Confirm eligibility to take questionnaire PCI DSS C-VT
Merchant Eligibility Criteria for Self-Assessment Questionnaire C-VT Self-Assessment Questionnaire (SAQ) C-VT includes only those PCI DSS requirements applicable to merchants that process account data only via third-party virtual payment terminal solutions on an isolated computing device connected to the Internet.
A virtual payment terminal is third-party solution used to submit payment card transactions for authorization to a PCI DSS compliant third-party service provider (TPSP) website. Using this solution, the merchant manually enters account data from an isolated computing device via a securely connected web browser. Unlike physical terminals, virtual payment terminals do not read data directly from a payment card.
This SAQ option is intended to apply only to merchants that manually enter a single transaction at a time via a keyboard into an Internet-based virtual payment terminal solution. SAQ C-VT merchants may be brick-and-mortar (card-present) or mail/telephone-order (card-not-present) merchants, and do not store account data on any computer system.
SAQ C-VT merchants confirm that, for this payment channel:
- The only payment processing is via a virtual payment terminal accessed by an Internet-connected
web browser;
- The virtual payment terminal solution is provided and hosted by a PCI DSS compliant third-party
service provider;
- The PCI DSS-compliant virtual payment terminal solution is only accessed via a computing
device that is isolated in a single location, and is not connected to other locations or systems (this
can be achieved via a firewall or network segmentation to isolate the merchant system(s)
accessing the virtual payment terminal from other merchant systems);
- The computing device does not have software installed that causes account data to be stored (for
example, there is no software for batch processing or store-and-forward);
- The computing device does not have any attached hardware devices that are used to capture or
store account data (for example, there are no card readers attached);
- The merchant does not otherwise receive, transmit, or store account data electronically through
any channels (for example, via an internal network or the Internet); and
- Any account data the merchant might retain is on paper (for example, printed reports or receipts),
and these documents are not received electronically.