POS Systems

PCI DSS Gas Station SAQ Guide: Choose the Right Form

September 18, 2026|9 min read

Figures in this article are being re-verified.

Penalty amounts, deadlines and regulatory citations are being checked against primary sources. Until this notice clears, confirm any figure with your state program before acting on it. Not yet verified. Not legal advice.

Why PCI DSS SAQ Compliance Matters for Fuel Retailers

Every gas station that accepts payment cards — at the pump, at the counter, or both — is subject to the Payment Card Industry Data Security Standard (PCI DSS). The standard is enforced not by a government agency but by your acquiring bank and the card brands (Visa, Mastercard, and others). Non-compliance can result in fines levied by the card brands, higher interchange rates, and ultimately the loss of your ability to accept cards. For a fuel retailer where the vast majority of transactions are card-based, that outcome is existential.

The primary compliance tool for most independent and small-chain operators is the Self-Assessment Questionnaire (SAQ) — a structured checklist that lets you validate your own compliance without hiring a Qualified Security Assessor (QSA) for a full on-site audit. But choosing the wrong SAQ form, or completing it incorrectly, can give you a false sense of security and expose you to liability when a breach occurs.

This guide explains how PCI DSS applies specifically to fuel retail environments, how to select the correct SAQ, and what your annual compliance calendar should look like. For a deep dive into the version-specific changes that affect fuel retailers, see our companion article on PCI DSS v4.0.1 for Fuel Retailers: What Changed and Deadlines.

PCI DSS Fundamentals for Gas Stations

What PCI DSS Covers

PCI DSS applies to any entity that stores, processes, or transmits cardholder data. At a gas station, cardholder data flows through multiple touchpoints:

  • Outdoor payment terminals (OPTs) — the card readers built into or mounted on fuel dispensers
  • Point-of-sale (POS) systems — the indoor cashier terminal and site controller
  • Back-office and network infrastructure — routers, switches, and any system that touches payment data
  • Third-party payment processors — the entities that actually move transaction data off-site

The Cardholder Data Environment (CDE)

PCI DSS defines the Cardholder Data Environment (CDE) as all systems that store, process, or transmit cardholder data, plus all systems connected to them. Reducing the size of your CDE — through network segmentation, point-to-point encryption (P2PE), and tokenization — is the single most effective way to reduce your SAQ burden. A station with a validated P2PE solution and no cardholder data on its own systems may qualify for a much shorter questionnaire than one where the POS stores card numbers locally.

The SAQ Landscape: Which Form Applies to You?

The PCI Security Standards Council (PCI SSC) publishes multiple SAQ types. The correct form depends on how your station accepts and processes card payments. The table below summarizes the forms most relevant to fuel retailers.

SAQ Type Who Qualifies Typical Fuel Retail Scenario Approximate Question Count
SAQ A Card-not-present merchants; all cardholder data functions fully outsourced Rarely applicable at the pump; may apply to a pure e-commerce fuel delivery booking with no in-person card acceptance Short
SAQ B Imprint-only or standalone dial-up terminals; no electronic cardholder data storage Legacy standalone dial-up terminal at the cashier; no IP connectivity for payment Moderate
SAQ B-IP Standalone IP-connected terminals; PCI SSC-listed PTS devices; no electronic storage IP-connected standalone terminal at the counter, isolated from other systems Moderate
SAQ C Payment application systems connected to the internet; no electronic cardholder data storage POS system with internet connectivity but no stored card data; common in mid-tier independent stations Substantial
SAQ C-VT Virtual terminal only; no other payment systems on-site Rare in fuel retail; may apply to a fleet billing office Short
SAQ P2PE Hardware P2PE solution listed by PCI SSC; no cardholder data on merchant systems Station using a validated P2PE solution at both the pump and the counter Short
SAQ D (Merchant) All other merchants not qualifying for A, B, B-IP, C, C-VT, or P2PE Stations with integrated POS/dispenser networks, stored card data, or complex network topologies Longest (~300+ requirements)

Practical note: Most independent gas stations with a networked POS system connected to outdoor dispensers will land on SAQ C or SAQ D. If your acquiring bank or processor has told you to complete SAQ B, verify that your outdoor payment terminals are truly not IP-connected — a common miscategorization at fuel sites.

