Websites11 min read

PCI-DSS compliance for cards in Lagos 2026

Mohamed Bah·Fondateur, Kolonell
August 27, 2026
Share:
PCI-DSS compliance for cards in Lagos 2026

PCI-DSS compliance for cards in Lagos 2026

Websites

The verdict in three sentences

The moment your site accepts a bank card, you enter the PCI-DSS scope, the global standard for card data security. The good news: if you never touch the card number (PAN) and let an aggregator collect it through a hosted field, your compliance is limited to the SAQ-A questionnaire — free and light. Storing cards yourself pushes you into SAQ-D, with an annual audit topping 5,000,000 FCFA — a cost and a risk that 99 % of merchants must avoid.

SAQ levels and their real 2026 cost

The self-assessment questionnaire (SAQ) type depends on how card data flows through your system. Here are the 2026 orders of magnitude.

SAQ levelWho it applies toEstimated annual costBurden
SAQ-AHosted field / aggregator redirect0 FCFAVery low
SAQ-A-EPPayment script embedded in site300,000 to 800,000 FCFALow
SAQ-D merchantStoring / processing the PAN5,000,000 FCFA and upVery heavy

The 2026 golden rule: stay in SAQ-A. An aggregator (Paystack, Flutterwave, Stripe) renders the card field from ITS servers; the number never crosses yours, so there is nothing to audit on that scope.

PAN, tokenization and burden transfer

The PAN (Primary Account Number) is the 16-digit number. Never storing it in the clear is the baseline. Tokenization replaces that number with a token useless outside your aggregator.

ElementNever storeWhat you may keep
Card number (PAN)Forbidden in the clearAggregator token
CVV / security codeForbidden after authorizationNothing
Expiry dateAvoidHandled by aggregator
Cardholder nameLimitOrder reference
TokenYes, safe and reusable

By delegating to an aggregator you transfer the compliance burden: it holds PCI-DSS Level 1 certification and absorbs the heavy audit. You keep only the token, which enables one-click payment without ever exposing the card.

Mini case study

Parfait runs a SaaS platform in Lagos that bills 2,500 customers by card. Tempted to store cards to "go faster," he would have shifted to SAQ-D: a 5,000,000 FCFA/year audit plus a 2,000,000 FCFA pentest, or 7,000,000 FCFA in annual compliance cost. By choosing tokenization through his aggregator, he stays in SAQ-A at 0 FCFA and removes the data-breach risk entirely. Direct saving: 7,000,000 FCFA a year, plus legal peace of mind.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

FAQ

Must I be PCI-DSS compliant if I accept cards?

Yes, without exception, from the first card transaction. But with a hosted field your compliance reduces to SAQ-A: a one-page questionnaire, no paid audit.

How much does an SAQ-D audit cost in 2026?

The order of magnitude is 5,000,000 FCFA and up per year, before penetration tests. That is why almost no merchant should store cards themselves.

Is tokenization really safe?

Yes: the token is useless outside your aggregator account. Even if stolen, it cannot charge anything elsewhere, unlike a plaintext card number.

Can I store the CVV for recurring payments?

No, never. The CVV must be destroyed after authorization. Recurring payments use the token, not the security code.

Who is liable in a breach?

In SAQ-A the aggregator carries the PCI burden for card processing. If you store cards yourself, liability and penalties fall on you, with fines that can reach tens of millions of FCFA.

Let's talk about your project. We wire your card payments in SAQ-A with tokenization, never exposing the PAN. WhatsApp +221 77 596 93 33.

Tags:#pci-dss#cards#compliance#security#tokenization#2026
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.