Payment card industry
(PCI) compliance

Payments and refunds

Payment card industry (PCI) compliance

The Division of Finance's Accounting Operations provides training, information, and resources about Payment Card Industry (PCI) standards and procedures.

The Finance Compliance Coordinator is Becky Yorgason [email protected]

PCI training for state employees, vendors, and volunteers

Contact [email protected] to arrange staff assignments for the training.

Download PCI self-assessment questionnaires (SAQs) & worksheets

 


SAQ A  

Used when card not present, i.e. e-commerce, full site outsourced.

SAQ A pdf
SAQ A docx

SAQ B 

Used for standalone, dial-out terminals with no electronic cardholder data storage.

SAQ B pdf
SAQ B docx

SAQ B-IP

Used for standalone, IP-connected terminals; no electronic cardholder data storage.

SAQ B-IP pdf
SAQ B-IP docx

SAQ C 

Used for payment application systems connected to the Internet, no electronic cardholder data storage.

SAQ C pdf
SAQ C docx

SAQ C-VT 

Used with web-based virtual terminals; no electronic cardholder data storage.

SAQ C-VT pdf
SAQ C-VT docx

SAQ D 

Used with in-person transactions, not outsourced; may have electronic cardholder data storage.

SAQ D pdf
SAQ D docx