If the application demands your prospects to enter their information on their particular devices, Then you really qualify for SAQ A. Formally attest your compliance. An AOC (attestation of compliance) is the shape you use to sign which you’ve accomplished PCI DSS compliance. Ending your questionnaire with no “Completely wrong” https://www.nathanlabsadvisory.com/blog/tag/security-culture/