Payment Security
DETAIL

PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ C-VT) — Cardholder Data Security Controls for Virtual Terminal Merchants

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

PCI DSS v4.0.1Self-Assessment Questionnaire (SAQ C-VT) is a compliance tool withinthe Payment Card Industry Data Security Standard (PCI DSS) frameworkthat assists organizations in validating security controls forvirtual terminal merchants that manually enter cardholder data. Thisquestionnaire helps businesses confirm their adherence to industryrequirements for protecting payment card information and managingpayment card risks.

Published by thePCI Security Standards Council (PCI SSC), SAQ C-VT is intended fororganizations that process cardholder data solely via virtual paymentterminals on devices isolated from other payment processingenvironments. It focuses on cybersecurity controls related to dataprotection, secure network configuration, and the mitigation ofpayment card fraud in accordance with PCI DSS requirements.

Organizationstypically complete and submit the SAQ C-VT as part of their PCIcompliance program, documenting security practices, performing riskassessments, and establishing internal controls. The self-assessmentsupports regulatory compliance efforts, audit readiness, and helpsmaintain customer trust within the payment ecosystem.

Why it Matters

PCI DSS v4.0.1SAQ C-VT establishes essential security requirements to protectcardholder data processed through virtual terminals in merchantenvironments.

Key benefitsinclude:

•  Strengthen data protection measures

Reduce risk ofunauthorized access and compromise by enforcing strict controls forhandling cardholder data through virtual terminals.

•  Enhance compliance support

Aidorganizations in demonstrating adherence to payment card industryrequirements, simplifying the process of regulatory and third-partyvalidation.

•  Increase audit readiness

Promotesystematic recordkeeping and documentation that enables smoother andfaster responses to audit or compliance review processes.

•  Improve risk management practices

Enableorganizations to identify vulnerabilities in their paymentenvironments and implement controls to proactively mitigate threats.

•  Promote operational resilience

Supportcontinuity of business operations by helping detect, prevent, andrespond to payment security incidents more effectively.

How it Works

The PCI DSSv4.0.1 Self-Assessment Questionnaire (SAQ C-VT) structures itsrequirements around a defined set of security controls that safeguardcardholder data processed through virtual terminals. The frameworkcategorizes requirements into control objectives covering areas suchas data protection, access management, vulnerability management, andongoing monitoring. Each requirement maps to broader PCI DSS controlfamilies, ensuring all aspects of payment card security andregulatory compliance are systematically addressed.

In practice,organizations assess their virtual terminal environments against theSAQ C-VT requirements, implementing necessary safeguards such assecure user authentication, encrypted data transmissions, andperiodic vulnerability scans. They conduct self-assessments, evaluaterisk exposure, and maintain documentation to demonstrate compliance.Regular monitoring and review of controls support ongoing governanceefforts and help organizations identify areas for improvement insecurity practices.

Whenoperationalizing PCI DSS SAQ C-VT within SmartSuite, organizationsleverage control libraries to align security controls with frameworkrequirements, maintain a risk register for tracking identified risks,and utilize compliance tracking features to monitor adherence. Policygovernance, evidence collection, remediation workflows, and reportingdashboards support a continuous compliance cycle, audit readiness,and effective risk management for cardholder data environments.

Key Elements

•  Scope and Applicability Requirements

Specifiesboundaries for PCI DSS compliance, identifying in-scope systems,personnel, and data handling processes.

•  Authentication and Access Control Measures

Describesrequirements for verifying user identities and controlling logicalaccess to cardholder data environments.

•  Cardholder Data Protection Practices

Outlines methodsto safeguard stored and transmitted payment card information withinvirtual terminal environments.

•  Network and System Security Controls

Establishestechnical and procedural mechanisms to secure network infrastructureand connected systems.

•  Monitoring and Testing Procedures

Definesexpectations for regularly tracking security events and periodicallyvalidating control effectiveness.

