual terminals.
• Enhance compliance support
Aidorganizations in demonstrating adherence to payment card industryrequirements, simplifying the process of regulatory and third-partyvalidation.
• Increase audit readiness
Promotesystematic recordkeeping and documentation that enables smoother andfaster responses to audit or compliance review processes.
• Improve risk management practices
Enableorganizations to identify vulnerabilities in their paymentenvironments and implement controls to proactively mitigate threats.
• Promote operational resilience
Supportcontinuity of business operations by helping detect, prevent, andrespond to payment security incidents more effectively.
How it Works
The PCI DSSv4.0.1 Self-Assessment Questionnaire (SAQ C-VT) structures itsrequirements around a defined set of security controls that safeguardcardholder data processed through virtual terminals. The frameworkcategorizes requirements into control objectives covering areas suchas data protection, access management, vulnerability management, andongoing monitoring. Each requirement maps to broader PCI DSS controlfamilies, ensuring all aspects of payment card security andregulatory compliance are systematically addressed.
In practice,organizations assess their virtual terminal environments against theSAQ C-VT requirements, implementing necessary safeguards such assecure user authentication, encrypted data transmissions, andperiodic vulnerability scans. They conduct self-assessments, evaluaterisk exposure, and maintain documentation to demonstrate compliance.Regular monitoring and review of controls support ongoing governanceefforts and help organizations identify areas for improvement insecurity practices.
Whenoperationalizing PCI DSS SAQ C-VT within SmartSuite, organizationsleverage control libraries to align security controls with frameworkrequirements, maintain a risk register for tracking identified risks,and utilize compliance tracking features to monitor adherence. Policygovernance, evidence collection, remediation workflows, and reportingdashboards support a continuous compliance cycle, audit readiness,and effective risk management for cardholder data environments.
Key Elements
• Scope and Applicability Requirements
Specifiesboundaries for PCI DSS compliance, identifying in-scope systems,personnel, and data handling processes.
• Authentication and Access Control Measures
Describesrequirements for verifying user identities and controlling logicalaccess to cardholder data environments.
• Cardholder Data Protection Practices
Outlines methodsto safeguard stored and transmitted payment card information withinvirtual terminal environments.
• Network and System Security Controls
Establishestechnical and procedural mechanisms to secure network infrastructureand connected systems.
• Monitoring and Testing Procedures
Definesexpectations for regularly tracking security events and periodicallyvalidating control effectiveness.
• Policy and Process Documentation
Organizesrequired documentation of security policies, operational procedures,and evidence for assessment purposes.
Framework Scope
PCI DSS v4.0.1Self-Assessment Questionnaire (SAQ C-VT) is used by merchantsprocessing cardholder data solely via virtual terminals with noelectronic cardholder data storage. This framework governs paymentenvironments and internet-connected systems, typically duringcompliance reviews or when supporting assurance programs focused ondata protection, security controls, and regulatory standards.
Framework Objectives
PCI DSS v4.0.1SAQ C-VT defines essential security controls and governance practicesto protect cardholder data for virtual terminal merchants.
• Safeguard cardholder data through robust data protection andcybersecurity controls
• Strengthen risk management and governance over paymentprocessing environments
• Ensure compliance with regulatory and industry data securityrequirements
• Enhance operational resilience by reducing the likelihood ofdata breaches
• Promote audit readiness through systematic documentation andcontrol validation
• Support ongoing improvement in cybersecurity posture andoversight PCI DSS v4.0.1 SAQ C-VT aligns with overarching PCI DSSrequirements and relates to frameworks like ISO 27001 and NIST SP800-53 regarding payment card data protection. Merchants usingvirtual terminals, without electronic cardholder data storage,typically implement this SAQ to validate regulatory compliance andassure secure handling of cardholder information.
Common Framework Mappings
PCI DSS SAQ C-VTis often mapped to other leading cybersecurity frameworks tostreamline compliance efforts, demonstrate robust cardholder dataprotection, and support broader security and regulatory obligationsacross industries.
