Websites11 min read

PCI DSS Compliance & Card Tokenization: Storing Cards Safely (2026)

Mohamed Bah·Fondateur, Kolonell
August 24, 2026
Share:
PCI DSS Compliance & Card Tokenization: Storing Cards Safely (2026)

PCI DSS Compliance & Card Tokenization: Storing Cards Safely (2026)

Websites

The verdict in three sentences

Storing a card number puts you on the hook for the PCI DSS standard and its 12 requirements, with costly audits and heavy penalties in the event of a leak. Tokenization — replacing the number with a token that is useless anywhere else, managed by your payment provider — moves that burden off your servers. In practice, it takes you from a full audit (SAQ-D or a ROC at 15-30 million FCFA) to a simple, free SAQ-A.

Why tokenization changes everything

Without tokenization, card data touches your code, your logs, your database: you enter the most demanding PCI scope. With tokenization, the card form is hosted by Paystack, Flutterwave or Stripe (via an iframe or SDK), the number never touches your servers, and you only handle a token that is worthless to an attacker. That token then powers recurring payments (subscriptions, one-click buying) without ever re-storing the card.

ApproachPCI scopeWho sees the numberCompliance cost / yearBreach risk
Direct storage in DBSAQ-D / ROCYou15,000,000 - 30,000,000 FCFAMaximal
Redirect to PSPSAQ-AThe PSP0 FCFAMinimal
Iframe / tokenized fieldSAQ-A / A-EPThe PSP0 FCFAVery low
Token for recurringSAQ-AThe PSP0 FCFAVery low

The lesson: the best card data is the data you never store.

SAQ levels and their obligations

The self-assessment questionnaire (SAQ) depends on how you collect payment. The closer the card gets to your servers, the heavier the questionnaire.

LevelUse caseNumber of questions (2026 order)External audit required
SAQ-A100% outsourced payment (redirect / iframe)~22No
SAQ-A-EPMerchant page loading the PSP script~140No (recommended)
SAQ-D merchantYou touch or store the card~330Often yes
ROC (level 1)> 6M transactions/yearFull QSA reportYes, mandatory

For 95% of African e-commerce merchants, the goal is to stay at SAQ-A by fully outsourcing card entry.

Penalties in case of a leak

A card data leak triggers network fines (Visa, Mastercard), the cost of card re-issuance, forensic audits and reputational damage. Amounts vary, but a 2026 order of magnitude: from several million to several tens of millions of FCFA for an SME, not counting the possible suspension of your ability to accept cards.

Mini case study

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Ibrahim launches a subscription platform in Lagos with monthly recurring payments. Tempted to store the cards himself to "stay in control," he discovers the cost: a ROC audit estimated at 20,000,000 FCFA in year one, plus the technical compliance work. He switches to Flutterwave tokenization: cards never touch his server, he keeps only tokens for the monthly charges, and his scope drops to free SAQ-A. First-year saving: about 20,000,000 FCFA, with near-zero breach risk.

FAQ

Am I covered by PCI DSS if I only accept mobile money?

PCI DSS targets bank card data. If you only accept Wave and Orange Money, you are outside the card scope, but you still have general security duties (signed webhooks, protected customer data).

Does tokenization support subscriptions?

Yes, that's its flagship use: the token represents the card for recurring charges without ever re-entering or re-storing the number. Paystack, Flutterwave and Stripe all offer this.

Is SAQ-A really free?

The questionnaire itself is free to complete each year. The "cost" is keeping the architecture clean (no contact with the number). That is incomparable to a ROC billed at 15 to 30 million FCFA.

Can I store the last 4 digits of the card?

Yes: the last 4 digits, the brand and the expiry date can be kept for display ("card ending in 4242"). That is not the full number (PAN), so it's outside the sensitive scope.

How much does a tokenized integration cost?

A 2026 order of magnitude: 400,000 to 900,000 FCFA to cleanly integrate a PSP SDK with token and recurring management, versus tens of millions to run compliant in-house storage.

Let's talk about your project. We integrate Paystack, Flutterwave or Stripe tokenization to keep you in SAQ-A and eliminate card-storage risk. WhatsApp +221 77 596 93 33.

Tags:#pci dss#tokenization#card#compliance#security#stripe
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.