The Outdoor Payment Terminal Problem

Fuel dispensers present a unique PCI DSS challenge. Outdoor payment terminals are physically exposed, often in locations that are difficult to monitor continuously, and historically have been targeted by skimming devices. PCI DSS requirements around physical security, tamper detection, and device inspection are especially demanding for the forecourt.

Key OPT Compliance Requirements

  • Device inventory: Maintain a list of all payment-accepting devices, including make, model, serial number, and location. Inspect devices periodically for tampering or substitution.
  • Tamper detection: Train staff to recognize signs of skimming hardware. Document inspections.
  • Software/firmware: Ensure OPT firmware is current and that devices are on the PCI SSC's list of approved PIN Transaction Security (PTS) devices. Devices that have reached end-of-life on the PTS list must be replaced.
  • Network segmentation: The payment network serving your dispensers should be isolated from your general business network (Wi-Fi, back-office systems, surveillance).

Equipment vendors such as Gilbarco (whose outdoor payment terminal line is branded FlexPay), Dover Fueling Solutions' Wayne brand (which offers the iX Pay outdoor payment terminal), and Verifone (whose unattended outdoor payment line is the UX series) each publish guidance on their devices' PTS approval status. Confirm with your vendor that any terminal you operate is currently listed — not just that it was listed when you installed it.

For a broader look at how your POS and site controller fit into the compliance picture, see our guide on Best Gas Station POS Systems for Independent Operators.

Step-by-Step: Completing Your SAQ

Step 1 — Scope Your Cardholder Data Environment

  1. Map every location where a card is swiped, dipped, or tapped: each dispenser OPT, each indoor POS lane, any mobile payment device.
  2. Trace the data path from each device to your processor. Identify every network component in that path.
  3. Determine whether any cardholder data is stored anywhere on your systems — even temporarily in logs or batch files.
  4. Identify any third-party service providers (payment processors, managed IT, loyalty platform vendors) that touch your CDE.

Step 2 — Confirm Your SAQ Type with Your Acquirer

Your acquiring bank or payment processor has the final word on which SAQ you must complete. Do not self-select a shorter form without written confirmation. Misclassification shifts liability to you in the event of a breach.

Step 3 — Complete the SAQ Honestly

Each SAQ requirement has a "Yes," "No," or "N/A" response. A "No" answer does not automatically disqualify you — it identifies a gap you must remediate. Document your compensating controls where you cannot fully meet a requirement. Never mark "Yes" for a control you have not actually implemented.

Step 4 — Complete the Attestation of Compliance (AOC)

The SAQ is accompanied by an Attestation of Compliance. An authorized officer of your business must sign it. The AOC is what you submit to your acquirer as proof of compliance.

Step 5 — Submit and Retain Records

Submit the completed SAQ and AOC to your acquirer by their deadline — typically annual. Retain copies for your records. Your acquirer may also require quarterly network vulnerability scans performed by an Approved Scanning Vendor (ASV).

Quarterly ASV Scans: What Fuel Retailers Need to Know

If your payment systems are internet-facing — which is true of virtually any station with an IP-connected POS or OPT — PCI DSS requires quarterly external vulnerability scans by a PCI SSC-approved ASV. These scans probe your external IP addresses for known vulnerabilities. A passing scan report must accompany your SAQ submission for most SAQ types (C, D, and others with internet-facing components).

Internal vulnerability scans are also required under SAQ D. These can be performed by qualified internal staff using approved tools, but the process must be documented.

Third-Party Service Providers and Responsibility Matrices

Most gas stations rely on third parties for payment processing, managed network services, and sometimes point-to-point encryption. PCI DSS requires you to:

  • Maintain a written list of all third-party service providers that handle cardholder data.
  • Obtain and review each provider's current AOC or equivalent evidence of compliance.
  • Execute written agreements that define each party's PCI DSS responsibilities.
  • Monitor providers at least annually for continued compliance.