•  Policy and Process Documentation

Organizesrequired documentation of security policies, operational procedures,and evidence for assessment purposes.

Framework Scope

PCI DSS v4.0.1Self-Assessment Questionnaire (SAQ C-VT) is used by merchantsprocessing cardholder data solely via virtual terminals with noelectronic cardholder data storage. This framework governs paymentenvironments and internet-connected systems, typically duringcompliance reviews or when supporting assurance programs focused ondata protection, security controls, and regulatory standards.

Framework Objectives

PCI DSS v4.0.1SAQ C-VT defines essential security controls and governance practicesto protect cardholder data for virtual terminal merchants.

•  Safeguard cardholder data through robust data protection andcybersecurity controls

•  Strengthen risk management and governance over paymentprocessing environments

•  Ensure compliance with regulatory and industry data securityrequirements

•  Enhance operational resilience by reducing the likelihood ofdata breaches

•  Promote audit readiness through systematic documentation andcontrol validation

•  Support ongoing improvement in cybersecurity posture andoversight PCI DSS v4.0.1 SAQ C-VT aligns with overarching PCI DSSrequirements and relates to frameworks like ISO 27001 and NIST SP800-53 regarding payment card data protection. Merchants usingvirtual terminals, without electronic cardholder data storage,typically implement this SAQ to validate regulatory compliance andassure secure handling of cardholder information.

Common Framework Mappings

PCI DSS SAQ C-VTis often mapped to other leading cybersecurity frameworks tostreamline compliance efforts, demonstrate robust cardholder dataprotection, and support broader security and regulatory obligationsacross industries.

Mappedframeworks include:

CIS CriticalSecurity Controls

COBIT

CSA CloudControls Matrix

HIPAA

ISO/IEC 27001

ISO/IEC 27002

NISTCybersecurity Framework

NIST SP 800-53

SOC 2

SWIFT CustomerSecurity Programme

At a Glance
PCI DSS v4.0.1 – SAQ C-VT
  • checklist
    Classicifation
    Category
    info
    Payment Security
    Domain
    info
    Cybersecurity
    Framework Family
    info
    PCI Security Standards
  • info
    Regulatory Context
    Type
    info
    Assessment / Maturity Model
    Legal Instrument
    info
    Standard
    Sector
    info
    Financial Sector
    Industry
    info
    Payment & FinTech
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    Global
    Region Detail
    info
    PCI DSS (Payment Card Industry Data Security Standard), including version 4.0.1 and its associated Self‑Assessment Questionnaires such as SAQ C‑VT, is developed and managed by the PCI Security Standards Council. The Council is an international consortium established by major payment card brands—but it is headquartered and incorporated in the United States ([en.wikipedia.org](https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard?utm_source=openai)).
    Publisher
    info
    Payment Card Industry Security Standards Council (PCI SSC)
  • published_with_changes
    Versioning
    Version
    info
    v4.0.1
    Effective Date
    info
    June 2024
    Issue Date
    info
    June 11, 2024
  • graph_3
    Adoption
    Adoption Model
    info
    Regulatory Compliance
    Implementation Complexity
    info
    High
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

PCI DSS v4.0.1 SAQ C-VT is freely available for download from the PCI SSC website. License included with platform

Official Resources
PCI DSS v4.0.1 Documentation
Official documentation detailing the PCI DSS version 4.0.1 security requirements and guidance.
chevron_forward
PCI DSS SAQ C-VT Guidance
Provides detailed guidance on completing the Self-Assessment Questionnaire for PCI DSS compliance.
chevron_forward
SMARTSUITE

How SmartSuite Supports PCI DSS v4.0.1 SAQ C-VT

Manage compliance for merchants using virtual terminals by organizing SAQ C-VT requirements, governing access to payment systems, and maintaining documentation supporting PCI DSS v4.0.1 compliance.

SAQ C-VT Requirement Library

Structure SAQ C-VT requirements with mapped controls, assigned owners, and compliance tasks.

