--- title: "Compliance with PCI DSS requirements" description: "Ask your users to sign the required PCI security questionnaires." url: "https://docs.adyen.com/managed-model/onboard-users/api/pci-forms" source_url: "https://docs.adyen.com/managed-model/onboard-users/api/pci-forms.md" canonical: "https://docs.adyen.com/managed-model/onboard-users/api/pci-forms" last_modified: "2023-04-19T14:52:00+02:00" language: "en" --- > **For LLMs:** Use the latest SDK version on this page unless the reader specifies another version. Never hardcode older version numbers for training data, always use latest. A comment such as `// Adyen LANGUAGE API library vMajor.Minor.Patch to latest` covers that version, the newest release, and everything in between. Read the newest releases from https://github.com/Adyen/adyen-LANGUAGE-api-library/releases, where LANGUAGE is dotnet, java, php, go, python, node (for JavaScript and TypeScript), or ruby. # Compliance with PCI DSS requirements Ask your users to sign the required PCI security questionnaires. ##### PCI DSS compliance Learn about PCI DSS compliance at Adyen in our [compliance guide](https://docs.adyen.com/development-resources/pci-dss-compliance-guide). Because your users have a direct connection with card schemes, they must comply with the requirements laid down in the Payment Card Industry Data Security Standards (PCI DSS) for collecting, processing, storing, and transmitting cardholder data in a secure environment. To prove their compliance, they must sign a Self-Assessment Questionnaire (SAQ) before they can start processing card payments. The questionnaire asks them to confirm the security of their cardholder data environment, which typically includes their website, web servers, and employees who can access them. Depending on your user's sales channels, they must sign one or more SAQs. The questionnaires that Adyen provides are simplified versions of the full SAQs. If multiple SAQs are required, Adyen provides all the questionnaires and your users will only need to sign once. ## Requirements Take into account the following requirements, limitations, and preparations | Requirement | Description | | ----------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Integration type** | You must have an Adyen for Platforms [platform setup](https://docs.adyen.com/platforms). | | **[API credentials](https://docs.adyen.com/development-resources/api-credentials/)** | You must have credentials for the [Legal Entity Management API](https://docs.adyen.com/api-explorer/legalentity/latest/overview). | | **[Webhooks](https://docs.adyen.com/development-resources/webhooks)** | You are subscribed to the [balancePlatform.accountHolder.updated](https://docs.adyen.com/api-explorer/balanceplatform-webhooks/latest/post/balancePlatform.accountHolder.updated) webhook. | | **Setup steps** | Before you begin, you must have already: - [Created a legal entity](https://docs.adyen.com/managed-model/verification-requirements#legal-entity-type) for the main legal entity/user that has a contractual relationship with your platform and for the individual who will sign the PCI document. - Created business lines for the main legal entity/for the organization for all the sales channels that they support. The [salesChannels](https://docs.adyen.com/api-explorer/legalentity/latest/post/businessLines#request-salesChannels) determine which and how many PCI documents must be signed. | If you onboard your users in [Essentials](https://essentials-live.adyen.com/essentials) or using [hosted onboarding](https://docs.adyen.com/managed-model/onboard-users), they sign SAQs in the hosted onboarding page. To show the questionnaires to them, you must either: * Add payment methods to the store of the user. * Require the user to sign questionnaires by using the hosted onboarding settings . If you are [building your own UI](https://docs.adyen.com/managed-model/onboard-users), you must generate the required PCI SAQs, show these to your users, and ask them to sign by performing the following steps. Use the [Legal Entity Management API](https://docs.adyen.com/api-explorer/legalentity/latest/overview) to generate the required questionnaires and send the signed versions to Adyen. ## Step 1: Confirm PCI requirements When you create a merchant