Payment Security
DETAIL

PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ C-VT) — Cardholder Data Security Controls for Virtual Terminal Merchants

Reviewed by
·

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ C-VT) is a compliance tool within the Payment Card Industry Data Security Standard (PCI DSS) framework that assists organizations in validating security controls for virtual terminal merchants that manually enter cardholder data. This questionnaire helps businesses confirm their adherence to industry requirements for protecting payment card information and managing payment card risks.

Published by the PCI Security Standards Council (PCI SSC), SAQ C-VT is intended for organizations that process cardholder data solely via virtual payment terminals on devices isolated from other payment processing environments. It focuses on cybersecurity controls related to data protection, secure network configuration, and the mitigation of payment card fraud in accordance with PCI DSS requirements.

Organizations typically complete and submit the SAQ C-VT as part of their PCI compliance program, documenting security practices, performing risk assessments, and establishing internal controls. The self-assessment supports regulatory compliance efforts, audit readiness, and helps maintain customer trust within the payment ecosystem.

Why it Matters

PCI DSS v4.0.1 SAQ C-VT establishes essential security requirements to protect cardholder data processed through virtual terminals in merchant environments.

Key benefits include:

  • Strengthen data protection measures

Reduce risk of unauthorized access and compromise by enforcing strict controls for handling cardholder data through virtual terminals.

  • Enhance compliance support

Aid organizations in demonstrating adherence to payment card industry requirements, simplifying the process of regulatory and third-party validation.

  • Increase audit readiness

Promote systematic recordkeeping and documentation that enables smoother and faster responses to audit or compliance review processes.

  • Improve risk management practices

Enable organizations to identify vulnerabilities in their payment environments and implement controls to proactively mitigate threats.

  • Promote operational resilience

Support continuity of business operations by helping detect, prevent, and respond to payment security incidents more effectively.

How it Works

The PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ C-VT) structures its requirements around a defined set of security controls that safeguard cardholder data processed through virtual terminals. The framework categorizes requirements into control objectives covering areas such as data protection, access management, vulnerability management, and ongoing monitoring. Each requirement maps to broader PCI DSS control families, ensuring all aspects of payment card security and regulatory compliance are systematically addressed.

In practice, organizations assess their virtual terminal environments against the SAQ C-VT requirements, implementing necessary safeguards such as secure user authentication, encrypted data transmissions, and periodic vulnerability scans. They conduct self-assessments, evaluate risk exposure, and maintain documentation to demonstrate compliance. Regular monitoring and review of controls support ongoing governance efforts and help organizations identify areas for improvement insecurity practices.

When operationalizing PCI DSS SAQ C-VT within SmartSuite, organizations use control libraries to align security controls with framework requirements, maintain a risk register for tracking identified risks, and utilize compliance tracking features to monitor adherence. Policy governance, evidence collection, remediation workflows, and reporting dashboards support a continuous compliance cycle, audit readiness, and effective risk management for cardholder data environments.

Key Elements

  • Scope and Applicability Requirements

Specifies boundaries for PCI DSS compliance, identifying in-scope systems, personnel, and data handling processes.

  • Authentication and Access Control Measures

Describes requirements for verifying user identities and controlling logical access to cardholder data environments.

  • Cardholder Data Protection Practices

Outlines methods to safeguard stored and transmitted payment card information within virtual terminal environments.

  • Network and System Security Controls

Establishes technical and procedural mechanisms to secure network infrastructure and connected systems.

  • Monitoring and Testing Procedures

Defines expectations for regularly tracking security events and periodically validating control effectiveness.

  • Policy and Process Documentation

Organizes required documentation of security policies, operational procedures, and evidence for assessment purposes.

Framework Scope

PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ C-VT) is used by merchants processing cardholder data solely via virtual terminals with no electronic cardholder data storage. This framework governs payment environments and internet-connected systems, typically during compliance reviews or when supporting assurance programs focused on data protection, security controls, and regulatory standards.

Framework Objectives

PCI DSS v4.0.1 SAQ C-VT defines essential security controls and governance practices to protect cardholder data for virtual terminal merchants.

Safeguard cardholder data through data protection and cybersecurity controls

Strengthen risk management and governance over payment processing environments

Ensure compliance with regulatory and industry data security requirements

Enhance operational resilience by reducing the likelihood of data breaches

Promote audit readiness through systematic documentation and control validation

Support ongoing improvement in cybersecurity posture and oversight PCI DSS v4.0.1 SAQ C-VT aligns with overarching PCI DSS requirements and relates to frameworks like ISO 27001 and NIST SP 800-53 regarding payment card data protection. Merchants using virtual terminals, without electronic cardholder data storage, typically implement this SAQ to validate regulatory compliance and assure secure handling of cardholder information.

Framework in Context

PCI DSS v4.0.1 SAQC-VT aligns with overarching PCI DSS requirements and relates to frameworks like ISO 27001 and NIST SP 800-53 regarding payment card data protection. Merchants using virtual terminals, without electronic cardholder data storage, typically implement this SAQ to validate regulatory compliance and assure secure handling of cardholder information.

Common Framework Mappings

PCI DSS SAQ C-VT is often mapped to other leading cybersecurity frameworks to simplify compliance efforts, demonstrate cardholder data protection, and support broader security and regulatory obligations across industries.

