Digital Africa11 min read

PCI DSS for mobile money: what an SME actually has to implement

Mohamed Bah·Fondateur, Kolonell
August 14, 2026
Share:
PCI DSS for mobile money: what an SME actually has to implement

PCI DSS for mobile money: what an SME actually has to implement

Digital Africa

The verdict in three sentences

Most SMEs do not need the heaviest PCI DSS compliance: a hosted checkout (redirect to the operator or PSP) cuts your scope by roughly 80%. You then move from the SAQ-D questionnaire (hundreds of controls) to the SAQ-A (a handful), never storing card data. The key is to never touch sensitive data: tokenization and redirection do the work for you.

SAQ-A vs SAQ-D: the choice that changes everything

Your questionnaire level depends on how you collect. Touching card data pushes you into the heavy scope. 2026 order of magnitude.

CriterionSAQ-A (hosted)SAQ-D (direct API)
You touch card dataNoYes
Number of controls~22~300+
Scope reduction~80%None
Annual audit cost1.5M FCFA3 to 4M FCFA
Compliance effortLowHigh
Recommended for SMEYesRarely

*2026 estimate; audit costs vary by QSA and transaction volume.*

The 12 requirement groups and local data

PCI DSS is organised into 12 requirement groups. In mobile money via hosted checkout, most are covered by your PSP, but a few remain your responsibility, notably data residency under Senegal's 2008-12 personal data law.

Requirement groupWho bears it (hosted)Watch point
Firewall and networkPSPCheck the contract
No default passwordsYouAdmin accounts
Protect stored dataPSP (vault)Store nothing yourself
Encryption in transitPSP + youHTTPS/TLS mandatory
Antivirus / patchingYouKeep servers updated
Access controlYouSeparate roles
Logging and testingSharedAudit trail

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Mini case study

Khadija launches an online cosmetics shop in Dakar. Her developer wanted to integrate the card API directly, which would have placed her in SAQ-D with an annual audit around 3.5M FCFA and hundreds of controls. By choosing a hosted checkout with tokenization (the customer enters data at the PSP, never on her site), she moves to SAQ-A: audit brought down to 1.5M FCFA, scope cut by 80%, and zero card data stored locally — compliant with the 2008-12 law at no extra infrastructure cost.

FAQ

Is a mobile money SME concerned by PCI DSS? Yes as soon as it accepts cards alongside wallets. But with a hosted checkout, scope drops by about 80% and the questionnaire becomes SAQ-A, easily manageable.

What is the difference between SAQ-A and SAQ-D? SAQ-A (~22 controls) applies when you never touch card data. SAQ-D (300+ controls) applies as soon as your servers process or store it. Stay on SAQ-A.

What is tokenization? Replacing sensitive data with an unusable token stored in a vault at the PSP. You handle the token, never the real number, which removes the data from your scope.

How much does a PCI DSS audit cost? 2026 order of magnitude: 1.5M FCFA in SAQ-A, 3 to 4M FCFA in SAQ-D. The gap alone justifies choosing the hosted checkout.

Does the 2008-12 law change anything? Yes, it governs the residency and processing of personal data in Senegal. By storing no sensitive data locally (everything sits at the PSP), you greatly simplify local compliance.

Let's talk about your project. We can design your hosted checkout with tokenization to stay in SAQ-A and compliant with the 2008-12 law. WhatsApp +221 77 596 93 33.

Tags:#PCI DSS#conformite#securite#mobile money#PME#SAQ#tokenisation#audit
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.