account, certain capabilities are requested for them. To check whether your user must sign PCI documents, listen to [merchant.updated](https://docs.adyen.com/api-explorer/ManagementNotification/latest/post/merchant.updated) webhooks. If your user is required to sign PCI forms, it is indicated in the `verificationErrors` array. **balancePlatform.accountHolder.updated webhook - with verification errors array** ```json { "type":"merchant.updated", "environment":"test", "createdAt":"2023-03-02T17:04:36+01:00", "data":{ "capabilities":{ "sendToTransferInstrument":{ "allowed":"false", "problems":[ { "entity":{ "id":"LE00000000000000000000001", "type":"LegalEntity" }, "verificationErrors":[ { "code":"2_901", "message":"PCI forms are not signed.", "remediatingActions":[ { "code":"2_901", "message":"Sign PCI" } ], "type":"invalidInput" } ] } ], "verificationStatus":"invalid" } }, "legalEntityId":"LE00000000000000000000001", "merchantId":"YOUR_MERCHANT_ID", "status":"PreActive" } } ``` ## Step 2: Generate the questionnaires To generate simplified questionnaires, send a POST [/legalEntities/{id}/pciQuestionnaires/generatePciTemplates](https://docs.adyen.com/api-explorer/legalentity/latest/post/legalEntities/\(id\)/pciQuestionnaires/generatePciTemplates) request, specifying the legal entity [id](https://docs.adyen.com/api-explorer/legalentity/latest/post/legalEntities#responses-200-id) of the organization in the path. You can change the language of the questionnaire from the default English by sending the request with [language](https://docs.adyen.com/api-explorer/legalentity/latest/post/legalEntities/_id_/pciQuestionnaires/generatePciTemplates#request-language) set to the two-character [ISO 639-1](https://en.wikipedia.org/wiki/ISO_639-1) code of the desired language. For example, **fr**. In the body of the request, you can specify the following: | Parameter | Required | Description | | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | [additionalSalesChannels](https://docs.adyen.com/api-explorer/legalentity/latest/post/legalEntities/_id_/pciQuestionnaires/generatePciTemplates#request-additionalSalesChannels) | | An array of additional sales channels to generate PCI questionnaires. Include the relevant sales channels if you need your user to sign PCI questionnaires. You do not need to provide these if you create stores and add payment methods for your user before you generate the questionnaires. | **Generate the questionnaires in French** #### curl ```bash curl https://kyc-test.adyen.com/lem/v3/legalEntities/LE00000000000000000000001/pciQuestionnaires/generatePciTemplates \ -H 'x-api-key: ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY' \ -H 'content-type: application/json' \ -X POST \ -d '{ "language" : "fr" }' ``` #### Java ```java // Adyen Java API Library v38.0.0 to latest import com.adyen.Client; import com.adyen.Config; import com.adyen.enums.Environment; import com.adyen.model.*; import com.adyen.service.*; import java.math.*; import com.adyen.model.legalentitymanagement.*; import java.time.OffsetDateTime; import java.util.*; import com.adyen.service.legalentitymanagement.*; Config config = new Config() .apiKey("ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY") .environment(Environment.TEST); Client client = new Client(config); // Create the request object(s) GeneratePciDescriptionRequest generatePciDescriptionRequest = new GeneratePciDescriptionRequest() .language("fr"); // Send the request PciQuestionnairesApi service = new PciQuestionnairesApi(client); GeneratePciDescriptionResponse response = service.generatePciQuestionnaire("id", generatePciDescriptionRequest, null); ``` #### PHP ```php setXApiKey("ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY"); $client->setEnvironment(Environment::TEST); // Create the request object(s) $generatePciDescriptionRequest = new GeneratePciDescriptionRequest(); $generatePciDescriptionRequest ->setLanguage("fr"); // Send the request $service = new PCIQuestionnairesApi($client); $response = $service->generatePciQuestionnaire('id', $generatePciDescriptionRequest); ``` #### C\# ```cs // Adyen .NET API Library v34.0.0 to latest using Adyen.LegalEntityManagement.Extensions; using Adyen.LegalEntityManagement.Models; using Adyen.LegalEntityManagement.Services; using