---
title: Filling out the Self-Assessment Questionnaire For Merchants Using ServiceBox and Paysafe
description: Filling out the Self-Assessment Questionnaire For Merchants Using ServiceBox and Paysafe
---

[Skip to content](https://learn.getservicebox.com/filling-out-the-self-assessment-questionnaire-for-merchants-using-servicebox-and-paysafe#main-content)

English

Show submenu for translations

[![ServiceBox Workmark OrangeGradient](https://learn.getservicebox.com/hs-fs/hubfs/ServiceBox%20Workmark%20OrangeGradient.png?width=225&height=57&name=ServiceBox%20Workmark%20OrangeGradient.png)](https://learn.getservicebox.com/knowledge-base?hsLang=en)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations

 How can we help you?

- There are no suggestions because the search field is empty.

1. [ServiceBox Support Knowledge Base](https://learn.getservicebox.com/?hsLang=en)
2. [Invoices](https://learn.getservicebox.com/invoices?hsLang=en)
3. [User Guide](https://learn.getservicebox.com/invoices?hsLang=en#user-guide)

# Filling out the Self-Assessment Questionnaire For Merchants Using ServiceBox and Paysafe

## This guide provides a step-by-step breakdown of the Self-Assessment Questionnaire A (SAQ A) for merchants. It is designed for businesses that outsource all payment processing to a PCI DSS–validated third-party provider (such as Paysafe) and do not electronically store, process, or transmit cardholder data.

(For the latest eligibility criteria, refer to: [listings.pcisecuritystandards.org](http://listings.pcisecuritystandards.org))

 

### **1. Eligibility Confirmation**

Before beginning, verify that your business meets the following updated criteria for SAQ A eligibility:

 

**Card-Not-Present Transactions Only:** Your business accepts only e-commerce or mail/telephone-order transactions.

**Outsourced Payment Processing:** All payment processing is handled by a PCI DSS–validated third-party provider (e.g., Paysafe).

*Ensure you have the most recent Attestation of Compliance (AOC) from your provider.*

**No Electronic Cardholder Data Storage:** You do not store, process, or transmit cardholder data on your systems or premises.

*Any cardholder data retained must only exist in paper form (e.g., printed reports or receipts) and not be received electronically.*

Confirm that your business model strictly adheres to these standards before proceeding.

 

 

### **2. Gathering Required Information**

Before filling out the SAQ A, collect the following:

 

**Business Information:**

- Legal business name
- DBA name (if applicable)
- Full business address
- Contact details

**Third-Party Provider Information:**

- The most recent Attestation of Compliance (AOC) from Paysafe
- Any additional compliance documentation verifying Paysafe’s PCI DSS status

**Internal Policies & Procedures:**

- Up-to-date security policies and procedures related to PCI DSS requirements

**IT Systems Overview:**

- Confirmation that no cardholder data is stored or processed on internal systems

### **3. Complete Section 1 – Merchant Information**

Enter the following details accurately:

 

**Merchant Name:** Provide the legal name of your business.

**DBA Name (if applicable):** Enter the trade name if it differs from the legal name.

**Business Address:** Enter the full physical address.

**Contact Person:** List the name and role (e.g., CEO, Compliance Officer) of the individual responsible for PCI compliance.

**Third-Party Provider:** Specify Paysafe as your PCI DSS–compliant payment processor.

 

 

### **4. Section 1: Assessment Information**

**Part 1: Contact Information**

 

**Company Name:** Enter your legal business name.

**DBA (Doing Business As):** Provide the trade name if applicable.

**Company Mailing Address:** Include the full address (city, state, and country).

**Company Website:** Provide the URL.

**Contact Name & Title:** Enter the full name and title (e.g., CEO, Compliance Officer) of the responsible party.

**Contact Phone & Email:** Provide a valid phone number and email address.

 

### **5. Section 2: PCI DSS Scope Information**

**Part 2a: Merchant Business Payment Channels**

 

Select the applicable channels:

- **E-Commerce:** ✅ (Checked in PDF)
- **Mail Order/Telephone Order:** ❌ (Not applicable)
- **Card-Present Transactions:** ❌ (Not applicable)

**Part 2b: Role with Payment Cards**

 

Describe your role:

 

**Narrative:** "Our business uses ServiceBox in conjunction with Paysafe. We do not store, process, or transmit cardholder data internally. All transactions are handled by a PCI DSS–validated third-party service provider."

