Websites11 min read

Reducing PCI DSS scope with a hosted checkout in 2026

Mohamed Bah·Fondateur, Kolonell
August 26, 2026
Share:
Reducing PCI DSS scope with a hosted checkout in 2026

Reducing PCI DSS scope with a hosted checkout in 2026

Websites

The verdict in three sentences

From your very first card transaction, PCI DSS applies — but its weight depends entirely on who handles the numbers. With a hosted checkout (provider redirect or iframe), you never touch card data and move from the dreaded SAQ D (300+ requirements) to the light SAQ A (22 requirements). The result: a heavy 2 to 10 million FCFA audit avoided, and a simplified annual review.

SAQ A vs SAQ D: the wide gap

The self-assessment questionnaire (SAQ) depends on how you capture the card. Fully outsourcing entry drastically reduces the scope to audit.

2026 criterionSAQ A (hosted checkout)SAQ D (entry on your site)
Number of controls~22300+
Card data storedNonePotentially
Annual audit costAvoided / minimal2 to 10 M FCFA
Vulnerability scanLightQuarterly mandatory
Internal effortLowHigh (dedicated team)
Breach liabilityProviderMerchant

Redirect, iframe and tokenization

Three mechanics keep card data off your server. Tokenization replaces the number with a token that is useless if leaked.

MethodCard data on your serverCustomer experienceSAQ A eligible
Provider page redirectNoLeaves the site brieflyYes
Iframe/hosted fieldNoStays on your pageYes
Direct entry + APIYesSeamlessNo (SAQ D)
TokenizationToken only1-click paymentYes

Mini case study

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Fatou, founder of an electronics store in Dakar, planned to code her own card form. A provider quotes the SAQ D audit at 4,000,000 FCFA in year one, plus quarterly scans. By choosing a hosted checkout with iframe and tokenization, she stays in SAQ A: 22 declarative controls, zero heavy audit, and a launch faster by several weeks. Direct saving: about 4,000,000 FCFA.

FAQ

When does PCI DSS apply to me? From the first card transaction accepted. The standard applies regardless of size; only the level of requirement (SAQ A to D) varies with your architecture.

What is the workload difference between SAQ A and SAQ D? SAQ A has about 22 declarative controls, SAQ D has over 300 with mandatory quarterly scans. It is the difference between a formality and a company-wide project.

Redirect or iframe: which to choose? Both are SAQ A eligible. The iframe keeps the customer on your page (better conversion), the redirect is simpler to integrate. Neither stores the card with you.

Does tokenization really protect me? It replaces the number with a token that is useless elsewhere, so a leak exposes no usable data. It also enables 1-click payment without keeping the card.

Is mobile money subject to PCI DSS? No: Wave and Orange Money do not run on the card network. That is a strong argument for favoring these methods locally and shrinking your scope further.

Let's talk about your project. We deploy a SAQ A-compliant hosted checkout to spare you any heavy audit. WhatsApp +221 77 596 93 33.

Tags:#pci dss#securite#checkout heberge#tokenisation#conformite#carte#saq#paiement
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.