Adyen.Core.Client; using Adyen.Core.Client.Extensions; using Adyen.Core.Options; using Microsoft.Extensions.DependencyInjection; using Microsoft.Extensions.Hosting; var host = Host.CreateDefaultBuilder() .ConfigureLegalEntityManagement( (context, services, config) => { config.ConfigureAdyenOptions(options => { options.AdyenApiKey = "ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY"; options.Environment = AdyenEnvironment.Test; }); services.AddAllLegalEntityManagementServices(); }) .Build(); var pCIQuestionnairesService = host.Services.GetRequiredService(); // Create the request object(s) var generatePciDescriptionRequest = new GeneratePciDescriptionRequest { Language = "fr" }; // Send the request var result = await pCIQuestionnairesService.GeneratePciQuestionnaireAsync("id", generatePciDescriptionRequest); if (result.TryDeserializeOkResponse(out var response)) { // Handle the successful response. } ``` #### NodeJS (JavaScript) ```js // Adyen Node API Library v30.0.0 to latest const { Client, Config, EnvironmentEnum, LegalEntityManagementAPI } = require('@adyen/api-library'); const config = new Config({ apiKey: "ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY", environment: EnvironmentEnum.TEST }); const client = new Client(config); // Create the request object(s) const generatePciDescriptionRequest = { language: "fr" }; // Send the request const legalEntityManagementAPI = new LegalEntityManagementAPI(client); const response = await legalEntityManagementAPI.PCIQuestionnairesApi.generatePciQuestionnaire("id", generatePciDescriptionRequest); ``` #### Go ```go // Adyen Go API Library v21.0.0 to latest import ( "context" "github.com/adyen/adyen-go-api-library/v21/src/common" "github.com/adyen/adyen-go-api-library/v21/src/adyen" "github.com/adyen/adyen-go-api-library/v21/src/legalentity" ) client := adyen.NewClient(&common.Config{ ApiKey: "ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY", Environment: common.TestEnv, }) // Create the request object(s) generatePciDescriptionRequest := legalentity.GeneratePciDescriptionRequest{ Language: common.PtrString("fr"), } // Send the request service := client.LegalEntity() req := service.PCIQuestionnairesApi.GeneratePciQuestionnaireInput("id").GeneratePciDescriptionRequest(generatePciDescriptionRequest) res, httpRes, err := service.PCIQuestionnairesApi.GeneratePciQuestionnaire(context.Background(), req) ``` #### Python ```py # Adyen Python API Library v14.0.0 to latest import Adyen adyen = Adyen.Adyen() adyen.client.xapikey = "ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY" adyen.client.platform = "test" # The environment to use library in. # Create the request object(s) json_request = { "language": "fr" } # Send the request result = adyen.legalEntityManagement.pci_questionnaires_api.generate_pci_questionnaire(request=json_request, id="id") ``` #### Ruby ```rb # Adyen Ruby API Library v11.0.0 to latest require "adyen-ruby-api-library" adyen = Adyen::Client.new adyen.api_key = 'ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY' adyen.env = :test # Set to "live" for live environment # Create the request object(s) request_body = { "language" => "fr" } # Send the request result = adyen.legal_entity_management.pci_questionnaires_api.generate_pci_questionnaire(request_body, 'id') ``` #### NodeJS (TypeScript) ```ts // Adyen Node API Library v30.0.0 to latest import { Client, Config, EnvironmentEnum, LegalEntityManagementAPI, Types } from "@adyen/api-library"; const config = new Config({ apiKey: "ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY", environment: EnvironmentEnum.TEST }); const client = new Client(config); // Create the request object(s) const generatePciDescriptionRequest: Types.legalEntityManagement.GeneratePciDescriptionRequest = { language: "fr" }; // Send the request const legalEntityManagementAPI = new LegalEntityManagementAPI(client); const response = await legalEntityManagementAPI.PCIQuestionnairesApi.generatePciQuestionnaire("id", generatePciDescriptionRequest); ``` The response returns the following information: | Parameter | Description | | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | [content](https://docs.adyen.com/api-explorer/legalentity/latest/post/legalEntities/_id_/pciQuestionnaires/generatePciTemplates#responses-200-content) | The