Who Decides PCI DSS Scope? The August 2026 PCI SSC FAQ #1331 Update Explained

Ever been in a meeting where everyone thinks they’re in charge until the real boss walks in? That’s what just happened in the PCI DSS community. On August 4, 2026, the PCI Security Standards Council (PCI SSC) dropped a revised FAQ #1331, and it’s a game-changer for anyone involved in merchant PCI DSS assessments. Here’s the headline: Merchants and QSAs don’t get to decide if SAQ eligibility can shrink the scope of a Report on Compliance (ROC). That power sits squarely with the accepting entity, the folks who actually answer to the payment brands. If you’re a QSA, an acquirer, or a merchant, this update just changed your playbook.

What Changed in FAQ #1331? (And Why It Matters)

  • The FAQ now says, flat out, that SAQ eligibility criteria are only for deciding if a merchant can use an SAQ, not for deciding which PCI DSS requirements apply in a ROC.
  • For Level 1 merchants (the big ones), the full PCI DSS applies unless the accepting entity says otherwise.
  • Merchants and QSAs can’t unilaterally decide to use SAQ criteria to cut down ROC scope.
  • This doesn’t apply to service providers, just merchants.
Who Decides?What’s Their Role?
Accepting EntityDecides if scope can be reduced for a ROC
MerchantCannot decide scope or use SAQ criteria for ROC
QSACannot unilaterally reduce scope using SAQ criteria

For QSAs: You Finally Have Explicit Backing

  • No more awkward debates when a merchant wants to “just use the SAQ scope” for their ROC.
  • The FAQ gives you a clear, official reference: Only the accepting entity can approve a reduced scope.
  • If you’re uncomfortable with a merchant’s push for a narrower assessment, you can point to this FAQ and stand your ground.
  • You’re not the one holding the risk the accepting entity is. That’s now in writing.

For Accepting Entities: You Hold the Risk—And the Power

  • The FAQ spells it out: You’re the one who answers to the payment brands, so you get to decide if a merchant can use an SAQ or reduce scope for a ROC.
  • Merchants and QSAs can’t cut you out of the conversation. If someone tries, you can point to this FAQ and remind them who’s responsible.
  • This is your reminder: Don’t let anyone scope you out of a risk decision you’re ultimately responsible for.

For Merchants: You Don’t Get to Decide Your Own Scope

  • You can’t unilaterally decide to use SAQ eligibility to shrink your ROC requirements.
  • The accepting entity (your acquirer or payment brand) has to be involved in any decision to reduce scope.
  • If you’re a Level 1 merchant, expect to meet the full PCI DSS requirements unless your accepting entity says otherwise.
  • This doesn’t apply to service providers, so don’t try to use this FAQ as a loophole.

The Exact Language (So There’s No Confusion)

“The Self-Assessment Questionnaire (SAQ) eligibility criteria are designed solely to determine whether a merchant may validate PCI DSS compliance using an SAQ, and do not define or limit the applicability of PCI DSS requirements for merchants required to complete a Report on Compliance (ROC).
…The accepting entity may, at its discretion, permit a merchant to use a reduced set of requirements or a specific SAQ as the basis for a ROC, but this determination is solely at the discretion of the accepting entity.
Merchants and Qualified Security Assessors (QSAs) do not have the authority to unilaterally determine ROC scope or to apply SAQ eligibility criteria as a basis for excluding PCI DSS requirements from a ROC assessment. The accepting entity is responsible for determining whether a merchant may reduce scope or use an SAQ as the basis for a ROC. This FAQ applies only to merchant assessments and does not apply to service provider assessments.”

The New Rules of the Road

The August 2026 update to PCI SSC FAQ #1331 draws a hard line: Only the accepting entity can decide if a merchant can use SAQ eligibility to reduce PCI DSS scope for a ROC. QSAs now have clear cover, accepting entities have the final say, and merchants can’t unilaterally shrink their compliance obligations. If you’re in PCI DSS, this is your new reference point. Don’t let anyone tell you otherwise.


Key Takeaway:
Only the accepting entity (like your acquirer or payment brand) can decide if a merchant can use SAQ eligibility to reduce PCI DSS scope for a Report on Compliance. Merchants and QSAs don’t get to make that call. This rule now applies clearly to Level 1 merchants—not service providers.

Ready to review your PCI DSS approach? Start by talking to your accepting entity. They’re the ones who get the final word.


Discover more from Chad M. Barr

Subscribe to get the latest posts sent to your email.

Disclaimer
The views and opinions expressed in this article are solely my own and do not necessarily reflect the views, opinions, or policies of my current or any previous employer, organization, or any other entity I may be associated with.

Similar Posts