The verdict in three sentences
PCI-DSS is not reserved for banks: as soon as you accept a card, even via an aggregator, you have obligations. The winning 2026 strategy is full delegation: the PAN (card number) never touches your server, you stay in SAQ-A (the simplest questionnaire), and you avoid a heavy audit. The trap: a card field hosted on your own page, or a log capturing a number, pushes you into a far costlier scope.
The principle: never touch the card
For mobile money (Wave, Orange Money) there is no card PAN: the PCI-DSS risk mainly concerns the bank-card part of your checkout (international customers, Stripe). The golden rule: tokenization. The card is entered in a field hosted by the aggregator (iframe or redirect), which returns a token. You store and replay the token, never the number.
| Integration type | Who sees the PAN | Applicable SAQ | Compliance burden |
|---|---|---|---|
| Redirect to aggregator page | Aggregator only | SAQ-A | Minimal |
| Hosted iframe field (tokenization) | Aggregator only | SAQ-A | Minimal |
| Card field on your page + aggregator JS | Grey zone | SAQ-A-EP | Medium |
| Card form transiting your server | You | SAQ-D | Heavy and costly |
| PAN storage in database | You | SAQ-D + audit | Very heavy |
The higher you climb the table, the more the cost explodes. SAQ-D means quarterly scans, penetration tests, and documentation; SAQ-A fits in one self-assessment questionnaire.
What a merchant must actually handle
Even in SAQ-A you are not exempt from everything. Here are the controls on you and the compliance cost avoided by staying well positioned.
| Merchant-side requirement | Applies in SAQ-A | Cost of a gap (order of magnitude) |
|---|---|---|
| HTTPS/TLS across the whole checkout | Yes | Lost trust, browser blocking |
| No PAN in logs | Yes | Fall to SAQ-D |
| Tokenization via aggregator | Yes | Fall to SAQ-D |
| Access management (least privilege) | Yes | Internal breach |
| Security updates | Yes | Exploitable vulnerability |
| Annual penetration test | No (SAQ-A) | 1,500,000 to 4,000,000 FCFA avoided |
| Quarterly ASV scan | No (SAQ-A) | Recurring cost avoided |
By staying in SAQ-A, an African merchant typically avoids 1,500,000 to 4,000,000 FCFA in annual audit fees. That is the main economic argument for delegation.
Mini case study
Ibrahim, a restaurateur in Abidjan, adds online ordering with card payment for the diaspora. His first provider codes a card form on his own page, with the number transiting his PHP server. Verdict: SAQ-D, mandatory scans and audit, about 2,800,000 FCFA of compliance in year one. Rebuild with Kolonell: tokenized iframe card field, no PAN on the server. He drops back to SAQ-A, a simple annual questionnaire. Direct saving: about 2,500,000 FCFA, plus legal peace of mind.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
FAQ
Is mobile money subject to PCI-DSS?
PCI-DSS targets bank-card data. Wave and Orange Money do not use a card PAN, so most PCI risk comes from the card part of your checkout (often Stripe for international).
What is SAQ-A and why aim for it?
SAQ-A is the lightest self-assessment questionnaire, reserved for merchants who fully delegate the card to a third party. It avoids quarterly scans and penetration tests, worth several million FCFA per year.
Can I store card numbers to ease repeat purchases?
No, never in clear text. Use the aggregator's tokenization: you store a reusable token, not the PAN. Storing the PAN drops you to SAQ-D with a full audit.
Does a card field on my page take me out of SAQ-A?
Often yes, toward SAQ-A-EP or even SAQ-D depending on implementation. Prefer an iframe or a redirect where only the aggregator sees the input.
Who checks my PCI-DSS compliance?
Your aggregator or acquiring bank may request your signed SAQ. In an incident, lack of compliance can bring fines and increased liability.
Let's talk about your project. We design your checkout to stay in SAQ-A and spare you an unnecessary audit. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