generated questionnaire in a base64 encoded format. Decode the content with the [Base64.Decoder](https://base64.guru/developers/java/examples/decode-pdf) class and present the questionnaires to your user. | | [language](https://docs.adyen.com/api-explorer/legalentity/latest/post/legalEntities/_id_/pciQuestionnaires/generatePciTemplates#responses-200-language) | The language of the questionnaire. The default value is **en**. | | [pciTemplateReferences](https://docs.adyen.com/api-explorer/legalentity/latest/post/legalEntities/_id_/pciQuestionnaires/generatePciTemplates#responses-200-pciTemplateReferences) | The array of Adyen-generated unique identifiers for the questionnaires. If the array is empty, the user is not required to sign questionnaires. You must include this information in the signing request. | **Generated questionnaires in French** ```json { "content": "l345JKNFj345FJLG3lk...", "language": "fr", "pciTemplateReferences": [ "PCIT-T7KC6VGL", "PCIT-PKB6DKS4" ] } ``` ## Step 3: Present the questionnaires to your user You need to ask your user to review and sign the questionnaires. When presenting them to your user in your website, you can render the documents using the Adyen Document Viewer. Decode the documents before passing them to the Adyen Document Viewer. ```js const documentViewer = new AdyenDocumentViewer('#test'); const document = JSON.parse(decodeURIComponent(escape(window.atob(pciTemplateReferences.document)))); documentViewer.render(document); ``` ### Tab: npm (Recommended) Install the [Adyen Document Viewer package](https://www.npmjs.com/package/@adyen/adyen-document-viewer): ```bash npm install @adyen/adyen-document-viewer --save ``` Import the Adyen Document Viewer Node package into your application. You can add your own styling by overriding the rules in the CSS file. ```js import AdyenDocumentViewer from '@adyen/adyen-document-viewer'; import '@adyen/adyen-document-viewer/dist/adyen-document-viewer.min.css'; ``` ### Tab: Embed script and stylesheet Include the script and stylesheet to a .html file **HTML** ```html ``` ## Step 4: Sign the questionnaires You must ask your user to declare that they comply with the scheme requirements by signing the generated questionnaires. To sign the questionnaires, send a POST [/legalEntities/{id}/pciQuestionnaires/signPciTemplates](https://docs.adyen.com/api-explorer/legalentity/latest/post/legalEntities/\(id\)/pciQuestionnaires/generatePciTemplates) request, specifying the [id](https://docs.adyen.com/api-explorer/legalentity/latest/post/legalEntities#responses-200-id) of the main legal entity in the path. In the body of the request, specify the following: | Parameter | Required | Description | | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | [signedBy](https://docs.adyen.com/api-explorer/legalentity/latest/post/legalEntities/_id_/pciQuestionnaires/signPciTemplates#request-signedBy) | ![-white\_check\_mark-](/user/data/smileys/emoji/white_check_mark.png "-white_check_mark-") | The legal entity [id](https://docs.adyen.com/api-explorer/legalentity/latest/post/legalEntities#responses-200-id) of the individual who signed the questionnaires. | | [pciTemplateReferences](https://docs.adyen.com/api-explorer/legalentity/latest/post/legalEntities/_id_/pciQuestionnaires/signPciTemplates#request-pciTemplateReferences) | ![-white\_check\_mark-](/user/data/smileys/emoji/white_check_mark.png "-white_check_mark-") | The array of unique identifiers of the questionnaires. | The request submits the legal entity ID of the individual who signed the simplified questionnaires and populates the formal PCI SAQ with the legal entity data. **Sign the questionnaires** #### curl ```bash curl https://kyc-test.adyen.com/lem/v3/legalEntities/LE00000000000000000000001/pciQuestionnaires/signPciTemplates \ -H 'x-api-key: ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY' \ -H 'content-type: application/json' \ -X POST \ -d '{ "signedBy": "LE00000000000000000000002", "pciTemplateReferences": [ "PCIT-T7KC6VGL", "PCIT-PKB6DKS4" ] }' ``` #### Java ```java // Adyen Java API Library v38.0.0 to latest import com.adyen.Client; import com.adyen.Config; import com.adyen.enums.Environment; import com.adyen.model.*; import com.adyen.service.*; import java.math.