Virtual Terminal Access Governance

Track authorized users, authentication policies, and approved devices accessing virtual payment terminals.

Endpoint Security and Configuration Management

Manage security controls for systems used to access payment terminals, including patching and malware protection.

Logging and Monitoring Evidence

Capture logs and monitoring data supporting detection of unauthorized payment system activity.

Service Provider and Processor Oversight

Track payment processors, contracts, and compliance documentation supporting PCI requirements.

SAQ Completion and Compliance Reporting

Provide dashboards showing SAQ completion status, control coverage, and outstanding compliance actions.

Related frameworks

CIS Controls v8.1

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
ISO 27002:2022

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

Learn More
arrow_forward
NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

Learn More
arrow_forward
NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

Learn More
arrow_forward
SOC 2

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.

Learn More
arrow_forward
SWIFT CSCF

SWIFT Customer Security Framework establishes baseline cybersecurity controls for organizations using the SWIFT network to secure financial transactions.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For PCI DSS v4.0.1 SAQ C-VT (Cardholder Data Security Controls for Virtual Terminal Merchants)

What is PCI DSS v4.0.1 SAQ C-VT used for?

PCI DSS v4.0.1 SAQ C-VT is designed for merchants who process cardholder data solely via virtual terminals on personal computers connected to the internet. It provides a tailored set of security requirements to ensure that cardholder data is protected during payment transactions, specifically when no electronic storage of cardholder data occurs.

Is compliance with PCI DSS SAQ C-VT mandatory?

Yes, compliance with PCI DSS SAQ C-VT is mandatory for merchants who meet the eligibility criteria defined by the Payment Card Industry Security Standards Council (PCI SSC). Acquirers and payment brands may require proof of compliance through annual self-assessment and periodic vulnerability scans.

Who is eligible to use SAQ C-VT under PCI DSS v4.0.1?

SAQ C-VT applies to merchants that process card payments solely through validated virtual terminals (not storing cardholder data electronically) and do not transmit cardholder data via other channels. It is not applicable to merchants using POS systems or any systems that store, process, or transmit cardholder data outside the virtual terminal environment.

What are the most important controls required by PCI DSS SAQ C-VT?

Key controls include maintaining secure configurations for computers, strong access controls, regular system monitoring, and ensuring encrypted transmission of cardholder data. Merchants must also implement anti-virus software, restrict physical access, and ensure no cardholder data is stored electronically.

How is PCI DSS SAQ C-VT implemented in practice?

Implementation involves assessing the environment for eligibility, configuring systems to support only virtual terminal transactions, restricting access to systems processing card data, and documenting compliance using the SAQ C-VT questionnaire. Regular employee training and policy enforcement are also essential.

How does PCI DSS SAQ C-VT relate to other PCI SAQs or versions?

PCI DSS SAQ C-VT is one of several self-assessment options within PCI DSS, each tailored to a specific merchant environment. It is more limited in scope compared to SAQ D (for service providers and larger merchants) and is specifically for those using virtual terminals exclusively.

What are the ongoing compliance requirements for PCI DSS SAQ C-VT?

Ongoing requirements include annual completion of the SAQ C-VT, continued adherence to the outlined controls, regular review of system configurations, and ongoing security awareness training for staff. Merchants must also remain vigilant for any environment changes that could affect their eligibility or compliance status.

How would SmartSuite support PCI DSS v4.0.1 SAQ C-VT?

SmartSuite can help organizations manage PCI DSS SAQ C-VT by tracking compliance risks, managing security control implementation, collecting and organizing compliance evidence, and ensuring readiness for internal or external audits. The platform also provides robust reporting capabilities and supports workflow management to help teams maintain continuous compliance.

NEXT STEP

Put CRI Profile into action with SmartSuite

Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.

Explore in SmartSuite
chevron_forward
View all Frameworks
chevron_forward