Easiest path
SAQ A: fully outsourced
Around 24 requirements under v4.0.1, the lowest count of any SAQ. For merchants who use a hosted payment page (Stripe Checkout, PayPal, Shopify Payments) where customers are redirected entirely off your domain. Card data never enters your servers, and the controls you are not answering are the ones that would have applied to it.
The condition to check: since v4.0.1, SAQ A eligibility asks you to confirm your site is not susceptible to attacks from scripts that could affect your e-commerce systems. PCI SSC FAQ #1588 gives two ways to satisfy it: protect the page yourself using the techniques in Requirements 6.4.3 and 11.6.1, or get confirmation from your provider that its solution carries those protections when implemented to its instructions. Get that confirmation in writing.