The verdict in three sentences
PCI DSS applies the moment you accept a bank card, even through a provider. The right strategy for an African site is to delegate card data handling to a certified aggregator, which drops your scope down to SAQ-A, the lightest tier. You save millions of FCFA in audit costs while staying compliant.
Self-assessment levels (SAQ)
The self-assessment questionnaire depends on how your site touches card data. The more you delegate, the shorter the form.
| SAQ level | Use case | Number of requirements | Compliance cost (2026 estimate) |
|---|---|---|---|
| SAQ-A | 100% redirect/iframe aggregator | ~22 | 0 - 300,000 FCFA |
| SAQ-A-EP | Merchant page calling the aggregator | ~140 | 500,000 - 1M FCFA |
| SAQ-D merchant | Card data passes through your servers | ~330 | 1.5 - 4M FCFA |
| Level 1 (QSA audit) | > 6M transactions/year | On-site audit | 4M FCFA+ |
Merchant vs aggregator: who does what
The key is knowing where your responsibility ends. A certified aggregator (Stripe, Paystack, Flutterwave, or a local PSP) carries most of the burden if you never store a card number.
| Responsibility | Merchant (SAQ-A) | Certified aggregator |
|---|---|---|
| Card number storage | Forbidden | Tokenised vault |
| Tokenisation | Uses the token | Generates the token |
| Encryption in transit (TLS 1.2+) | Yes (site) | Yes (API) |
| Intrusion detection | Best practice | Certified |
| Annual PCI audit | Signed SAQ-A | QSA attestation |
| Incident response | Notify the PSP | Handle the breach |
Minimal SAQ-A checklist
- HTTPS/TLS 1.2+ across the entire payment flow
- No card number stored, logged or transmitted in clear text
- Iframe or redirect to the aggregator for card entry
- Strong passwords and MFA on admin
- SAQ-A signed and renewed each year
Mini case study
Ibrahim, who runs an online electronics shop, hesitated to accept cards for his diaspora customers. By integrating an aggregator in iframe mode, he stays in SAQ-A scope: compliance costs him under 300,000 FCFA/year instead of the 2,000,000 FCFA of a SAQ-D audit. He now takes international cards without ever touching a number, and without the risk of a costly breach.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
Am I concerned if I only accept mobile money?
No, PCI DSS only covers bank card data. Mobile money (Wave, Orange Money) has other security requirements but does not fall under the PCI DSS framework.
Does tokenisation exempt me from everything?
It sharply reduces your scope: you handle a token unusable elsewhere, never the real number. You remain responsible for your site's security (TLS, MFA, patches).
How much does a full PCI audit cost in 2026?
A SAQ-D or Level 1 audit by a QSA runs between 1.5 and 4 million FCFA, excluding technical remediation. That is why delegating to an aggregator is almost always more cost-effective.
What is the risk of non-compliance?
In a breach: network fines, suspension of card acceptance and notification costs. The reputational damage often exceeds the fine itself.
Compliance and support
We scope your PCI DSS perimeter and integrate the right aggregator to keep you at SAQ-A. A site designed from the start to delegate card data spares you months of remediation.
Let's talk about your project. We secure your card and mobile money payments in 2026 compliance. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
