SAQ B-IP is essentially SAQ B's IP-connected cousin — merchants using only standalone, PCI-listed PTS point-of-interaction (POI) devices that connect to the processor over an IP network instead of a phone line.
Eligibility criteria — a merchant needs all of these to be true
They use only standalone, PCI-listed approved PTS POI devices connected via IP — this specifically excludes Secure Card Readers (SCR) and Secure Card Readers for PIN (SCRP).
Those devices are validated on the PCI SSC PTS POI list.
The devices aren't connected to any other system in the merchant's environment (network segmentation can achieve this).
Account data only ever moves from the approved POI device to the processor — nowhere else.
The POI device doesn't rely on another device (a computer, phone, tablet) to connect to the processor.
No account data is stored electronically; anything retained is paper only.
Two disqualifiers worth flagging to a merchant: if the terminal is classified as an SCR or SCRP, SAQ B-IP doesn't apply. And if the device is connected to a cash register system or relies on another device to reach the processor, that also rules it out.
What this looks like in practice
A standalone countertop terminal plugged straight into ethernet or broadband, talking directly to the processor — not routed through the merchant's own POS system or network.
Requirement scope
10 requirement categories (Requirements 1, 2, 3, 4, 6, 7, 8, 9, 11, 12) — network security controls, secure configurations, protecting stored and transmitted data, secure systems, access control, physical security, external vulnerability scanning, and security policy.
ASV scanning
Yes — Requirement 11 applies, so quarterly ASV scans are required given the IP connection.
Not a fit?
If the terminal connects over a phone line instead, that's plain SAQ B. If the device is an SCR/SCRP or relies on another device to connect, or there's a cash register in the mix, look at SAQ C or SAQ D.
