PCI DSS compliance is not one artifact — it is a tiered set, and the artifact you file is decided by who actually stores, processes, or transmits cardholder data (CHD), and how. Merchants are tiered by Visa/Mastercard into Level 1 (more than 6M transactions/year — full Report on Compliance by a QSA), Level 2 (1M–6M — SAQ plus Attestation of Compliance), Level 3 (20K–1M e-commerce or 1M total — SAQ plus AOC), and Level 4 (below the Level 3 thresholds — SAQ plus AOC, with compliance enforcement typically delegated to the acquiring bank). Service providers have their own two-tier split: Level 1 (more than 300K transactions/year — full ROC by a QSA) and Level 2 (below — SAQ-D for Service Providers plus AOC).
The 'SAQ' the analyst files is itself a family, not a single form. Eight named SAQ documents sit across four SAQ families (sometimes called four SAQ 'levels' in shorthand): SAQ A (card-not-present merchants that fully outsource all cardholder data functions to a PCI-DSS-compliant processor — the cleanest case), SAQ A-EP (e-commerce merchants that outsource processing but retain a page that touches the consumer's browser), SAQ B (standalone dial-out or IP-terminal merchants with no cardholder data storage — now retired for most modern use cases), SAQ B-IP (standalone POI-terminal merchants that connect via IP, no cardholder data storage), SAQ C-VT (virtual-terminal merchants, one transaction at a time, no cardholder data storage), SAQ C (merchants with a payment application system connected to the internet, no cardholder data storage), and SAQ D (the catch-all — all other merchants and most service providers). The framework language you will see quoted is 'four SAQ levels'; that is the four SAQ families (A, A-EP, B/B-IP, C-VT/C, D), with the variously retired or split subforms collapsed inside each family.
The gate that decides which SAQ you file is concrete: who holds the PAN at rest, who transmits the PAN, and who has the keys. A D2C merchant that redirects consumers to a PCI-DSS-compliant tokenized checkout (Stripe Checkout, Braintree Hosted Fields, Adyen Drop-in) is SAQ-A territory — the merchant never sees the PAN and the tokenized integration is the one the processor attests on. The same merchant touching a customer-data field on its own server (a saved-card flow on the merchant's backend, a custom checkout page that POSTs to its own API) is SAQ-D: full twelve-requirements territory, with the auditor on the hook for everything below.