Digital Africa11 min read

PCI-DSS and mobile money: merchant checklist 2026

Mohamed Bah·Fondateur, Kolonell
August 25, 2026
Share:
PCI-DSS and mobile money: merchant checklist 2026

PCI-DSS and mobile money: merchant checklist 2026

Digital Africa

The verdict in three sentences

PCI-DSS is not reserved for banks: as soon as you accept a card, even via an aggregator, you have obligations. The winning 2026 strategy is full delegation: the PAN (card number) never touches your server, you stay in SAQ-A (the simplest questionnaire), and you avoid a heavy audit. The trap: a card field hosted on your own page, or a log capturing a number, pushes you into a far costlier scope.

The principle: never touch the card

For mobile money (Wave, Orange Money) there is no card PAN: the PCI-DSS risk mainly concerns the bank-card part of your checkout (international customers, Stripe). The golden rule: tokenization. The card is entered in a field hosted by the aggregator (iframe or redirect), which returns a token. You store and replay the token, never the number.

Integration typeWho sees the PANApplicable SAQCompliance burden
Redirect to aggregator pageAggregator onlySAQ-AMinimal
Hosted iframe field (tokenization)Aggregator onlySAQ-AMinimal
Card field on your page + aggregator JSGrey zoneSAQ-A-EPMedium
Card form transiting your serverYouSAQ-DHeavy and costly
PAN storage in databaseYouSAQ-D + auditVery heavy

The higher you climb the table, the more the cost explodes. SAQ-D means quarterly scans, penetration tests, and documentation; SAQ-A fits in one self-assessment questionnaire.

What a merchant must actually handle

Even in SAQ-A you are not exempt from everything. Here are the controls on you and the compliance cost avoided by staying well positioned.

Merchant-side requirementApplies in SAQ-ACost of a gap (order of magnitude)
HTTPS/TLS across the whole checkoutYesLost trust, browser blocking
No PAN in logsYesFall to SAQ-D
Tokenization via aggregatorYesFall to SAQ-D
Access management (least privilege)YesInternal breach
Security updatesYesExploitable vulnerability
Annual penetration testNo (SAQ-A)1,500,000 to 4,000,000 FCFA avoided
Quarterly ASV scanNo (SAQ-A)Recurring cost avoided

By staying in SAQ-A, an African merchant typically avoids 1,500,000 to 4,000,000 FCFA in annual audit fees. That is the main economic argument for delegation.

Mini case study

Ibrahim, a restaurateur in Abidjan, adds online ordering with card payment for the diaspora. His first provider codes a card form on his own page, with the number transiting his PHP server. Verdict: SAQ-D, mandatory scans and audit, about 2,800,000 FCFA of compliance in year one. Rebuild with Kolonell: tokenized iframe card field, no PAN on the server. He drops back to SAQ-A, a simple annual questionnaire. Direct saving: about 2,500,000 FCFA, plus legal peace of mind.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

FAQ

Is mobile money subject to PCI-DSS?

PCI-DSS targets bank-card data. Wave and Orange Money do not use a card PAN, so most PCI risk comes from the card part of your checkout (often Stripe for international).

What is SAQ-A and why aim for it?

SAQ-A is the lightest self-assessment questionnaire, reserved for merchants who fully delegate the card to a third party. It avoids quarterly scans and penetration tests, worth several million FCFA per year.

Can I store card numbers to ease repeat purchases?

No, never in clear text. Use the aggregator's tokenization: you store a reusable token, not the PAN. Storing the PAN drops you to SAQ-D with a full audit.

Does a card field on my page take me out of SAQ-A?

Often yes, toward SAQ-A-EP or even SAQ-D depending on implementation. Prefer an iframe or a redirect where only the aggregator sees the input.

Who checks my PCI-DSS compliance?

Your aggregator or acquiring bank may request your signed SAQ. In an incident, lack of compliance can bring fines and increased liability.

Let's talk about your project. We design your checkout to stay in SAQ-A and spare you an unnecessary audit. WhatsApp +221 77 596 93 33.

Tags:#pci dss#payment compliance#tokenization#security#merchant#bank card
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.