**Channel Entry:** Enter “ServiceBox” where required.

*Ensure this narrative is consistent throughout your SAQ.*

 

**Part 2c: Payment Card Environment Description**

 

Provide an overview of your payment processing setup:

 

**Sample Text:** "Our business uses ServiceBox software integrated with Paysafe’s hosted payment solution. Transactions are securely processed via a redirect to the Paysafe system, and no cardholder data is stored, processed, or transmitted within our environment."

**Segmentation:** Select “Yes” if ServiceBox restricts internal access to cardholder data processing to Paysafe.

*Make sure this description accurately represents your setup with ServiceBox and Paysafe.*

 

**Part 2d: In-Scope Locations/Facilities**

 

**Instructions:** List all physical locations relevant to PCI DSS compliance. If transactions are exclusively online, note that no physical locations are in scope.

**Part 2e: PCI SSC Validated Products and Solutions**

 

**Question:** “Does the merchant use any item identified on any PCI SSC Lists of Validated Products and Solutions?”

**Answer:** Yes

**Details:**

- **Payment Processor:** Paysafe
- **Payment Solution:** Hosted Payment Page (iFrame/Redirect)
- **Version Number:** (If applicable)
- **Compliance:** Confirm that the Paysafe solution is listed on the PCI SSC's validated applications list, if applicable.

**Part 2f: Third-Party Service Providers**

 

Answer the following:

- **Storing/processing/transmitting account data on behalf of the merchant?** Answer: Yes
- **Managing system components included in the PCI DSS scope?** Answer: Yes
- **Could impact the security of the CDE?** Answer: No

**Details:**

- **Primary Payment Processor:** Paysafe
- **Application:** ServiceBox processes payments via the Paysafe API.

**Part 2g: Summary of Assessment**

 

For each requirement, indicate the status and provide supporting evidence or documentation:

 

**Requirement 2 (Secure Configurations):** Status: ✅ In Place

*Documentation should verify the removal of vendor default accounts and proper security configurations.*

**Requirement 3 (Protect Stored Account Data):** Status: ✅ In Place (or Not Applicable if no data is stored)

*Provide documentation or a policy confirming that cardholder data is neither stored nor electronically processed.*

**Requirement 6 (Vulnerability Management):**

**6.3.1 Vulnerability Identification:** Status: ❌ Not Applicable (transactions are processed via Paysafe)

**6.3.3 Protection Against Known Vulnerabilities:** Status: ✅ In Place

*Maintain evidence that systems accessing ServiceBox are up-to-date with security patches.*

 

**Requirement 8 (Access Control):**

- **8.2.1 Unique User Identification:** Status: ✅ In Place
- **8.2.2 Restrictions on Shared/Generic IDs:** Status: ✅ In Place
- **8.2.5 Revoking Access for Terminated Users:** Status: ✅ In Place

**Requirement 9 (Physical Access):** Status: ❌ Not Applicable (no physical cardholder data storage)

**Requirement 11 (Security Testing):**

**11.3.2.1 External Vulnerability Scans:** Status: ❌ Not Applicable

**11.6.1 Change/Tamper Detection:** Status: ❌ Not Applicable

**Requirement 12 (Information Security Policy):**

**Policy Maintenance and Third-Party Management:** Status: ✅ In Place

*Ensure you have documentation, written agreements, and annual reviews of Paysafe’s compliance.*

**12.3.1 Risk Analysis (for CHD):** Status: ❌ Not Applicable until mandated (after March 31, 2025)

*For each requirement marked “Not Applicable,” include a clear explanation in Appendix D of your SAQ to justify the response.*

 

 

**Part 2h: Eligibility for SAQ A**

Confirm the following:

- Only e-commerce transactions are processed.
- All cardholder data processing is outsourced to a PCI DSS–validated third party (Paysafe).
- No electronic storage, processing, or transmission of cardholder data occurs.
- There is no internal access to full Primary Account Numbers (PAN).
- No on-premises cardholder data environment exists.

*Statement:*

 

"Merchant qualifies for SAQ A as all transactions are processed through a PCI DSS–validated payment gateway. No cardholder data is stored or transmitted within our environment."

 

 

### **6. PCI DSS Self-Assessment Questionnaire Responses**

For each PCI DSS requirement, ensure that your selected response ("In Place," "Not Applicable," etc.) is fully justified with evidence or documentation. Briefly summarize the evidence and refer to supporting documentation as needed.

