The verdict in three sentences
If you never store, process or transmit a card number in clear — because a PSP like Paystack, Flutterwave or Stripe does it for you — you fall under SAQ-A, the lightest level, free and self-assessed. That avoids over 90 % of PCI-DSS costs, including a full audit at NGN 5 to 15 million. Card compliance is only a nightmare for those who store cards: don't.
The SAQ levels: find yours
PCI-DSS is not one single standard: it's a scale. Your effort depends on how cards flow through you. The founding principle: the less you touch the card, the fewer obligations you have.
| Store type | Questionnaire (SAQ) | Compliance cost | Timeline |
|---|---|---|---|
| Full redirect to PSP | SAQ-A | Free (self-assessed) | 2 to 4 weeks |
| PSP-hosted iframe card field | SAQ-A | Free (self-assessed) | 2 to 4 weeks |
| Card field on your page (direct JS) | SAQ-A-EP | Low to medium | 1 to 2 months |
| Card processing on your servers | SAQ-D | NGN 5-15M (QSA audit) | 3 to 6 months |
| Card storage | SAQ-D + tokenization | NGN 10-15M+ | 4 to 8 months |
The lesson is clear: stay in SAQ-A. In practice, that means the card form is served by the PSP (redirect or hosted iframe) and the card never touches your code or servers.
What is actually required (and what isn't)
Many merchants pay for useless things or neglect the essentials. Here is the real 2026 breakdown for a Nigerian or Ghanaian store in SAQ-A.
| Obligation | SAQ-A (delegated) | SAQ-D (you store) |
|---|---|---|
| HTTPS/TLS across the whole site | Yes | Yes |
| Card form off your servers | Yes | No |
| Tokenization to store a card | Not applicable | Mandatory |
| Annual audit by a QSA | No | Yes (NGN 5-15M) |
| Quarterly ASV scan | No | Yes |
| Written security policy | Recommended | Mandatory |
| Encryption of data at rest | Not applicable | Mandatory |
| Total year-1 cost | near zero | NGN 5 to 15M |
Bottom line: if you store even a tokenized card with a trusted third party, tokenization becomes mandatory and you must never keep the full number (PAN) in clear. For mobile money (Opay, M-Pesa, MoMo), PCI-DSS does not apply — those aren't cards — but sound webhook security still matters.
Mini case study
Emeka launches a fashion store in Lagos. A vendor offers him a "full PCI compliance pack" for NGN 6,500,000. In reality, his store redirects all card payments to Paystack: he therefore falls under SAQ-A, free. He saves NGN 6,500,000 at once.
His only real cost: a TLS certificate (often bundled with hosting) and 2 to 4 weeks to fill the self-assessment. Result: 100 % compliant, NGN 0 audit, and the saved budget goes into ads to launch his collection.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
Does my store really need PCI-DSS certification?
If you accept cards, yes, but at your matching level. By delegating to a PSP (SAQ-A), "certification" is a free self-assessment questionnaire. Only those who process or store cards themselves face the NGN 5-15M audit.
Is mobile money covered by PCI-DSS?
No. Opay, M-Pesa and peers aren't card payments, so they are out of PCI-DSS scope. That said, webhook security and server verification remain essential to prevent fraud.
Can I store my customers' cards for recurring payments?
Not directly. You must use the PSP's tokenization: it keeps the card, you keep only a harmless token. Storing a clear PAN would push you into SAQ-D with a mandatory audit.
How long to become SAQ-A compliant?
Between 2 and 4 weeks: verify HTTPS everywhere, confirm the card form is PSP-served, and fill the questionnaire. No paid external audit is required.
What does a non-compliant store risk?
Variable fines from the card networks, merchant account suspension, and full liability in a card breach. The most concrete risk is PSP termination, which cuts your payments overnight.
Let's talk about your project. We architect your store to stay in SAQ-A and avoid every needless PCI cost. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
