The verdict in three sentences
PCI DSS compliance governs any card acceptance, but its weight depends on who handles the card data. If you delegate tokenisation to your PSP (Stripe, Paystack, Flutterwave), you fall under the lightest questionnaire, SAQ-A, and you never store the card number (PAN). The real cost then ranges from 0 (self-assessed SAQ-A) to a full QSA level-1 audit costing the equivalent of 3,000,000 FCFA.
The principle: never touch the PAN
The golden rule of card security: never store, transmit or process the clear card number on your servers. By redirecting the customer to the PSP hosted page or using a tokenised iframe field, sensitive data never reaches your infrastructure. You receive a harmless token instead.
Baseline technical requirements:
- TLS 1.2+ mandatory on all payment pages.
- Tokenisation: never a PAN in the database.
- Quarterly ASV scan if you handle data (higher levels).
- Encryption at rest and in transit for sensitive data.
SAQ level matrix and 2026 costs
| Level | Use case | PAN storage | ASV scan | Compliance cost |
|---|---|---|---|---|
| SAQ-A | PSP redirect/iframe | Never | No | 0 |
| SAQ-A-EP | Merchant page + PSP script | Never | Quarterly | 100,000 to 500,000 FCFA |
| SAQ-D merchant | Direct card handling | Possible | Quarterly | 1,000,000 to 3,000,000 FCFA |
| Level 1 (QSA) | >6 M transactions/yr | Depends on arch | Quarterly | 2,000,000 to 3,000,000 FCFA+ |
Obligations by transaction volume
| Merchant level | Card transactions/yr | Required validation |
|---|---|---|
| Level 4 | < 20,000 e-commerce | Self-assessed SAQ |
| Level 3 | 20,000 to 1 M | SAQ + ASV scan |
| Level 2 | 1 M to 6 M | SAQ + quarterly ASV scan |
| Level 1 | > 6 M | Annual on-site QSA audit |
Mini case study
Awa, who runs a fashion store in Johannesburg, accepts cards from her diaspora customers through a PSP-hosted payment page. Because she never handles the PAN, she falls under SAQ-A, which she completes herself in an hour, at a cost of zero. Had she embedded a card form on her own server, she would have moved to SAQ-D with an audit costing at least 1,000,000 FCFA equivalent. Delegating to the PSP saves her that cost and security burden.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
Do I need a full PCI DSS audit?
Rarely. If your PSP hosts the payment page or tokenises the card, you fall under self-assessed SAQ-A at zero cost. A full QSA audit (2,000,000 to 3,000,000 FCFA equivalent) applies only to level 1, above 6 million transactions per year.
Can I store my customers' card numbers?
No, unless you take on SAQ-D level and costly controls. Best practice is tokenisation: the PSP keeps the card and returns a harmless token.
What is the minimum technical bar?
TLS 1.2 or higher on all payment pages, no clear card data, and a quarterly ASV scan as soon as you handle data (SAQ-A-EP and above).
How much does compliance cost a small shop?
For a level-4 merchant using PSP redirect, the cost is zero (SAQ-A). With a PSP script on your page, expect 100,000 to 500,000 FCFA equivalent for SAQ-A-EP and the quarterly scan.
What are the risks of non-compliance?
Penalties from the card networks (Visa/Mastercard), increased liability in case of fraud, and even suspension of card acceptance. Compliance also protects your reputation.
Let's talk about your project. We design your card integration as SAQ-A, with no PAN storage, audit-ready. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
