Your card processor (the bank or company that gave you your Authorize.net merchant account) will ask you to file a PCI self-assessment once a year. For shops using Manifold's integrated Authorize.net card charging, the right form is the **SAQ A**. It's the shortest PCI form because card data never touches your systems.

Step 1: Get the official form

Ask your card processor for "the SAQ A self-assessment for PCI DSS v4.0.1." They will either send you the PDF or point you to a portal you fill in online. Don't try to download it from the internet; use the version your processor accepts.

Step 2: Fill in the merchant information

The first page asks about your business: legal name, doing-business-as name, contact, address, and what type of card payments you accept. For the "payment acceptance channels" question, answer "e-commerce" only (the in-person terminal at the counter has its own form; see the related article).

Step 3: Pre-filled answers for the eligibility criteria

The form will ask whether several statements are true about your card setup. With Manifold + Authorize.net, the honest answers are:

  • "We accept only card-not-present transactions for this scope" - **YES** (in-person terminal sales are on a separate form)
  • "All cardholder data functions are outsourced to PCI DSS compliant third parties" - **YES** (Authorize.net)
  • "We do not electronically store, process, or transmit any cardholder data on our systems" - **YES** (Manifold uses Authorize.net's hosted AcceptUI card form, served from an Authorize.net iframe, so card data never reaches our or Manifold's servers and no card field is rendered by Manifold)
  • "We have confirmed our third parties are PCI DSS compliant" - **YES** (you can ask your card processor for Authorize.net's current AOC)
  • "We retain only paper receipts with last-4 of the card" - **YES** (Manifold's receipts only show last-4)
  • "The payment page cannot be tampered with by our website" - **YES** (Manifold loads Authorize.net's payment script directly and restricts what other scripts can load on card pages)

Step 4: Pre-filled answers for the questionnaire

A few yes/no questions about controls. For each

  • "Sensitive authentication data is not retained after authorization" - **In Place** (CVV is never received)
  • "Stored cardholder data is protected" - **In Place** (no cardholder data is stored on your systems)
  • "System components are kept patched" - **In Place** (Manifold patches the platform; your shop is not running its own card-data servers)
  • "Strong authentication for users" - **In Place** (Manifold requires a password and a bot challenge to log in)
  • "Quarterly external vulnerability scans" - **In Place via Manifold** (Manifold engages an Approved Scanning Vendor for the manifold.1sixty8.com domain; ask Manifold for the latest passing scan if your processor wants a copy)
  • "Maintain a list of third-party service providers" - **In Place** (your list: Authorize.net, Manifold)
  • "Written agreements with TPSPs" - **In Place** (your Authorize.net merchant agreement, your Manifold subscription agreement)
  • "Annual review of TPSP PCI status" - **In Place** (refresh each year)
  • "Incident response plan exists" - one short page describing what you'd do if you suspected a card-data breach. Ask Manifold for a starter template if you don't have one.

Step 5: Sign and send

Sign the form (typed name and date is accepted), and send the signed copy back to your card processor. They keep it on file. PCI SSC doesn't receive a copy; the card brands don't receive a copy; only your processor.

Step 6: Repeat next year

The form is filed annually, or sooner if you change something major (new payment channel, new processor, new TPSP).

If your card processor asks for documentation about Manifold's part of the picture, you can ask Manifold for: our current SAQ A AOC, our latest passing ASV scan, and a copy of the incident response plan we use.