Mappedframeworks include:
CIS CriticalSecurity Controls
COBIT
CSA CloudControls Matrix
HIPAA
ISO/IEC 27001
ISO/IEC 27002
NISTCybersecurity Framework
NIST SP 800-53
SOC 2
SWIFT CustomerSecurity Programme
- ClassicifationCategoryPayment SecurityDomainCybersecurityFramework FamilyPCI Security Standards
- Regulatory ContextTypeAssessment / Maturity ModelLegal InstrumentStandardSectorFinancial SectorIndustryPayment & FinTech
- Region / PublisherRegionGlobalRegion DetailPCI DSS (Payment Card Industry Data Security Standard), including version 4.0.1 and its associated Self‑Assessment Questionnaires such as SAQ C‑VT, is developed and managed by the PCI Security Standards Council. The Council is an international consortium established by major payment card brands—but it is headquartered and incorporated in the United States ([en.wikipedia.org](https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard?utm_source=openai)).PublisherPayment Card Industry Security Standards Council (PCI SSC)
- VersioningVersionv4.0.1Effective DateJune 2024Issue DateJune 11, 2024
- AdoptionAdoption ModelRegulatory ComplianceImplementation ComplexityHigh
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
PCI DSS v4.0.1 SAQ C-VT is freely available for download from the PCI SSC website. License included with platform
How SmartSuite Supports PCI DSS v4.0.1 SAQ C-VT
Manage compliance for merchants using virtual terminals by organizing SAQ C-VT requirements, governing access to payment systems, and maintaining documentation supporting PCI DSS v4.0.1 compliance.
SAQ C-VT Requirement Library
Structure SAQ C-VT requirements with mapped controls, assigned owners, and compliance tasks.
Virtual Terminal Access Governance
Track authorized users, authentication policies, and approved devices accessing virtual payment terminals.
Endpoint Security and Configuration Management
Manage security controls for systems used to access payment terminals, including patching and malware protection.
Logging and Monitoring Evidence
Capture logs and monitoring data supporting detection of unauthorized payment system activity.
Service Provider and Processor Oversight
Track payment processors, contracts, and compliance documentation supporting PCI requirements.
SAQ Completion and Compliance Reporting
Provide dashboards showing SAQ completion status, control coverage, and outstanding compliance actions.
Related frameworks

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.
Frequently Asked Questions For PCI DSS v4.0.1 SAQ C-VT (Cardholder Data Security Controls for Virtual Terminal Merchants)
PCI DSS v4.0.1 SAQ C-VT is designed for merchants who process cardholder data solely via virtual terminals on personal computers connected to the internet. It provides a tailored set of security requirements to ensure that cardholder data is protected during payment transactions, specifically when no electronic storage of cardholder data occurs.
Yes, compliance with PCI DSS SAQ C-VT is mandatory for merchants who meet the eligibility criteria defined by the Payment Card Industry Security Standards Council (PCI SSC). Acquirers and payment brands may require proof of compliance through annual self-assessment and periodic vulnerability scans.
SAQ C-VT applies to merchants that process card payments solely through validated virtual terminals (not storing cardholder data electronically) and do not transmit cardholder data via other channels. It is not applicable to merchants using POS systems or any systems that store, process, or transmit cardholder data outside the virtual terminal environment.
Key controls include maintaining secure configurations for computers, strong access controls, regular system monitoring, and ensuring encrypted transmission of cardholder data. Merchants must also implement anti-virus software, restrict physical access, and ensure no cardholder data is stored electronically.
Implementation involves assessing the environment for eligibility, configuring systems to support only virtual terminal transactions, restricting access to systems processing card data, and documenting compliance using the SAQ C-VT questionnaire. Regular employee training and policy enforcement are also essential.
PCI DSS SAQ C-VT is one of several self-assessment options within PCI DSS, each tailored to a specific merchant environment. It is more limited in scope compared to SAQ D (for service providers and larger merchants) and is specifically for those using virtual terminals exclusively.
Ongoing requirements include annual completion of the SAQ C-VT, continued adherence to the outlined controls, regular review of system configurations, and ongoing security awareness training for staff. Merchants must also remain vigilant for any environment changes that could affect their eligibility or compliance status.
SmartSuite can help organizations manage PCI DSS SAQ C-VT by tracking compliance risks, managing security control implementation, collecting and organizing compliance evidence, and ensuring readiness for internal or external audits. The platform also provides robust reporting capabilities and supports workflow management to help teams maintain continuous compliance.
Put CRI Profile into action with SmartSuite
Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.