 

**Requirement 2: Secure Configurations**

 

**2.2.2 Vendor Default Accounts:**  

- **Response:** ✅ In Place
- **Explanation:** Default accounts on systems used to access ServiceBox are either removed or secured according to industry best practices.

**Requirement 3: Protect Stored Account Data**

 

**3.1.1 Security Policies and Procedures:**

- **Response:** ✅ In Place
- **Explanation:** A documented policy confirms that no cardholder data is stored electronically.

**3.2.1 Minimized Data Storage:**

- **Response:**  ✅ In Place
- **Explanation:** Policies are in place to minimize or eliminate the storage of cardholder data (e.g., printed receipts are secured).

**Requirement 6: Vulnerability Management**

 

**6.3.1 Security Vulnerabilities Identification:**

- **Response:**  ❌ Not Applicable
- *Explanation:*  Since all transactions are processed through Paysafe’s PCI DSS–validated gateway, this requirement is not applicable.

**6.3.3 Protection Against Known Vulnerabilities:**

- **Response:**  ✅ In Place
- *Explanation:* Systems used to access ServiceBox are maintained with up-to-date security patches and vendor updates.

**Requirement 8: Access Control Measures**

 

**8.2.1 Unique User Identification:**

- **Response:** ✅ In Place

**8.2.2 Restrictions on Shared/Generic IDs:**

- **Response:** ✅ In Place

**8.2.5 Revoking Access for Terminated Users:**

- **Response:** ✅ In Place

**Requirement 11: Security Testing**

 

**11.3.2.1 External Vulnerability Scans:**

- **Response:** ❌ Not Applicable

**11.6.1 Change/Tamper Detection for Payment Pages:**

- **Response:** ❌ Not Applicable

**Requirement 12: Information Security Policy**

 

**12.3.1 Risk Analysis:**

- **Response:** ❌ Not Applicable (until required after March 31, 2025)

**12.8.x Third-Party Service Provider Management:**

- **Response:** ✅ In Place
- *Explanation:* Documentation, written agreements, and annual monitoring verify that Paysafe remains PCI DSS–compliant.

**12.10.1 Incident Response Plan:**

- **Response:** ✅ In Place
- *Explanation:* An incident response plan is documented and ready to guide actions in the event of a data breach.

### **7. Validation and Attestation**

**Part 3a: Merchant Acknowledgment**

The merchant must confirm:

- SAQ A was completed following the provided instructions.
- All information accurately reflects the assessment results.
- PCI DSS controls will be maintained at all times.

*All checkboxes should be selected as required.*

 

**Part 3b: Merchant Attestation**

The Merchant Executive Officer must complete and sign the attestation by providing:

- **Merchant Executive Officer Name:** (Enter full name)
- **Title:** (e.g., CEO, Owner, Compliance Officer)
- **Date:** (Enter in YYYY-MM-DD format)

*Example Statement:* "Electronically signed by \[Merchant Name\] on behalf of \[Business Name\]."

 

### **Need Help?**

If you have any questions or need support, please click the Help button in your ServiceBox account or email us at **support@getservicebox.com**.

- [Video Learning](https://learn.getservicebox.com/video-learning?hsLang=en#main-content)

    - [Accounting Integrations](https://learn.getservicebox.com/video-learning?hsLang=en#accounting-integrations)
- [FAQs](https://learn.getservicebox.com/faqs?hsLang=en)
- [Getting started](https://learn.getservicebox.com/getting-started?hsLang=en#main-content)

    - [User Guides](https://learn.getservicebox.com/getting-started?hsLang=en#user-guides)
- [ServiceBox Mobile](https://learn.getservicebox.com/servicebox-mobile?hsLang=en#main-content)

    - [Getting Started](https://learn.getservicebox.com/servicebox-mobile?hsLang=en#getting-started)
    - [User Guide Technician](https://learn.getservicebox.com/servicebox-mobile?hsLang=en#user-guide-technician)
    - [User Guide Admin](https://learn.getservicebox.com/servicebox-mobile?hsLang=en#user-guide-admin)
    - [FAQ](https://learn.getservicebox.com/servicebox-mobile?hsLang=en#faq)
    - [New Release](https://learn.getservicebox.com/servicebox-mobile?hsLang=en#new-release)
- [Invoices](https://learn.getservicebox.com/invoices?hsLang=en#main-content)

