Websites11 min read

PCI DSS compliance for card payments in Johannesburg 2026

Mohamed Bah·Fondateur, Kolonell
August 27, 2026
Share:
PCI DSS compliance for card payments in Johannesburg 2026

PCI DSS compliance for card payments in Johannesburg 2026

Websites

The verdict in three sentences

PCI DSS compliance governs any card acceptance, but its weight depends on who handles the card data. If you delegate tokenisation to your PSP (Stripe, Paystack, Flutterwave), you fall under the lightest questionnaire, SAQ-A, and you never store the card number (PAN). The real cost then ranges from 0 (self-assessed SAQ-A) to a full QSA level-1 audit costing the equivalent of 3,000,000 FCFA.

The principle: never touch the PAN

The golden rule of card security: never store, transmit or process the clear card number on your servers. By redirecting the customer to the PSP hosted page or using a tokenised iframe field, sensitive data never reaches your infrastructure. You receive a harmless token instead.

Baseline technical requirements:

  • TLS 1.2+ mandatory on all payment pages.
  • Tokenisation: never a PAN in the database.
  • Quarterly ASV scan if you handle data (higher levels).
  • Encryption at rest and in transit for sensitive data.

SAQ level matrix and 2026 costs

LevelUse casePAN storageASV scanCompliance cost
SAQ-APSP redirect/iframeNeverNo0
SAQ-A-EPMerchant page + PSP scriptNeverQuarterly100,000 to 500,000 FCFA
SAQ-D merchantDirect card handlingPossibleQuarterly1,000,000 to 3,000,000 FCFA
Level 1 (QSA)>6 M transactions/yrDepends on archQuarterly2,000,000 to 3,000,000 FCFA+

Obligations by transaction volume

Merchant levelCard transactions/yrRequired validation
Level 4< 20,000 e-commerceSelf-assessed SAQ
Level 320,000 to 1 MSAQ + ASV scan
Level 21 M to 6 MSAQ + quarterly ASV scan
Level 1> 6 MAnnual on-site QSA audit

Mini case study

Awa, who runs a fashion store in Johannesburg, accepts cards from her diaspora customers through a PSP-hosted payment page. Because she never handles the PAN, she falls under SAQ-A, which she completes herself in an hour, at a cost of zero. Had she embedded a card form on her own server, she would have moved to SAQ-D with an audit costing at least 1,000,000 FCFA equivalent. Delegating to the PSP saves her that cost and security burden.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

FAQ

Do I need a full PCI DSS audit?

Rarely. If your PSP hosts the payment page or tokenises the card, you fall under self-assessed SAQ-A at zero cost. A full QSA audit (2,000,000 to 3,000,000 FCFA equivalent) applies only to level 1, above 6 million transactions per year.

Can I store my customers' card numbers?

No, unless you take on SAQ-D level and costly controls. Best practice is tokenisation: the PSP keeps the card and returns a harmless token.

What is the minimum technical bar?

TLS 1.2 or higher on all payment pages, no clear card data, and a quarterly ASV scan as soon as you handle data (SAQ-A-EP and above).

How much does compliance cost a small shop?

For a level-4 merchant using PSP redirect, the cost is zero (SAQ-A). With a PSP script on your page, expect 100,000 to 500,000 FCFA equivalent for SAQ-A-EP and the quarterly scan.

What are the risks of non-compliance?

Penalties from the card networks (Visa/Mastercard), increased liability in case of fraud, and even suspension of card acceptance. Compliance also protects your reputation.

Let's talk about your project. We design your card integration as SAQ-A, with no PAN storage, audit-ready. WhatsApp +221 77 596 93 33.

Tags:#pci dss#conformite#securite paiement#carte#dakar#johannesburg#tokenisation#2026
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.