A Responsibility Matrix (sometimes called a shared responsibility matrix) documents which PCI DSS requirements your processor or P2PE solution provider covers versus which ones remain your responsibility. If your processor provides a validated P2PE solution, they should supply this matrix — and it is the document that determines whether you qualify for SAQ P2PE.

Understanding how your payment processing agreement allocates these responsibilities is critical. Our article on Back-Office Reconciliation: Match POS, Dispenser & Bank Data covers how transaction data flows from dispenser to bank, which is directly relevant to scoping your CDE accurately.

Annual PCI DSS Compliance Calendar for Gas Stations

Frequency Task Who Is Responsible
Ongoing Monitor payment devices for tampering; review security logs Site manager / IT
Quarterly External ASV vulnerability scan (if internet-facing systems) Approved Scanning Vendor
Quarterly Review and update list of authorized personnel with CDE access Owner / IT
Quarterly Verify third-party service provider compliance status Owner / compliance manager
Annual Complete SAQ and AOC; submit to acquirer Owner / authorized officer
Annual Update device inventory (all OPTs, POS terminals) Site manager
Annual Review and update network diagram and data flow diagram IT / managed service provider
Annual Security awareness training for all staff with CDE access Owner / manager
Annual Review and test incident response plan Owner / IT
As needed Replace OPTs that have reached PTS end-of-life Owner / equipment vendor

Common SAQ Mistakes at Gas Stations

1. Selecting SAQ B When You Have IP-Connected Dispensers

SAQ B is for standalone dial-up or imprint-only terminals. If your dispensers communicate over IP — even through a proprietary network — SAQ B does not apply. This is one of the most frequent miscategorizations in fuel retail.

2. Ignoring the Back-Office Network

Stations often focus on the payment terminals and overlook the router, switch, or back-office PC that sits between the dispenser and the processor. If that equipment is on the same network segment as your payment systems and is not properly segmented, it is in scope.

3. Assuming Your Processor Handles Everything

Even with a fully outsourced payment solution, you retain responsibility for physical security of devices, staff training, and your own network infrastructure. Your processor's AOC covers their systems, not yours.

4. Not Replacing End-of-Life PTS Devices

The PCI SSC publishes expiration dates for approved PTS devices. Operating an expired device is a compliance violation regardless of whether the hardware still functions. Check the PCI SSC's online PTS device list annually.

5. Failing to Document Compensating Controls

If you cannot meet a specific requirement — for example, because a legacy dispenser does not support a required security feature — you must document a compensating control that provides equivalent protection. Leaving the field blank or marking "N/A" without justification is not acceptable.

Cybersecurity and PCI DSS: The Broader Picture

PCI DSS compliance is a floor, not a ceiling. The standard addresses cardholder data specifically, but a gas station's network also carries ATG data, surveillance feeds, loyalty program data, and back-office financial records. A breach that starts outside the CDE can migrate into it. For a broader treatment of network security at fuel retail sites, see our guide on Gas Station Cybersecurity: Protect POS, Dispensers & Data.

Action Items: Your PCI DSS SAQ Checklist

  1. Confirm your SAQ type in writing with your acquiring bank or payment processor before completing any form.
  2. Map your CDE — every device, every network path, every third party that touches card data.
  3. Audit your OPTs — verify PTS approval status, check for tamper evidence, and update your device inventory.
  4. Segment your network — isolate payment systems from general business and guest Wi-Fi networks.
  5. Collect third-party AOCs — obtain current compliance documentation from every service provider in your payment chain.
  6. Schedule your ASV scan — if you have internet-facing payment systems, book your first quarterly scan now.
  7. Train your staff — anyone who handles payment devices or has access to the CDE needs annual security awareness training.
  8. Complete and sign the AOC — an authorized officer must attest; do not delegate the signature without legal authority to do so.
  9. Set calendar reminders — quarterly scans, annual SAQ renewal, and PTS device expiration dates all need to be tracked.
  10. Review after any significant change — a new POS system, a new dispenser, a network upgrade, or a new processor relationship may change your SAQ type or scope.

Sources

Was this helpful?
Disclaimer: Always verify with your state UST program. Regulations change.