    - [Getting Started](https://learn.getservicebox.com/invoices?hsLang=en#getting-started)
    - [Advanced Functionality](https://learn.getservicebox.com/invoices?hsLang=en#advanced-functionality)
    - [User Guide](https://learn.getservicebox.com/invoices?hsLang=en#user-guide)
    - [FAQ](https://learn.getservicebox.com/invoices?hsLang=en#faq)
- [Quotes](https://learn.getservicebox.com/quotes?hsLang=en#main-content)

    - [Getting Started](https://learn.getservicebox.com/quotes?hsLang=en#getting-started)
    - [User Guide](https://learn.getservicebox.com/quotes?hsLang=en#user-guide)
    - [Advanced Functionality](https://learn.getservicebox.com/quotes?hsLang=en#advanced-functionality)
    - [FAQ](https://learn.getservicebox.com/quotes?hsLang=en#faq)
- [Work Orders](https://learn.getservicebox.com/work-orders?hsLang=en#main-content)

    - [Getting Started](https://learn.getservicebox.com/work-orders?hsLang=en#getting-started)
    - [User Guide](https://learn.getservicebox.com/work-orders?hsLang=en#user-guide)
    - [Advanced Functionalities](https://learn.getservicebox.com/work-orders?hsLang=en#advanced-functionalities)
    - [Work Order - FAQ](https://learn.getservicebox.com/work-orders?hsLang=en#work-order-faq)
- [Job Sites](https://learn.getservicebox.com/job-sites?hsLang=en#main-content)

    - [User Guide](https://learn.getservicebox.com/job-sites?hsLang=en#user-guide)
    - [Advanced Functionality](https://learn.getservicebox.com/job-sites?hsLang=en#advanced-functionality)
    - [FAQ](https://learn.getservicebox.com/job-sites?hsLang=en#faq)
- [Recurring Work](https://learn.getservicebox.com/recurring-work?hsLang=en#main-content)

    - [User Guide](https://learn.getservicebox.com/recurring-work?hsLang=en#user-guide)
    - [FAQ](https://learn.getservicebox.com/recurring-work?hsLang=en#faq)
- [Scheduler](https://learn.getservicebox.com/scheduler?hsLang=en#main-content)

    - [User Guide](https://learn.getservicebox.com/scheduler?hsLang=en#user-guide)
    - [Advanced Functionality](https://learn.getservicebox.com/scheduler?hsLang=en#advanced-functionality)
    - [FAQ](https://learn.getservicebox.com/scheduler?hsLang=en#faq)
- [Timesheets](https://learn.getservicebox.com/timesheets?hsLang=en#main-content)

    - [User Guide](https://learn.getservicebox.com/timesheets?hsLang=en#user-guide)
    - [Advanced Functionality](https://learn.getservicebox.com/timesheets?hsLang=en#advanced-functionality)
    - [FAQ](https://learn.getservicebox.com/timesheets?hsLang=en#faq)
- [Inventory](https://learn.getservicebox.com/inventory?hsLang=en#main-content)

    - [User Guides](https://learn.getservicebox.com/inventory?hsLang=en#user-guides)
    - [FAQ](https://learn.getservicebox.com/inventory?hsLang=en#faq)
- [Vendor Orders](https://learn.getservicebox.com/vendor-orders?hsLang=en#main-content)

    - [Getting Started](https://learn.getservicebox.com/vendor-orders?hsLang=en#getting-started)
    - [Advanced Functionality](https://learn.getservicebox.com/vendor-orders?hsLang=en#advanced-functionality)
    - [User Guide](https://learn.getservicebox.com/vendor-orders?hsLang=en#user-guide)
    - [FAQ](https://learn.getservicebox.com/vendor-orders?hsLang=en#faq)
- [Reporting](https://learn.getservicebox.com/reporting?hsLang=en#main-content)

    - [Getting Started](https://learn.getservicebox.com/reporting?hsLang=en#getting-started)
    - [FAQ](https://learn.getservicebox.com/reporting?hsLang=en#faq)
    - [User Guide](https://learn.getservicebox.com/reporting?hsLang=en#user-guide)
- [Integrations](https://learn.getservicebox.com/integrations?hsLang=en#main-content)

