The verdict in three sentences
The moment your site accepts a bank card, you enter the PCI-DSS scope, the global standard for card data security. The good news: if you never touch the card number (PAN) and let an aggregator collect it through a hosted field, your compliance is limited to the SAQ-A questionnaire — free and light. Storing cards yourself pushes you into SAQ-D, with an annual audit topping 5,000,000 FCFA — a cost and a risk that 99 % of merchants must avoid.
SAQ levels and their real 2026 cost
The self-assessment questionnaire (SAQ) type depends on how card data flows through your system. Here are the 2026 orders of magnitude.
| SAQ level | Who it applies to | Estimated annual cost | Burden |
|---|---|---|---|
| SAQ-A | Hosted field / aggregator redirect | 0 FCFA | Very low |
| SAQ-A-EP | Payment script embedded in site | 300,000 to 800,000 FCFA | Low |
| SAQ-D merchant | Storing / processing the PAN | 5,000,000 FCFA and up | Very heavy |
The 2026 golden rule: stay in SAQ-A. An aggregator (Paystack, Flutterwave, Stripe) renders the card field from ITS servers; the number never crosses yours, so there is nothing to audit on that scope.
PAN, tokenization and burden transfer
The PAN (Primary Account Number) is the 16-digit number. Never storing it in the clear is the baseline. Tokenization replaces that number with a token useless outside your aggregator.
| Element | Never store | What you may keep |
|---|---|---|
| Card number (PAN) | Forbidden in the clear | Aggregator token |
| CVV / security code | Forbidden after authorization | Nothing |
| Expiry date | Avoid | Handled by aggregator |
| Cardholder name | Limit | Order reference |
| Token | — | Yes, safe and reusable |
By delegating to an aggregator you transfer the compliance burden: it holds PCI-DSS Level 1 certification and absorbs the heavy audit. You keep only the token, which enables one-click payment without ever exposing the card.
Mini case study
Parfait runs a SaaS platform in Lagos that bills 2,500 customers by card. Tempted to store cards to "go faster," he would have shifted to SAQ-D: a 5,000,000 FCFA/year audit plus a 2,000,000 FCFA pentest, or 7,000,000 FCFA in annual compliance cost. By choosing tokenization through his aggregator, he stays in SAQ-A at 0 FCFA and removes the data-breach risk entirely. Direct saving: 7,000,000 FCFA a year, plus legal peace of mind.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
Must I be PCI-DSS compliant if I accept cards?
Yes, without exception, from the first card transaction. But with a hosted field your compliance reduces to SAQ-A: a one-page questionnaire, no paid audit.
How much does an SAQ-D audit cost in 2026?
The order of magnitude is 5,000,000 FCFA and up per year, before penetration tests. That is why almost no merchant should store cards themselves.
Is tokenization really safe?
Yes: the token is useless outside your aggregator account. Even if stolen, it cannot charge anything elsewhere, unlike a plaintext card number.
Can I store the CVV for recurring payments?
No, never. The CVV must be destroyed after authorization. Recurring payments use the token, not the security code.
Who is liable in a breach?
In SAQ-A the aggregator carries the PCI burden for card processing. If you store cards yourself, liability and penalties fall on you, with fines that can reach tens of millions of FCFA.
Let's talk about your project. We wire your card payments in SAQ-A with tokenization, never exposing the PAN. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.

