Websites11 min read

PCI DSS compliance for payments in Lagos in 2026

Mohamed Bah·Fondateur, Kolonell
August 25, 2026
Share:
PCI DSS compliance for payments in Lagos in 2026

PCI DSS compliance for payments in Lagos in 2026

Websites

The verdict in three sentences

PCI DSS applies the moment you accept a bank card, even through a provider. The right strategy for an African site is to delegate card data handling to a certified aggregator, which drops your scope down to SAQ-A, the lightest tier. You save millions of FCFA in audit costs while staying compliant.

Self-assessment levels (SAQ)

The self-assessment questionnaire depends on how your site touches card data. The more you delegate, the shorter the form.

SAQ levelUse caseNumber of requirementsCompliance cost (2026 estimate)
SAQ-A100% redirect/iframe aggregator~220 - 300,000 FCFA
SAQ-A-EPMerchant page calling the aggregator~140500,000 - 1M FCFA
SAQ-D merchantCard data passes through your servers~3301.5 - 4M FCFA
Level 1 (QSA audit)> 6M transactions/yearOn-site audit4M FCFA+

Merchant vs aggregator: who does what

The key is knowing where your responsibility ends. A certified aggregator (Stripe, Paystack, Flutterwave, or a local PSP) carries most of the burden if you never store a card number.

ResponsibilityMerchant (SAQ-A)Certified aggregator
Card number storageForbiddenTokenised vault
TokenisationUses the tokenGenerates the token
Encryption in transit (TLS 1.2+)Yes (site)Yes (API)
Intrusion detectionBest practiceCertified
Annual PCI auditSigned SAQ-AQSA attestation
Incident responseNotify the PSPHandle the breach

Minimal SAQ-A checklist

  • HTTPS/TLS 1.2+ across the entire payment flow
  • No card number stored, logged or transmitted in clear text
  • Iframe or redirect to the aggregator for card entry
  • Strong passwords and MFA on admin
  • SAQ-A signed and renewed each year

Mini case study

Ibrahim, who runs an online electronics shop, hesitated to accept cards for his diaspora customers. By integrating an aggregator in iframe mode, he stays in SAQ-A scope: compliance costs him under 300,000 FCFA/year instead of the 2,000,000 FCFA of a SAQ-D audit. He now takes international cards without ever touching a number, and without the risk of a costly breach.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

FAQ

Am I concerned if I only accept mobile money?

No, PCI DSS only covers bank card data. Mobile money (Wave, Orange Money) has other security requirements but does not fall under the PCI DSS framework.

Does tokenisation exempt me from everything?

It sharply reduces your scope: you handle a token unusable elsewhere, never the real number. You remain responsible for your site's security (TLS, MFA, patches).

How much does a full PCI audit cost in 2026?

A SAQ-D or Level 1 audit by a QSA runs between 1.5 and 4 million FCFA, excluding technical remediation. That is why delegating to an aggregator is almost always more cost-effective.

What is the risk of non-compliance?

In a breach: network fines, suspension of card acceptance and notification costs. The reputational damage often exceeds the fine itself.

Compliance and support

We scope your PCI DSS perimeter and integrate the right aggregator to keep you at SAQ-A. A site designed from the start to delegate card data spares you months of remediation.

Let's talk about your project. We secure your card and mobile money payments in 2026 compliance. WhatsApp +221 77 596 93 33.

Tags:#pci dss#compliance#payment#lagos#security#tokenisation#audit#2026
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.