Mapped frameworks include:

CIS Critical Security Controls

COBIT

CSA Cloud Controls Matrix

HIPAA

ISO/IEC 27001

ISO/IEC 27002

NIST Cybersecurity Framework

NIST SP 800-53

SOC 2

SWIFT Customer Security Programme

At a Glance
PCI DSS v4.0.1 – SAQ C-VT
  • Classification
    Category
    Payment Security
    Domain
    Cybersecurity
    Framework Family
    PCI Security Standards
  • Regulatory Context
    Type
    Assessment / Maturity Model
    Legal Instrument
    Standard
    Sector
    Financial Sector
    Industry
    Payment & FinTech
  • Region / Publisher
    Region
    Global
    Region Detail
    PCI DSS (Payment Card Industry Data Security Standard), including version 4.0.1 and its associated Self‑Assessment Questionnaires such as SAQ C‑VT, is developed and managed by the PCI Security Standards Council. The Council is an international consortium established by major payment card brands—but it is headquartered and incorporated in the United States ([en.wikipedia.org](https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard?utm_source=openai)).
    Publisher
    Payment Card Industry Security Standards Council (PCI SSC)
  • Versioning
    Version
    v4.0.1
    Effective Date
    June 2024
    Issue Date
    June 11, 2024
  • Adoption
    Adoption Model
    Regulatory Compliance
    Implementation Complexity
    High
  • Official Reference
License Information

License included / downloadable: Yes

PCI DSS v4.0.1 SAQ C-VT is freely available for download from the PCI SSC website. License included with platform

Framework text is licensed by its publisher and is included only where stated above.

Official Resources
PCI DSS v4.0.1 Documentation
Official documentation detailing the PCI DSS version 4.0.1 security requirements and guidance.
PCI DSS SAQ C-VT Guidance
Provides detailed guidance on completing the Self-Assessment Questionnaire for PCI DSS compliance.
SMARTSUITE

How SmartSuite Supports PCI DSS v4.0.1 SAQ C-VT

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

Manage compliance for merchants using virtual terminals by organizing SAQ C-VT requirements, governing access to payment systems, and maintaining documentation supporting PCI DSS v4.0.1 compliance.

SAQ C-VT Requirement Library

Structure SAQ C-VT requirements with mapped controls, assigned owners, and compliance tasks.

Virtual Terminal Access Governance

Track authorized users, authentication policies, and approved devices accessing virtual payment terminals.

Endpoint Security and Configuration Management

Manage security controls for systems used to access payment terminals, including patching and malware protection.

Logging and Monitoring Evidence

Capture logs and monitoring data supporting detection of unauthorized payment system activity.

Service Provider and Processor Oversight

Track payment processors, contracts, and compliance documentation supporting PCI requirements.

SAQ Completion and Compliance Reporting

Provide dashboards showing SAQ completion status, control coverage, and outstanding compliance actions.

Related frameworks

CIS Controls v8.1

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ISO 27002:2022

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

SOC 2

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.

SWIFT CSCF

SWIFT Customer Security Framework establishes baseline cybersecurity controls for organizations using the SWIFT network to secure financial transactions.

ONBOARDING FAQS

Frequently Asked Questions For PCI DSS v4.0.1 SAQ C-VT (Cardholder Data Security Controls for Virtual Terminal Merchants)

What is PCI DSS v4.0.1 SAQ C-VT used for?

PCI DSS v4.0.1 SAQ C-VT is designed for merchants who process cardholder data solely via virtual terminals on personal computers connected to the internet. It provides a tailored set of security requirements to ensure that cardholder data is protected during payment transactions, specifically when no electronic storage of cardholder data occurs.

Is compliance with PCI DSS SAQ C-VT mandatory?

Yes, compliance with PCI DSS SAQ C-VT is mandatory for merchants who meet the eligibility criteria defined by the Payment Card Industry Security Standards Council (PCI SSC). Acquirers and payment brands may require proof of compliance through annual self-assessment and periodic vulnerability scans.

Who is eligible to use SAQ C-VT under PCI DSS v4.0.1?

SAQ C-VT applies to merchants that process card payments solely through validated virtual terminals (not storing cardholder data electronically) and do not transmit cardholder data via other channels. It is not applicable to merchants using POS systems or any systems that store, process, or transmit cardholder data outside the virtual terminal environment.

What are the most important controls required by PCI DSS SAQ C-VT?

Key controls include maintaining secure configurations for computers, strong access controls, regular system monitoring, and ensuring encrypted transmission of cardholder data. Merchants must also implement anti-virus software, restrict physical access, and ensure no cardholder data is stored electronically.

How is PCI DSS SAQ C-VT implemented in practice?

Implementation involves assessing the environment for eligibility, configuring systems to support only virtual terminal transactions, restricting access to systems processing card data, and documenting compliance using the SAQ C-VT questionnaire. Regular employee training and policy enforcement are also essential.

How does PCI DSS SAQ C-VT relate to other PCI SAQs or versions?

PCI DSS SAQ C-VT is one of several self-assessment options within PCI DSS, each tailored to a specific merchant environment. It is more limited in scope compared to SAQ D (for service providers and larger merchants) and is specifically for those using virtual terminals exclusively.

What are the ongoing compliance requirements for PCI DSS SAQ C-VT?

Ongoing requirements include annual completion of the SAQ C-VT, continued adherence to the outlined controls, regular review of system configurations, and ongoing security awareness training for staff. Merchants must also remain vigilant for any environment changes that could affect their eligibility or compliance status.

How would SmartSuite support PCI DSS v4.0.1 SAQ C-VT?

SmartSuite can help organizations manage PCI DSS SAQ C-VT by tracking compliance risks, managing security control implementation, collecting and organizing compliance evidence, and ensuring readiness for internal or external audits. The platform also provides robust reporting capabilities and supports workflow management to help teams maintain continuous compliance.

Operationalize PCI DSS 4.0 SAQ C-VT with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.