McTaba Labs logo
Bonaventure OgetoBy Bonaventure Ogeto|

PCI DSS Scope When You Use Paystack

If you use Paystack Inline or Paystack Popup and never handle raw card data, you qualify for SAQ A — the simplest PCI DSS compliance tier. Fill out the self-assessment questionnaire annually. If you use the Paystack Charge API to capture card data directly, you fall under SAQ A-EP or higher. If you store, process, or transmit raw card data yourself, you are in SAQ D and need a QSA audit.

Which SAQ Applies to Your Paystack Integration

Integration TypeSAQNotes
Paystack Popup / redirect to Paystack checkout SAQ A Simplest. ~20 requirements. Self-assessment only.
Paystack Inline.js on your own page (iframe) SAQ A-EP Your page delivers the payment script. More requirements.
Paystack Charge API with card tokenization in your app SAQ D or A-EP Depends on how the card data flows through your systems.
You store card numbers yourself SAQ D Full audit required. Never do this.

Most developers using Paystack Inline or the popup fall under SAQ A or SAQ A-EP. You do not need to hire a QSA (Qualified Security Assessor) for these tiers.

Your Residual PCI Responsibilities

Even at SAQ A, you have obligations:

  • Annual self-assessment — Complete the SAQ A questionnaire once a year.
  • Quarterly ASV scans — Run approved vulnerability scans on any server that handles payment pages (even if they just host the Paystack Inline script).
  • Patching — Keep your servers, frameworks, and dependencies up to date. A compromised server that hosts a Paystack integration can still be used to inject malicious scripts.
  • Access control — Only staff who need access to payment data (transaction history, not card numbers) should have it.
  • Incident response plan — Have a documented plan for what to do if you suspect a breach.
  • No cardholder data storage — Explicitly verify that no card numbers appear in your database, logs, or backups.

Get weekly developer tips

Join 25,000+ developers. Practical guides, job tips, and new content — straight to your inbox.

No spam. Unsubscribe anytime.

Key Takeaways

  • SAQ A applies when all card data functions are outsourced to Paystack and your pages only link or redirect to Paystack's checkout.
  • SAQ A-EP applies when your page loads scripts that could access card data (e.g., custom Inline JS implementations on your own domain).
  • SAQ D requires a QSA-led audit — only if you store, process, or transmit raw card data. Paystack prevents this.
  • Your residual PCI responsibilities: annual SAQ completion, quarterly vulnerability scans, keeping your server software patched.
  • Do not store cardholder data (full PAN, CVV, or PIN) in any system — databases, logs, or backups.
  • Paystack is itself PCI DSS Level 1 certified — the highest level. Their infrastructure handles the heavy compliance burden.

Frequently Asked Questions

Do I need to be PCI DSS certified to use Paystack?
No certification is required — PCI DSS for most merchants is a self-assessment (SAQ), not a third-party audit. As a Paystack merchant, fill out the appropriate SAQ annually. Certification by a QSA (Qualified Security Assessor) is only required at the highest merchant tiers (processing over 6 million transactions per year).
What is a QSA and do I need one?
A QSA (Qualified Security Assessor) is a company certified by the PCI Council to conduct formal PCI DSS audits. Most small to mid-size merchants using Paystack do not need a QSA — the self-assessment questionnaire is sufficient. QSAs are required for Level 1 merchants (very high volume) or when card networks specifically require a formal audit.
If Paystack is PCI Level 1, does that cover me?
Paystack's PCI Level 1 certification covers their infrastructure — not yours. You benefit from not having to handle card data, but you still have your own PCI scope (your servers, your code, your access controls). Paystack being Level 1 means the payment processing pipeline is secure, not that your entire system is compliant by proxy.
Can I get a letter from Paystack confirming they are PCI compliant?
Yes. Contact Paystack support or your account manager to request their Attestation of Compliance (AOC). This document confirms Paystack's PCI Level 1 status and is what you share with banks, enterprise clients, or auditors who ask about the compliance of your payment processor.

Learn Paystack Integration

KES 2,999

The definitive guide to building payment systems with Paystack — from your first transaction to production-grade payment infrastructure across Africa. 9 modules, 47 lessons. Free preview available.

Start Paystack Course

Not ready? Create Free Account