Websites11 min read

PCI-DSS Compliance for an Online Store in Anglophone Africa (2026)

Mohamed Bah·Fondateur, Kolonell
August 30, 2026
Share:
PCI-DSS Compliance for an Online Store in Anglophone Africa (2026)

PCI-DSS Compliance for an Online Store in Anglophone Africa (2026)

Websites

The verdict in three sentences

If your store never stores, processes or transmits a card number in clear, you fall under SAQ-A, the lightest compliance level. The key is to delegate 100% of card entry to the PSP (hosted fields or redirect page) to keep your server out of PCI scope. A merchant who tries to handle everything in-house risks SAQ-D — 300+ requirements and a costly audit — with no commercial benefit.

SAQ levels and what they require

The SAQ (Self-Assessment Questionnaire) depends on how card data flows through you. The more you delegate, the fewer obligations you carry. Here are the levels that concern an e-commerce store in 2026.

SAQ typeFor whomRequirements (ballpark)Burden
SAQ-AFully delegated payment (redirect / iframe)~22Very low
SAQ-A-EPMerchant page that influences card flow~139Medium
SAQ-D merchantIn-house card storage / processing~300+Very heavy

For 90% of stores in Anglophone Africa, the goal is simple: stay in SAQ-A. That means using the PSP's hosted fields or redirect, never logging a PAN, and serving the whole site over HTTPS.

Costs and timelines by integration mode

The integration choice does not just change security: it radically changes the cost and timeline of compliance. Here are the 2026 ballparks for an SME.

Integration modePCI levelCompliance cost (estimate)Timeline
PSP redirectSAQ-A0 - 150,000 FCFA1 - 3 days
Hosted fields (iframe)SAQ-A0 - 250,000 FCFA3 - 7 days
Direct API + tokenizationSAQ-A-EP800,000 - 2,500,000 FCFA3 - 8 weeks
In-house card storageSAQ-D5,000,000+ FCFA + QSA audit3 - 6 months

The lesson: PSP-side tokenization gives you the "saved card" experience without pulling your servers into heavy scope. You never hold the real number, only a token useless to a hacker.

Mini case study

Aminata is launching a fashion store in Dakar. A vendor offers a "direct API" integration at 1,800,000 FCFA that would put her in SAQ-A-EP, with mandatory quarterly scans. By switching to PSP hosted fields she stays in SAQ-A: compliance cost 0 FCFA, no imposed external scans, and a go-live in 5 days instead of several weeks. Direct saving: 1,800,000 FCFA, plus the avoided annual scan fees.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

FAQ

Am I required to be PCI-DSS compliant?

Yes, as soon as you accept cards. But in SAQ-A, compliance boils down to a ~20-point questionnaire and using a certified PSP. It is not a heavy audit.

Is mobile money covered by PCI-DSS?

No. PCI-DSS only covers payment card data. Wave, Orange Money and others have their own compliance requirements, separate from PCI.

Who fills the SAQ, me or the agency?

The merchant is responsible, but a good agency configures your store to stay in SAQ-A and helps you tick the questionnaire. Plan half a day of support.

What does a non-compliant store risk?

In a card-data breach, network penalties can reach several million FCFA, plus merchant account suspension. Staying in SAQ-A removes most of that risk.

Does tokenization really take me out of scope?

Yes, if the token is generated and held by the PSP and you never see the PAN. You store an identifier unusable elsewhere, which keeps you in SAQ-A.

Let's talk about your project. We design your store to stay in SAQ-A and spare you any needless audit. WhatsApp +221 77 596 93 33.

Tags:#PCI-DSS#compliance#security#PSP#SAQ#online store#card#e-commerce
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.