The verdict in three sentences
The right PCI DSS strategy for a store in anglophone Africa is to never touch the card number: by delegating entry to a PSP (hosted fields), you fall into SAQ A, the lightest. SAQ A has about 22 requirements versus ~300 for SAQ D, whose audit costs 3 to 6M FCFA a year. Tokenisation removes PAN storage and puts compliance within reach in about 2 weeks.
SAQ A vs SAQ D: the structuring decision
PCI DSS applies as soon as you accept cards. But your "scope" — the breadth of requirements — depends entirely on who handles card data. If it's your server, you're in SAQ D, heavy and costly. If it's the PSP via hosted fields (Paystack, Flutterwave), you're in SAQ A.
| Criterion | SAQ A (hosted) | SAQ D (custom) |
|---|---|---|
| Requirements | ~22 | ~300 |
| Who enters the card | PSP | Your site |
| PAN storage | None (token) | Yes, encrypted |
| Annual audit | Self-assessment | 3-6M FCFA/year |
| Compliance delay | ~2 weeks | Several months |
| Risk | Low | High |
The message is clear: unless there is a compelling reason, stay in SAQ A. Going SAQ D to "control the experience" means taking on hundreds of requirements and a five-figure (in euros) annual audit.
Tokenisation and the PSP's role
Tokenisation replaces the card number (PAN) with a token useless outside your PSP. You never store the card: you store a token for recurring payments. That is what keeps you in SAQ A while offering subscriptions or one-click payment.
| Element | Without tokenisation | With tokenisation |
|---|---|---|
| Stored data | Encrypted PAN | Token |
| PCI scope | SAQ D | SAQ A |
| Recurring payment | Complex | Native |
| Breach risk | High | Near zero |
| Compliance carried by | You | The PSP |
Often overlooked: non-compliance can cost up to 100,000 USD in fines (an order of magnitude set by the card networks), not counting the loss of the ability to accept cards. Against that, two weeks of SAQ A compliance with a PSP that carries the compliance is an obvious investment.
Need a professional website?
Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.
Mini case study
Moussa is launching a fashion store in Accra and hesitates to build his own card form "for the design". That option would place him in SAQ D: an annual audit estimated at 4M FCFA, several months of work, and fine risk.
By choosing his PSP's hosted fields and tokenisation, Moussa stays in SAQ A: compliance in 2 weeks, zero card storage, no heavy external audit. He saves about 4M FCFA a year and launches his store a quarter earlier.
FAQ
Am I subject to PCI DSS if I use a PSP? Yes, but at the lightest level. With hosted fields, you're in SAQ A (~22 requirements) instead of SAQ D (~300).
Does tokenisation allow subscriptions? Yes. You store a token, not the card, which enables recurring and one-click payment while staying in SAQ A.
How much does an SAQ D audit cost? Order of magnitude 3 to 6M FCFA a year, not counting internal time. That's the main reason to prefer SAQ A.
How long to become SAQ A compliant? About 2 weeks with a PSP like Paystack or Flutterwave, since they carry most of the compliance.
What's the risk of non-compliance? Fines up to 100,000 USD depending on the networks, and above all losing the right to accept cards. The risk is disproportionate to the cost of SAQ A.
Let's talk about your project. We integrate a PSP with hosted fields + tokenisation to keep you in SAQ A. WhatsApp +221 77 596 93 33.
Mohamed Bah
Fondateur, Kolonell
Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.
