PCI DSS Scope When You Use Paystack
If you use Paystack Inline or Paystack Popup and never handle raw card data, you qualify for SAQ A — the simplest PCI DSS compliance tier. Fill out the self-assessment questionnaire annually. If you use the Paystack Charge API to capture card data directly, you fall under SAQ A-EP or higher. If you store, process, or transmit raw card data yourself, you are in SAQ D and need a QSA audit.
Which SAQ Applies to Your Paystack Integration
| Integration Type | SAQ | Notes |
|---|---|---|
| Paystack Popup / redirect to Paystack checkout | SAQ A | Simplest. ~20 requirements. Self-assessment only. |
| Paystack Inline.js on your own page (iframe) | SAQ A-EP | Your page delivers the payment script. More requirements. |
| Paystack Charge API with card tokenization in your app | SAQ D or A-EP | Depends on how the card data flows through your systems. |
| You store card numbers yourself | SAQ D | Full audit required. Never do this. |
Most developers using Paystack Inline or the popup fall under SAQ A or SAQ A-EP. You do not need to hire a QSA (Qualified Security Assessor) for these tiers.
Your Residual PCI Responsibilities
Even at SAQ A, you have obligations:
- Annual self-assessment — Complete the SAQ A questionnaire once a year.
- Quarterly ASV scans — Run approved vulnerability scans on any server that handles payment pages (even if they just host the Paystack Inline script).
- Patching — Keep your servers, frameworks, and dependencies up to date. A compromised server that hosts a Paystack integration can still be used to inject malicious scripts.
- Access control — Only staff who need access to payment data (transaction history, not card numbers) should have it.
- Incident response plan — Have a documented plan for what to do if you suspect a breach.
- No cardholder data storage — Explicitly verify that no card numbers appear in your database, logs, or backups.
Learn More
This guide is part of the Paystack security and PCI compliance guide.
Key Takeaways
- ✓SAQ A applies when all card data functions are outsourced to Paystack and your pages only link or redirect to Paystack's checkout.
- ✓SAQ A-EP applies when your page loads scripts that could access card data (e.g., custom Inline JS implementations on your own domain).
- ✓SAQ D requires a QSA-led audit — only if you store, process, or transmit raw card data. Paystack prevents this.
- ✓Your residual PCI responsibilities: annual SAQ completion, quarterly vulnerability scans, keeping your server software patched.
- ✓Do not store cardholder data (full PAN, CVV, or PIN) in any system — databases, logs, or backups.
- ✓Paystack is itself PCI DSS Level 1 certified — the highest level. Their infrastructure handles the heavy compliance burden.
Frequently Asked Questions
- Do I need to be PCI DSS certified to use Paystack?
- No certification is required — PCI DSS for most merchants is a self-assessment (SAQ), not a third-party audit. As a Paystack merchant, fill out the appropriate SAQ annually. Certification by a QSA (Qualified Security Assessor) is only required at the highest merchant tiers (processing over 6 million transactions per year).
- What is a QSA and do I need one?
- A QSA (Qualified Security Assessor) is a company certified by the PCI Council to conduct formal PCI DSS audits. Most small to mid-size merchants using Paystack do not need a QSA — the self-assessment questionnaire is sufficient. QSAs are required for Level 1 merchants (very high volume) or when card networks specifically require a formal audit.
- If Paystack is PCI Level 1, does that cover me?
- Paystack's PCI Level 1 certification covers their infrastructure — not yours. You benefit from not having to handle card data, but you still have your own PCI scope (your servers, your code, your access controls). Paystack being Level 1 means the payment processing pipeline is secure, not that your entire system is compliant by proxy.
- Can I get a letter from Paystack confirming they are PCI compliant?
- Yes. Contact Paystack support or your account manager to request their Attestation of Compliance (AOC). This document confirms Paystack's PCI Level 1 status and is what you share with banks, enterprise clients, or auditors who ask about the compliance of your payment processor.
Ready to build real-world apps?
Join the McTaba Labs full-stack marathon (4 months full-time · 6 months part-time). Learn M-Pesa, USSD, and WhatsApp engineering while shipping 8 production apps.
Apply to the McTaba Marathon