SAQ pricing
PCI SAQ P2PE cost 2026: 33 controls, and why validated is the whole point
SAQ P2PE is the lightest questionnaire available for in-person card acceptance, at 33 controls against 160 for SAQ C. Qualifying requires using a PCI-validated P2PE solution exclusively, and validated is doing all the work in that sentence: a terminal marketed as encrypted is not the same thing. Nobody publishes what completion costs, so this page gives you the eligibility rules, the control counts, and where merchants get this wrong.
Updated July 2026
Controls
33
v4.0.1; lightest SAQ for in-person acceptance
Against SAQ C
~5x fewer
33 controls against 160
Qualifies
Validated P2PE solution, exclusively
What validated P2PE actually means
P2PE is point-to-point encryption: cardholder data is encrypted at the point of capture, typically in the terminal's PIN entry device, and stays encrypted until it reaches a validated decryption environment, typically the payment processor's hardware security module. Your network never sees decrypted cardholder data. That is the mechanism, and it is why the control count collapses to 33: most of your environment is genuinely out of scope rather than merely argued to be.
The PCI SSC maintains the official P2PE Solutions list, showing each validated solution by provider, validation date and expiry. For SAQ P2PE eligibility your terminal must be deployed as part of a listed solution, configured per that solution's Solution Provider Implementation Manual, and used exclusively for card acceptance. Vendors including Bluefin, Verifone and Ingenico offer validated P2PE solutions on select models, but treat that as a starting point for your search rather than as the answer. Listings carry expiry dates and cover specific models and configurations, so the brand name is never the qualification. The listing is.
This matters because the mistake is easy to make honestly. A merchant is sold an encrypted terminal, reasonably concludes the card data is protected, and attests to SAQ P2PE. The encryption may be real, but the eligibility is not, and the gap tends to surface during an acquirer compliance review or a post-incident investigation, when the merchant is dealing with both the underlying problem and an inaccurate attestation. Confirm validation explicitly, in writing, with your terminal vendor and solution provider, and keep that confirmation with your SAQ.
What P2PE buys you, in controls
Every count below is published in the SAQ documents in the PCI SSC library under v4.0.1, so you can check each one. Counts are approximate and shift slightly with counting method. This is the comparison to reason about, because the number of controls you have to evidence is the closest thing PCI has to a unit of work, and it is what any firm quoting you will price against.
| SAQ | Controls (v4.0.1) | What it means |
|---|---|---|
| SAQ P2PE | 33 | All card acceptance through one PCI-validated P2PE solution. |
| SAQ B-IP | 82 | Standalone IP-connected terminals. Roughly 2.5x SAQ P2PE. |
| SAQ C | 160 | Payment application on the internet, not isolated. Roughly 5x SAQ P2PE. |
| SAQ D (Merchant) | ~251 | The full standard. Roughly 8x SAQ P2PE. |
Source: the SAQ documents in the PCI SSC document library, v4.0.1. Older figures still circulate from the retired v3.2.1, where SAQ D-Merchant was 329; v4.0 consolidated many sub-requirements, so current counts are lower.
The terminal hardware sits on the other side of that trade, and it is quoted per terminal by your terminal vendor or acquirer rather than published anywhere. So price it yourself: ask for the validated P2PE terminal against what you would otherwise buy, multiply by your terminal count and your refresh cycle, and weigh it against the control delta above, every year, plus the scope reduction below. Ask also whether the solution provider charges a recurring fee per terminal, and what device inspection under Requirement 9 involves for your model, because those are the lines merchants forget to ask about rather than lines anyone publishes.
The three qualification mistakes
First, claiming eligibility with a non-validated encrypted terminal. Covered above, and it is the most common one by a distance. Eligibility requires the terminal to be part of a listed validated P2PE solution. If it is not listed, SAQ B-IP or SAQ C applies regardless of any marketing claim about encryption.
Second, deploying a validated solution outside its validated configuration. Each solution has a Solution Provider Implementation Manual specifying acceptable deployment patterns. Using the terminal with a processor the solution is not validated for, modifying firmware, or attaching non-validated peripherals can invalidate eligibility even though the terminal itself appears on the list. The listing is for a solution deployed a particular way, not for a box.
Third, mixed-channel acceptance. A merchant running validated P2PE in person and also taking payments by e-commerce, mail order or virtual terminal cannot use SAQ P2PE alone, because those channels are not covered by the P2PE solution. That environment typically needs SAQ D-Merchant or a submission covering each channel separately. The qualifying SAQ P2PE merchant uses validated P2PE for all card acceptance and nothing else. This is worth checking against reality rather than against intent, because the phone order somebody takes occasionally is exactly the channel that gets forgotten.
Check the official PCI SSC P2PE Solutions list
The PCI SSC publishes the validated P2PE Solutions list with each solution's provider, validation date and expiry. Confirm your solution is listed, and listed for the way you deploy it, before claiming SAQ P2PE eligibility.
Frequently asked
Nobody publishes a price for completing an SAQ, and we are not going to invent one. No QSA, consultant, ASV or acquirer publishes a fee schedule for SAQ P2PE completion, so any specific figure you find traces back to somebody's estimate rather than to a published rate. What is published, and what drives the work, is the control count: SAQ P2PE carries 33 controls, against 82 for SAQ B-IP, 160 for SAQ C and around 251 for SAQ D-Merchant. It is the lightest questionnaire available for in-person card acceptance, and roughly a fifth of SAQ C. The terminal hardware is a separate question, quoted per terminal by your terminal vendor or acquirer against your terminal count and your refresh cycle. Ask them, because they are the only people who have that number.
Continue reading
SAQ A cost
~24 controls, the e-commerce equivalent of P2PE's descoping.
SAQ C cost
160 controls, where many P2PE candidates are today.
SAQ D cost
~251 controls, where mixed-channel acceptance lands you.
Reduce PCI costs
Scope reduction, expressed in controls rather than guesses.
Level 3 PCI cost
Where most SAQ P2PE merchants sit in the level taxonomy.
ASV + pen test cost
The Requirement 11 testing set, its frequencies and its drivers.