    - [Accounting Connector](https://learn.getservicebox.com/integrations?hsLang=en#accounting-connector)
    - [ServiceBox Payments](https://learn.getservicebox.com/integrations?hsLang=en#servicebox-payments)
- [Product Updates](https://learn.getservicebox.com/product-updates?hsLang=en)
- [Data Services](https://learn.getservicebox.com/data-services?hsLang=en#main-content)

    - [FAQ](https://learn.getservicebox.com/data-services?hsLang=en#faq)
- [QuickBooks Desktop](https://learn.getservicebox.com/quickbooks-desktop?hsLang=en#main-content)

    - [User Guide](https://learn.getservicebox.com/quickbooks-desktop?hsLang=en#user-guide)
    - [Getting Started](https://learn.getservicebox.com/quickbooks-desktop?hsLang=en#getting-started)
    - [FAQ](https://learn.getservicebox.com/quickbooks-desktop?hsLang=en#faq)
- [QuickBooks Online](https://learn.getservicebox.com/quickbooks-online?hsLang=en#main-content)

    - [Getting Started](https://learn.getservicebox.com/quickbooks-online?hsLang=en#getting-started)
    - [User Guide](https://learn.getservicebox.com/quickbooks-online?hsLang=en#user-guide)
    - [FAQ](https://learn.getservicebox.com/quickbooks-online?hsLang=en#faq)
- [Printing](https://learn.getservicebox.com/printing?hsLang=en)
- [Sage 50 (Canada)](https://learn.getservicebox.com/sage-50-canada?hsLang=en#main-content)

    - [Configuration](https://learn.getservicebox.com/sage-50-canada?hsLang=en#configuration)
    - [FAQ](https://learn.getservicebox.com/sage-50-canada?hsLang=en#faq)
    - [User Guide](https://learn.getservicebox.com/sage-50-canada?hsLang=en#user-guide)
- [First Steps for ServiceBox Users](https://learn.getservicebox.com/first-steps-for-servicebox-users?hsLang=en#main-content)

    - [User Guide](https://learn.getservicebox.com/first-steps-for-servicebox-users?hsLang=en#user-guide)
    - [FAQ](https://learn.getservicebox.com/first-steps-for-servicebox-users?hsLang=en#faq)
- [Configuring Your ServiceBox Site](https://learn.getservicebox.com/configuring-your-servicebox-site?hsLang=en#main-content)

    - [Getting Started](https://learn.getservicebox.com/configuring-your-servicebox-site?hsLang=en#getting-started)
    - [User Guides](https://learn.getservicebox.com/configuring-your-servicebox-site?hsLang=en#user-guides)
    - [FAQ](https://learn.getservicebox.com/configuring-your-servicebox-site?hsLang=en#faq)
    - [Advanced Functionality](https://learn.getservicebox.com/configuring-your-servicebox-site?hsLang=en#advanced-functionality)
- [Customer](https://learn.getservicebox.com/customer?hsLang=en#main-content)

    - [User Guide](https://learn.getservicebox.com/customer?hsLang=en#user-guide)
    - [Advanced Functionality](https://learn.getservicebox.com/customer?hsLang=en#advanced-functionality)
    - [FAQ](https://learn.getservicebox.com/customer?hsLang=en#faq)
- [Notes](https://learn.getservicebox.com/notes?hsLang=en)
- [To Dos](https://learn.getservicebox.com/to-dos?hsLang=en#main-content)

    - [Getting Started](https://learn.getservicebox.com/to-dos?hsLang=en#getting-started)
    - [To Dos - User Guide](https://learn.getservicebox.com/to-dos?hsLang=en#to-dos-user-guide)
- [Vendor](https://learn.getservicebox.com/vendor?hsLang=en#main-content)

    - [User Guide](https://learn.getservicebox.com/vendor?hsLang=en#user-guide)

[![sblogo-whiteandtransparent120x30\[8666\]](https://learn.getservicebox.com/hs-fs/hubfs/sblogo-whiteandtransparent120x30%5B8666%5D.png?width=120&height=30&name=sblogo-whiteandtransparent120x30%5B8666%5D.png "sblogo-whiteandtransparent120x30[8666]")](https://learn.getservicebox.com/knowledge-base?hsLang=en)

 

<https://www.facebook.com/getservicebox/> <https://x.com/getservicebox> <https://www.instagram.com/getservicebox/?hl=en> <https://www.youtube.com/@JobboxSoftware> <https://www.linkedin.com/company/getservicebox/>

Copyright © 2026