The verdict in three sentences
The moment you accept card payments, PCI-DSS applies — even to a small online store. The good news: delegating collection to a PSP (redirect or hosted field, SAQ-A level) avoids 90 % of the compliance burden and spares you from ever handling card data. Conversely, storing card numbers pushes you toward a costly QSA audit and heavy fine risk.
The SAQ compliance levels
PCI-DSS does not demand the same effort from everyone: the self-assessment questionnaire (SAQ) depends on how you handle the card.
| SAQ level (2026 order of magnitude) | Who is affected | Compliance burden | QSA audit required |
|---|---|---|---|
| SAQ-A | Collection 100 % delegated to PSP | Minimal | No |
| SAQ-A-EP | Hosted page but site shapes the flow | Moderate | No (by volume) |
| SAQ-D merchant | Site touches/stores card data | Heavy | Often yes |
| Level 1 (high volume) | >6 M transactions/year | Maximal | Yes, annual |
| PSP tokenization | Card replaced by a token | Reduced | No |
The golden rule for an SME: stay at SAQ-A by never touching card data. Everything else gets exponentially more expensive.
Costs, timelines and risks
The real trade-off is financial: delegated compliance costs almost nothing, while internalizing runs into the millions.
| Item (2026 estimate) | Value |
|---|---|
| QSA audit cost (high volume) | 3 - 10 M FCFA |
| Non-compliance fine | up to 100,000 USD |
| Certification timeline | 4 - 12 weeks |
| Tokenization | Mandatory if storing |
| Card vs mobile money share (South Africa) | 55 / 45 |
| Compliance cost at SAQ-A | Close to 0 |
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
In South Africa, where cards still make up ~55 % of online payments, ignoring PCI-DSS is not an option; but architecting well lets you carry its minimal weight.
Mini case study
Thandi launches a fashion marketplace in Johannesburg and hesitates to store cards "to smooth repeat payments." That choice would push her to SAQ-D, with a QSA audit estimated at 6 M FCFA the first year, plus maintenance. Opting for tokenization via her PSP (SAQ-A), she keeps one-tap repeat payment without ever touching card data: near-zero compliance cost, go-live cut from 12 to 4 weeks. Direct saving: 6 M FCFA and weeks of delay avoided.
FAQ
Is a small store really subject to PCI-DSS? Yes, from the first card payment. But by delegating everything to the PSP (SAQ-A), the real burden becomes minimal: you fill a short annual questionnaire, with no heavy audit.
What is the risk of non-compliance? Fines reaching up to 100,000 USD depending on card schemes, plus liability in case of a data breach. It is never worth it against the near-zero cost of delegated compliance.
How much does a QSA audit cost? For high volumes at SAQ-D or level 1, count 3 to 10 M FCFA in 2026, plus technical remediation. That is exactly what PSP delegation lets you avoid.
Is tokenization enough? It is mandatory as soon as you want repeat payment without re-entry, and done well it keeps you at SAQ-A. The token replaces the card number, which you then never store in clear.
Let's talk about your project. We architect your card collection to stay at SAQ-A and avoid any heavy audit. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.

