The verdict in three sentences
If your store never stores, processes or transmits a card number in clear, you fall under SAQ-A, the lightest compliance level. The key is to delegate 100% of card entry to the PSP (hosted fields or redirect page) to keep your server out of PCI scope. A merchant who tries to handle everything in-house risks SAQ-D — 300+ requirements and a costly audit — with no commercial benefit.
SAQ levels and what they require
The SAQ (Self-Assessment Questionnaire) depends on how card data flows through you. The more you delegate, the fewer obligations you carry. Here are the levels that concern an e-commerce store in 2026.
| SAQ type | For whom | Requirements (ballpark) | Burden |
|---|---|---|---|
| SAQ-A | Fully delegated payment (redirect / iframe) | ~22 | Very low |
| SAQ-A-EP | Merchant page that influences card flow | ~139 | Medium |
| SAQ-D merchant | In-house card storage / processing | ~300+ | Very heavy |
For 90% of stores in Anglophone Africa, the goal is simple: stay in SAQ-A. That means using the PSP's hosted fields or redirect, never logging a PAN, and serving the whole site over HTTPS.
Costs and timelines by integration mode
The integration choice does not just change security: it radically changes the cost and timeline of compliance. Here are the 2026 ballparks for an SME.
| Integration mode | PCI level | Compliance cost (estimate) | Timeline |
|---|---|---|---|
| PSP redirect | SAQ-A | 0 - 150,000 FCFA | 1 - 3 days |
| Hosted fields (iframe) | SAQ-A | 0 - 250,000 FCFA | 3 - 7 days |
| Direct API + tokenization | SAQ-A-EP | 800,000 - 2,500,000 FCFA | 3 - 8 weeks |
| In-house card storage | SAQ-D | 5,000,000+ FCFA + QSA audit | 3 - 6 months |
The lesson: PSP-side tokenization gives you the "saved card" experience without pulling your servers into heavy scope. You never hold the real number, only a token useless to a hacker.
Mini case study
Aminata is launching a fashion store in Dakar. A vendor offers a "direct API" integration at 1,800,000 FCFA that would put her in SAQ-A-EP, with mandatory quarterly scans. By switching to PSP hosted fields she stays in SAQ-A: compliance cost 0 FCFA, no imposed external scans, and a go-live in 5 days instead of several weeks. Direct saving: 1,800,000 FCFA, plus the avoided annual scan fees.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
Am I required to be PCI-DSS compliant?
Yes, as soon as you accept cards. But in SAQ-A, compliance boils down to a ~20-point questionnaire and using a certified PSP. It is not a heavy audit.
Is mobile money covered by PCI-DSS?
No. PCI-DSS only covers payment card data. Wave, Orange Money and others have their own compliance requirements, separate from PCI.
Who fills the SAQ, me or the agency?
The merchant is responsible, but a good agency configures your store to stay in SAQ-A and helps you tick the questionnaire. Plan half a day of support.
What does a non-compliant store risk?
In a card-data breach, network penalties can reach several million FCFA, plus merchant account suspension. Staying in SAQ-A removes most of that risk.
Does tokenization really take me out of scope?
Yes, if the token is generated and held by the PSP and you never see the PAN. You store an identifier unusable elsewhere, which keeps you in SAQ-A.
Let's talk about your project. We design your store to stay in SAQ-A and spare you any needless audit. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.

