Websites11 min read

PCI-DSS compliance for online card payments in South Africa (2026)

Mohamed Bah·Fondateur, Kolonell
August 13, 2026
Share:
PCI-DSS compliance for online card payments in South Africa (2026)

PCI-DSS compliance for online card payments in South Africa (2026)

Websites

The verdict in three sentences

The moment you accept card payments, PCI-DSS applies — even to a small online store. The good news: delegating collection to a PSP (redirect or hosted field, SAQ-A level) avoids 90 % of the compliance burden and spares you from ever handling card data. Conversely, storing card numbers pushes you toward a costly QSA audit and heavy fine risk.

The SAQ compliance levels

PCI-DSS does not demand the same effort from everyone: the self-assessment questionnaire (SAQ) depends on how you handle the card.

SAQ level (2026 order of magnitude)Who is affectedCompliance burdenQSA audit required
SAQ-ACollection 100 % delegated to PSPMinimalNo
SAQ-A-EPHosted page but site shapes the flowModerateNo (by volume)
SAQ-D merchantSite touches/stores card dataHeavyOften yes
Level 1 (high volume)>6 M transactions/yearMaximalYes, annual
PSP tokenizationCard replaced by a tokenReducedNo

The golden rule for an SME: stay at SAQ-A by never touching card data. Everything else gets exponentially more expensive.

Costs, timelines and risks

The real trade-off is financial: delegated compliance costs almost nothing, while internalizing runs into the millions.

Item (2026 estimate)Value
QSA audit cost (high volume)3 - 10 M FCFA
Non-compliance fineup to 100,000 USD
Certification timeline4 - 12 weeks
TokenizationMandatory if storing
Card vs mobile money share (South Africa)55 / 45
Compliance cost at SAQ-AClose to 0

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

In South Africa, where cards still make up ~55 % of online payments, ignoring PCI-DSS is not an option; but architecting well lets you carry its minimal weight.

Mini case study

Thandi launches a fashion marketplace in Johannesburg and hesitates to store cards "to smooth repeat payments." That choice would push her to SAQ-D, with a QSA audit estimated at 6 M FCFA the first year, plus maintenance. Opting for tokenization via her PSP (SAQ-A), she keeps one-tap repeat payment without ever touching card data: near-zero compliance cost, go-live cut from 12 to 4 weeks. Direct saving: 6 M FCFA and weeks of delay avoided.

FAQ

Is a small store really subject to PCI-DSS? Yes, from the first card payment. But by delegating everything to the PSP (SAQ-A), the real burden becomes minimal: you fill a short annual questionnaire, with no heavy audit.

What is the risk of non-compliance? Fines reaching up to 100,000 USD depending on card schemes, plus liability in case of a data breach. It is never worth it against the near-zero cost of delegated compliance.

How much does a QSA audit cost? For high volumes at SAQ-D or level 1, count 3 to 10 M FCFA in 2026, plus technical remediation. That is exactly what PSP delegation lets you avoid.

Is tokenization enough? It is mandatory as soon as you want repeat payment without re-entry, and done well it keeps you at SAQ-A. The token replaces the card number, which you then never store in clear.

Let's talk about your project. We architect your card collection to stay at SAQ-A and avoid any heavy audit. WhatsApp +221 77 596 93 33.

Tags:#pci dss#conformite paiement#securite#carte bancaire#afrique du sud#psp#tokenisation#ecommerce
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.