The verdict in three sentences
Accepting cards without ever storing the number (PAN) spares you the heavy tier of PCI-DSS: everything hinges on the integration choice. In Johannesburg in 2026, a hosted or tokenized checkout (aggregator redirect, iframe) drops the merchant to SAQ A, the lightest, versus a costly, demanding SAQ D if you capture cards yourself. The golden rule: never touch card data, let the aggregator carry it.
SAQ levels and compliance burden
The applicable SAQ (Self-Assessment Questionnaire) depends on how card data flows through you. The less you see it, the shorter the questionnaire.
| Integration type | Applicable SAQ | # of controls | Burden |
|---|---|---|---|
| Aggregator redirect | SAQ A | ~20 | Very low |
| Iframe / hosted field | SAQ A / A-EP | ~30 to 190 | Low to medium |
| Form on your page + tokenization | SAQ A-EP | ~190 | Medium |
| Server-side PAN capture | SAQ D | ~300+ | Very heavy |
For 95% of stores, the right answer is aggregator redirect or iframe = SAQ A. Going to SAQ D to "own the experience" is costly and needlessly exposes you.
2026 obligations and cost of compliance
Even in SAQ A, a few technical obligations remain unavoidable in 2026. Here are the main ones and their cost order of magnitude.
| 2026 obligation | What it requires | Indicative cost |
|---|---|---|
| TLS 1.2+ mandatory | Encryption of the whole site | Included in hosting |
| Quarterly vulnerability scan | External ASV if A-EP/D | 0 to 300,000 FCFA/year |
| MFA on the back-office | Admin two-factor | Near zero |
| Password policy | Rotation, complexity | Near zero |
| SAQ A signed annually | Self-assessment | Internal |
| Access logging | Retained logs | Low |
In SAQ A, compliance often fits in a few hours of configuration; it is SAQ D that triggers audits, scans and pentests costing several hundred thousand FCFA per year.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
Sophie launches a home decor shop in Johannesburg and hesitates between a "homemade" card form and her aggregator's hosted checkout. The homemade form would push her into SAQ D: quarterly scan, pentest, enhanced logging, an order of magnitude of 300,000 to 600,000 FCFA/year. By choosing the aggregator redirect (SAQ A), she signs a self-assessment, enables TLS and MFA, and her annual compliance costs nearly zero. She reinvests the savings in advertising.
FAQ
Am I responsible for PCI-DSS if I use an aggregator? Yes, but your burden depends on the integration: with a redirect or iframe where you never see the PAN, you fall under SAQ A, the lightest.
What is the difference between SAQ A and SAQ D? SAQ A is for merchants who fully outsource card data (~20 controls); SAQ D targets those who capture or store the PAN (~300+ controls, audits and scans).
Do I need a quarterly vulnerability scan? In pure SAQ A, usually no; as soon as you move to A-EP or D, a quarterly external ASV scan becomes mandatory, with an indicative annual cost of 0 to 300,000 FCFA.
Is back-office MFA mandatory? Yes in 2026 for any admin access to payment-related systems; it is a near-free measure to enable and one of the most effective against intrusions.
Can I store cards to ease repeat purchases? Never store the PAN yourself: use the aggregator's tokenization, which returns a reusable token without dropping your store into SAQ D.
Let's talk about your project. We integrate an SAQ A-compliant, tokenized and secure card checkout, with no needless PCI-DSS burden. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
