E-commerce11 min read

PCI Compliance for SME Online Payments in Lagos in 2026

Mohamed Bah·Fondateur, Kolonell
August 22, 2026
Share:
PCI Compliance for SME Online Payments in Lagos in 2026

PCI Compliance for SME Online Payments in Lagos in 2026

E-commerce

The verdict in three sentences

A Lagos SME that touches card numbers falls under PCI DSS: the only sensible decision is to delegate compliance to a hosted gateway (Flutterwave, Paystack), placing you in SAQ-A with near-zero compliance cost. Conversely, storing cards yourself requires SAQ-D and an annual audit of 5-15 million FCFA, out of reach for an SME. Mobile money escapes PCI but remains subject to GDPR, local data law (NDPR in Nigeria, Benin's 2009-09 law) and CBN rules.

SAQ-A or SAQ-D: the structuring decision

PCI scope hinges on one question: do card details pass through or get stored on your servers? If not, your compliance burden collapses.

CriterionSAQ-A (hosted gateway)SAQ-D (in-house storage)
Card data on your serversNo (tokenization)Yes
Self-assessment questionnaire~22 questions300+ questions
External audit (QSA)Not requiredRequired
Annual compliance cost~0-500,000 FCFA5-15M FCFA
Liability on a breachReducedMaximum
Suitable for an SMEYesNo

Gateway tokenization is the default: the customer enters their card on a form hosted by Flutterwave or Paystack, and you only receive a token. You exit the heavy PCI scope while collecting normally.

Mobile money, GDPR and local law: the 2026 checklist

Mobile money involves no card, so no PCI — but you collect personal data (number, name, history). Here is the minimum compliance checklist.

MeasureGoalPriority
TLS 1.2+ / HTTPS everywhereProtect data in transitCritical
CSP + HSTS headersBlock injection and downgradeHigh
Encryption of data at restProtect the databaseHigh
Transaction loggingTraceability, disputesHigh
GDPR notices + consentLegal complianceCritical
Data processing registerLocal law (NDPR, Benin law)Medium
Retention/deletion policyData minimizationMedium

These measures are achievable for an SME without an audit budget: they're good engineering practice and clear documentation, not a costly certification.

Mini case study

Fatou is launching an online cosmetics store in Lagos and wanted to "store cards to ease repeat purchases." An SAQ-D audit quote came to about 7 million FCFA/year — impossible. By using Paystack tokenization (SAQ-A) and mobile money (outside PCI), her compliance burden dropped to implementing CSP headers, HTTPS, GDPR notices and a processing register: a 600,000 FCFA one-off effort versus 7M/year. One-click repeat purchases remain possible via the token stored at the gateway, without ever touching a card number.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

FAQ

Does my SME need PCI DSS certification?

If you use a hosted gateway that tokenizes cards, you fall under SAQ-A: a simplified self-assessment of about twenty questions, no external audit. You don't bear the cost of heavy certification.

Is mobile money covered by PCI DSS?

No, PCI DSS only covers payment cards. Mobile money remains subject to GDPR and local data laws (NDPR in Nigeria, Benin's 2009-09 law), which require consent, security and traceability.

How much does an SAQ-D audit cost?

Between 5 and 15 million FCFA per year depending on size, QSA auditor and scope. That's why no SME should store card numbers itself: tokenization avoids this cost.

Which security headers should I prioritize?

HTTPS/TLS 1.2+ everywhere, Content-Security-Policy, HSTS, X-Content-Type-Options and Referrer-Policy. These headers block the most common attacks and configure at no significant extra cost.

Does GDPR apply to a Nigerian store?

Yes if you target or process data of EU residents (diaspora included), and Nigeria's NDPR applies in all cases. Plan for consent, a processing register and a retention policy.

Let's talk about your project. We secure your payments via tokenization and bring your site into GDPR and local-law compliance without a costly audit. WhatsApp +221 77 596 93 33.

Tags:#PCI DSS#compliance#payment security#Lagos#Cotonou#SME#tokenization#GDPR
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.