
Practical Cybersecurity with Jen Stone · 2026-04-28 · 21 min
This episode of Practical Cybersecurity moves past the standard PCI checklist to focus on the operational realities, common misconceptions, and "stealth" requirements that define SAQ A in the PCI DSS v4.0.1 era. The Eligibility Foundation Most merchants skip the Eligibility Criteria , which is the actual foundation of the assessment. Total Data Outsourcing: To qualify, a merchant must not store, process, or transmit any electronic account data on their own systems or premises. Call Center Exception : Merchants can still qualify for SAQ A if you use a third-party call center to handle payments on your behalf. Paper Ghosts : While the standard includes criteria for paper records, our experts have virtually never seen a modern SAQ A merchant that actually handles card data on paper in 15 years of assessments. The Iframe Paradox A significant "stealth" requirement exists for merchants using iframes to capture payments. Susceptibility by Design : Iframes are "by definition" susceptible to scripting attacks, where malicious code scrapes data directly from the customer's browser.