If your application necessitates your clients to enter their info on their own personal products, Then you certainly qualify for SAQ A. Formally attest your compliance. An AOC (attestation of compliance) is the form you use to sign that you’ve reached PCI DSS compliance. Finishing your questionnaire without “Improper” answers https://www.nathanlabsadvisory.com/