Websites11 min read

PCI-DSS compliance for an African online store: what's actually required (2026)

Mohamed Bah·Fondateur, Kolonell
August 25, 2026
Share:
PCI-DSS compliance for an African online store: what's actually required (2026)

PCI-DSS compliance for an African online store: what's actually required (2026)

Websites

The verdict in three sentences

If you never store, process or transmit a card number in clear — because a PSP like Paystack, Flutterwave or Stripe does it for you — you fall under SAQ-A, the lightest level, free and self-assessed. That avoids over 90 % of PCI-DSS costs, including a full audit at NGN 5 to 15 million. Card compliance is only a nightmare for those who store cards: don't.

The SAQ levels: find yours

PCI-DSS is not one single standard: it's a scale. Your effort depends on how cards flow through you. The founding principle: the less you touch the card, the fewer obligations you have.

Store typeQuestionnaire (SAQ)Compliance costTimeline
Full redirect to PSPSAQ-AFree (self-assessed)2 to 4 weeks
PSP-hosted iframe card fieldSAQ-AFree (self-assessed)2 to 4 weeks
Card field on your page (direct JS)SAQ-A-EPLow to medium1 to 2 months
Card processing on your serversSAQ-DNGN 5-15M (QSA audit)3 to 6 months
Card storageSAQ-D + tokenizationNGN 10-15M+4 to 8 months

The lesson is clear: stay in SAQ-A. In practice, that means the card form is served by the PSP (redirect or hosted iframe) and the card never touches your code or servers.

What is actually required (and what isn't)

Many merchants pay for useless things or neglect the essentials. Here is the real 2026 breakdown for a Nigerian or Ghanaian store in SAQ-A.

ObligationSAQ-A (delegated)SAQ-D (you store)
HTTPS/TLS across the whole siteYesYes
Card form off your serversYesNo
Tokenization to store a cardNot applicableMandatory
Annual audit by a QSANoYes (NGN 5-15M)
Quarterly ASV scanNoYes
Written security policyRecommendedMandatory
Encryption of data at restNot applicableMandatory
Total year-1 costnear zeroNGN 5 to 15M

Bottom line: if you store even a tokenized card with a trusted third party, tokenization becomes mandatory and you must never keep the full number (PAN) in clear. For mobile money (Opay, M-Pesa, MoMo), PCI-DSS does not apply — those aren't cards — but sound webhook security still matters.

Mini case study

Emeka launches a fashion store in Lagos. A vendor offers him a "full PCI compliance pack" for NGN 6,500,000. In reality, his store redirects all card payments to Paystack: he therefore falls under SAQ-A, free. He saves NGN 6,500,000 at once.

His only real cost: a TLS certificate (often bundled with hosting) and 2 to 4 weeks to fill the self-assessment. Result: 100 % compliant, NGN 0 audit, and the saved budget goes into ads to launch his collection.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

FAQ

Does my store really need PCI-DSS certification?

If you accept cards, yes, but at your matching level. By delegating to a PSP (SAQ-A), "certification" is a free self-assessment questionnaire. Only those who process or store cards themselves face the NGN 5-15M audit.

Is mobile money covered by PCI-DSS?

No. Opay, M-Pesa and peers aren't card payments, so they are out of PCI-DSS scope. That said, webhook security and server verification remain essential to prevent fraud.

Can I store my customers' cards for recurring payments?

Not directly. You must use the PSP's tokenization: it keeps the card, you keep only a harmless token. Storing a clear PAN would push you into SAQ-D with a mandatory audit.

How long to become SAQ-A compliant?

Between 2 and 4 weeks: verify HTTPS everywhere, confirm the card form is PSP-served, and fill the questionnaire. No paid external audit is required.

What does a non-compliant store risk?

Variable fines from the card networks, merchant account suspension, and full liability in a card breach. The most concrete risk is PSP termination, which cuts your payments overnight.

Let's talk about your project. We architect your store to stay in SAQ-A and avoid every needless PCI cost. WhatsApp +221 77 596 93 33.

Tags:#pci-dss#compliance#payment security#bank card#africa#psp#online store#regulation
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.