Digital Africa11 min read

PCI DSS for an online store in anglophone Africa in 2026

Mohamed Bah·Fondateur, Kolonell
August 24, 2026
Share:
PCI DSS for an online store in anglophone Africa in 2026

PCI DSS for an online store in anglophone Africa in 2026

Digital Africa

The verdict in three sentences

The right PCI DSS strategy for a store in anglophone Africa is to never touch the card number: by delegating entry to a PSP (hosted fields), you fall into SAQ A, the lightest. SAQ A has about 22 requirements versus ~300 for SAQ D, whose audit costs 3 to 6M FCFA a year. Tokenisation removes PAN storage and puts compliance within reach in about 2 weeks.

SAQ A vs SAQ D: the structuring decision

PCI DSS applies as soon as you accept cards. But your "scope" — the breadth of requirements — depends entirely on who handles card data. If it's your server, you're in SAQ D, heavy and costly. If it's the PSP via hosted fields (Paystack, Flutterwave), you're in SAQ A.

CriterionSAQ A (hosted)SAQ D (custom)
Requirements~22~300
Who enters the cardPSPYour site
PAN storageNone (token)Yes, encrypted
Annual auditSelf-assessment3-6M FCFA/year
Compliance delay~2 weeksSeveral months
RiskLowHigh

The message is clear: unless there is a compelling reason, stay in SAQ A. Going SAQ D to "control the experience" means taking on hundreds of requirements and a five-figure (in euros) annual audit.

Tokenisation and the PSP's role

Tokenisation replaces the card number (PAN) with a token useless outside your PSP. You never store the card: you store a token for recurring payments. That is what keeps you in SAQ A while offering subscriptions or one-click payment.

ElementWithout tokenisationWith tokenisation
Stored dataEncrypted PANToken
PCI scopeSAQ DSAQ A
Recurring paymentComplexNative
Breach riskHighNear zero
Compliance carried byYouThe PSP

Often overlooked: non-compliance can cost up to 100,000 USD in fines (an order of magnitude set by the card networks), not counting the loss of the ability to accept cards. Against that, two weeks of SAQ A compliance with a PSP that carries the compliance is an obvious investment.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Mini case study

Moussa is launching a fashion store in Accra and hesitates to build his own card form "for the design". That option would place him in SAQ D: an annual audit estimated at 4M FCFA, several months of work, and fine risk.

By choosing his PSP's hosted fields and tokenisation, Moussa stays in SAQ A: compliance in 2 weeks, zero card storage, no heavy external audit. He saves about 4M FCFA a year and launches his store a quarter earlier.

FAQ

Am I subject to PCI DSS if I use a PSP? Yes, but at the lightest level. With hosted fields, you're in SAQ A (~22 requirements) instead of SAQ D (~300).

Does tokenisation allow subscriptions? Yes. You store a token, not the card, which enables recurring and one-click payment while staying in SAQ A.

How much does an SAQ D audit cost? Order of magnitude 3 to 6M FCFA a year, not counting internal time. That's the main reason to prefer SAQ A.

How long to become SAQ A compliant? About 2 weeks with a PSP like Paystack or Flutterwave, since they carry most of the compliance.

What's the risk of non-compliance? Fines up to 100,000 USD depending on the networks, and above all losing the right to accept cards. The risk is disproportionate to the cost of SAQ A.

Let's talk about your project. We integrate a PSP with hosted fields + tokenisation to keep you in SAQ A. WhatsApp +221 77 596 93 33.

Tags:#pci dss#compliance#security#west africa#tokenisation#psp#card#e-commerce
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.