E-commerce11 min read

Do You Need PCI-DSS If You Only Take Mobile Money? Nairobi 2026

Mohamed Bah·Fondateur, Kolonell
August 31, 2026
Share:
Do You Need PCI-DSS If You Only Take Mobile Money? Nairobi 2026

Do You Need PCI-DSS If You Only Take Mobile Money? Nairobi 2026

E-commerce

The verdict in three sentences

A 100% mobile-money store (Wave, Orange Money, M-Pesa, MTN MoMo) handles no card number: your PCI-DSS scope is minimal, near zero. Paying for a heavy SAQ-D audit "just in case" is waste as long as you touch no card. The real trigger is the day you add Stripe: cards bring scope back, which hosted fields (SAQ-A) and tokenization keep to a minimum.

What triggers PCI scope

PCI-DSS applies as soon as you "store, process or transmit" card data. Mobile money never touches that data: the operator handles everything.

Collection modeCard data handled?PCI scopeEffort
Mobile money onlyNoMinimal / out of scopeVery low
Card via hosted fieldsNo (provider iframe)SAQ-ALow
Card via redirectNo (provider page)SAQ-ALow
Card entered on your siteYesSAQ-DHigh
Storing the PANYesSAQ-D + auditVery high

With a wallet, no PAN is stored by you: the card number simply never exists in your system.

Scope decision and costs

The right reflex: choose the collection mode by the scope it imposes, not the reverse.

ScenarioSAQBurden of proofIndicative 2026 cost
Mobile money onlyNone/lightOperator contractsNear zero
+ Stripe hosted fieldsSAQ-A~22 questionsLow (self-assessment)
+ Redirected cardSAQ-A~22 questionsLow
Card on your serverSAQ-D300+ questionsHigh (QSA audit)
Very high card volumeAnnual QSA auditFormal reportVery high

The cost jump from SAQ-A to SAQ-D is huge: staying on hosted fields or mobile money keeps you on the right side. Only pay for SAQ-D weight if you truly enter cards yourself.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Mini case study

Awa runs a cosmetics shop in Nairobi, collecting only via M-Pesa and mobile money. A consultant offers "full PCI-DSS compliance" at 1,500,000 FCFA (about 2,300 EUR). Since she touches no card, her scope is minimal: that spend is pointless. Later, to sell to the diaspora, she adds Stripe with hosted fields (SAQ-A): the card is entered in Stripe's iframe, never on her server, and her scope stays light (self-assessment). Immediate saving: 1,500,000 FCFA of unneeded compliance, while keeping the card option for international sales.

FAQ

Does mobile money really take me out of PCI scope? Yes, largely: PCI-DSS concerns card data, which mobile money never handles. Your compliance then reduces to general security good practice and operator contracts.

What exactly is SAQ-A? It's the lightest self-assessment questionnaire (~22 questions), for merchants who fully outsource card entry (hosted fields or redirect). No heavy QSA audit is required.

Does adding Stripe force SAQ-D on me? No, if you use its hosted fields or a redirect: the card never passes through your server, so you stay on SAQ-A. You only move to SAQ-D if you capture the card yourself.

Do I need to store the card number for refunds? No. Use the provider's tokenization: you keep a token, never the PAN. That supports refunds and subscriptions without inflating your scope.

How much does a SAQ-D audit cost? The 2026 order of magnitude is high (support + QSA), nothing like a SAQ-A self-assessment. That's why you avoid SAQ-D until you capture cards yourself.

Let's talk about your project. We scope your PCI footprint and wire mobile money + hosted card to minimize your compliance costs. WhatsApp +221 77 596 93 33.

Tags:#PCI-DSS#compliance#mobile money#card#security#Douala#Nairobi#regulation
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.