*; import com.adyen.model.legalentitymanagement.*; import java.time.OffsetDateTime; import java.util.*; import com.adyen.service.legalentitymanagement.*; Config config = new Config() .apiKey("ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY") .environment(Environment.TEST); Client client = new Client(config); // Create the request object(s) PciSigningRequest pciSigningRequest = new PciSigningRequest() .signedBy("LE00000000000000000000002") .pciTemplateReferences(Arrays.asList("PCIT-T7KC6VGL", "PCIT-PKB6DKS4")); // Send the request PciQuestionnairesApi service = new PciQuestionnairesApi(client); PciSigningResponse response = service.signPciQuestionnaire("id", pciSigningRequest, null); ``` #### PHP ```php setXApiKey("ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY"); $client->setEnvironment(Environment::TEST); // Create the request object(s) $pciSigningRequest = new PciSigningRequest(); $pciSigningRequest ->setSignedBy("LE00000000000000000000002") ->setPciTemplateReferences(array("PCIT-T7KC6VGL", "PCIT-PKB6DKS4")); // Send the request $service = new PCIQuestionnairesApi($client); $response = $service->signPciQuestionnaire('id', $pciSigningRequest); ``` #### C\# ```cs // Adyen .NET API Library v34.0.0 to latest using System.Collections.Generic; using Adyen.LegalEntityManagement.Extensions; using Adyen.LegalEntityManagement.Models; using Adyen.LegalEntityManagement.Services; using Adyen.Core.Client; using Adyen.Core.Client.Extensions; using Adyen.Core.Options; using Microsoft.Extensions.DependencyInjection; using Microsoft.Extensions.Hosting; var host = Host.CreateDefaultBuilder() .ConfigureLegalEntityManagement( (context, services, config) => { config.ConfigureAdyenOptions(options => { options.AdyenApiKey = "ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY"; options.Environment = AdyenEnvironment.Test; }); services.AddAllLegalEntityManagementServices(); }) .Build(); var pCIQuestionnairesService = host.Services.GetRequiredService(); // Create the request object(s) var pciSigningRequest = new PciSigningRequest { SignedBy = "LE00000000000000000000002", PciTemplateReferences = new List { "PCIT-T7KC6VGL", "PCIT-PKB6DKS4" } }; // Send the request var result = await pCIQuestionnairesService.SignPciQuestionnaireAsync("id", pciSigningRequest); if (result.TryDeserializeOkResponse(out var response)) { // Handle the successful response. } ``` #### NodeJS (JavaScript) ```js // Adyen Node API Library v30.0.0 to latest const { Client, Config, EnvironmentEnum, LegalEntityManagementAPI } = require('@adyen/api-library'); const config = new Config({ apiKey: "ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY", environment: EnvironmentEnum.TEST }); const client = new Client(config); // Create the request object(s) const pciSigningRequest = { signedBy: "LE00000000000000000000002", pciTemplateReferences: ["PCIT-T7KC6VGL", "PCIT-PKB6DKS4"] }; // Send the request const legalEntityManagementAPI = new LegalEntityManagementAPI(client); const response = await legalEntityManagementAPI.PCIQuestionnairesApi.signPciQuestionnaire("id", pciSigningRequest); ``` #### Go ```go // Adyen Go API Library v21.0.0 to latest import ( "context" "github.com/adyen/adyen-go-api-library/v21/src/common" "github.com/adyen/adyen-go-api-library/v21/src/adyen" "github.com/adyen/adyen-go-api-library/v21/src/legalentity" ) client := adyen.NewClient(&common.Config{ ApiKey: "ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY", Environment: common.TestEnv, }) // Create the request object(s) pciSigningRequest := legalentity.PciSigningRequest{ SignedBy: "LE00000000000000000000002", PciTemplateReferences: []string{ "PCIT-T7KC6VGL", "PCIT-PKB6DKS4", }, } // Send the request service := client.LegalEntity() req := service.PCIQuestionnairesApi.SignPciQuestionnaireInput("id").PciSigningRequest(pciSigningRequest) res, httpRes, err := service.PCIQuestionnairesApi.SignPciQuestionnaire(context.Background(), req) ``` #### Python ```py # Adyen Python API Library v14.0.0 to latest import Adyen adyen = Adyen.Adyen() adyen.client.xapikey = "ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY" adyen.client.platform = "test" # The environment to use library in. # Create the request object(s) json_request = { "signedBy": "LE00000000000000000000002", "pciTemplateReferences": ["PCIT-T7KC6VGL", "PCIT-PKB6DKS4"] } # Send the request result = adyen.legalEntityManagement.pci_questionnaires_api.sign_pci_questionnaire(request=json_request, id="id") ``` #### Ruby ```rb # Adyen Ruby API Library v11.0.0 to latest require "adyen-ruby-api-library" adyen = Adyen::Client.new adyen.api_key = 'ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY' adyen.env = :test # Set to "live" for live environment # Create the request object(s) request_body = { "signedBy" => "LE00000000000000000000002", "pciTemplateReferences" => ["PCIT-T7KC6VGL", "PCIT-PKB6DKS4"] } # Send the request result = adyen.legal_entity_management.pci_questionnaires_api.sign_pci_questionnaire(request_body, 'id') ``` #### NodeJS (TypeScript) ```ts // Adyen Node API Library v30.0.0 to latest import { Client, Config, EnvironmentEnum, LegalEntityManagementAPI, Types } from "@adyen/api-library"; const config = new Config({ apiKey: "ADYEN_LEGAL_ENTITY_MANAGEMENT_API_KEY", environment: EnvironmentEnum.TEST }); const client = new Client(config); // Create the request object(s) const pciSigningRequest: Types.legalEntityManagement.PciSigningRequest = { signedBy: "LE00000000000000000000002", pciTemplateReferences: ["PCIT-T7KC6VGL", "PCIT-PKB6DKS4"] }; // Send the request const legalEntityManagementAPI = new LegalEntityManagementAPI(client); const response = await legalEntityManagementAPI.PCIQuestionnairesApi.signPciQuestionnaire("id", pciSigningRequest); ``` The response returns an array of the unique identifiers of the signed SAQ documents. **List of signed questionnaires** ```json { "pciQuestionnaireIds": [ "PCID422GZ22322565HHMH48CW63CPH", "PCID422GZ22322565HHMH49CW75Z9H" ], "signedBy": "LE00000000000000000000002" } ``` ## Step 5: Get a list of signed SAQs To retrieve a list of the documents signed by your user, send a GET [/legalEntities/{id}/pciQuestionnaires](https://docs.adyen.com/api-explorer/legalentity/latest/get/legalEntities/\(id\)/pciQuestionnaires) request, specifying the [id](https://docs.adyen.com/api-explorer/legalentity/latest/post/legalEntities#responses-200-id) of the main legal entity in the path. **Get a list of SAQs** ```json { "data": [ { "createdAt": "2023-03-02T17:54:19.538365Z", "id": "PCID422GZ22322565HHMH48CW63CPH", "validUntil": "2024-03-01T17:54:19.538365Z" }, { "createdAt": "2023-03-02T17:54:19.538365Z", "id": "PCID422GZ22322565HHMH49CW75Z9H", "validUntil": "2024-03-01T17:54:19.538365Z" } ] } ``` ## Step 6: Download a signed questionnaire To download a signed SAQ, send a GET [/legalEntities/{id}/pciQuestionnaires/{pciid}](https://docs.adyen.com/api-explorer/legalentity/latest/get/legalEntities/\(id\)/pciQuestionnaires/\(pciid\)) request, specifying the following parameters in the path: | Path parameter | Required | Description | | --------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------- | ---------------------------------------- | | [id](https://docs.adyen.com/api-explorer/legalentity/latest/post/legalEntities#responses-200-id) | ![-white\_check\_mark-](/user/data/smileys/emoji/white_check_mark.png "-white_check_mark-") | The legal entity ID of the organization. | | [pciid](https://docs.adyen.com/api-explorer/legalentity/latest/get/legalEntities/_id_/pciQuestionnaires/_pciid_#path-pciid) | ![-white\_check\_mark-](/user/data/smileys/emoji/white_check_mark.png "-white_check_mark-") | The ID of the signed questionnaire. | The response returns the base64 encoded form of the signed document in PDF format in the [content](https://docs.adyen.com/api-explorer/legalentity/latest/get/legalEntities/_id_/pciQuestionnaires/_pciid_#responses-200-content) field. To present the document to your user, use the [Base64.Decoder](https://base64.guru/developers/java/examples/decode-pdf) class. **Signed questionnaire** ```json { "content":"JVBERi0xLjUKJdDUxdgKMTAg.....", "createdAt":"2023-03-02T17:54:19.538365Z", "id":"PCID422GZ22322565HHMH48CW63CPH", "validUntil":"2024-03-01T17:54:19.538365Z" } ``` ## Next steps [required](https://docs.adyen.com/managed-model/onboard-users/api/terms-of-service) [Terms of Service](https://docs.adyen.com/managed-model/onboard-users/api/terms-of-service) [Ask your users to accept Adyen's Terms of Service.](https://docs.adyen.com/managed-model/onboard-users/api/terms-of-service)