Bonaventure OgetoBy Bonaventure Ogeto|

PCI DSS Scope When You Use Paystack

If you use Paystack Inline or Paystack Popup and never handle raw card data, you qualify for SAQ A — the simplest PCI DSS compliance tier. Fill out the self-assessment questionnaire annually. If you use the Paystack Charge API to capture card data directly, you fall under SAQ A-EP or higher. If you store, process, or transmit raw card data yourself, you are in SAQ D and need a QSA audit.

Which SAQ Applies to Your Paystack Integration

Integration TypeSAQNotes
Paystack Popup / redirect to Paystack checkout SAQ A Simplest. ~20 requirements. Self-assessment only.
Paystack Inline.js on your own page (iframe) SAQ A-EP Your page delivers the payment script. More requirements.
Paystack Charge API with card tokenization in your app SAQ D or A-EP Depends on how the card data flows through your systems.
You store card numbers yourself SAQ D Full audit required. Never do this.

Most developers using Paystack Inline or the popup fall under SAQ A or SAQ A-EP. You do not need to hire a QSA (Qualified Security Assessor) for these tiers.

Your Residual PCI Responsibilities

Even at SAQ A, you have obligations:

  • Annual self-assessment — Complete the SAQ A questionnaire once a year.
  • Quarterly ASV scans — Run approved vulnerability scans on any server that handles payment pages (even if they just host the Paystack Inline script).
  • Patching — Keep your servers, frameworks, and dependencies up to date. A compromised server that hosts a Paystack integration can still be used to inject malicious scripts.
  • Access control — Only staff who need access to payment data (transaction history, not card numbers) should have it.
  • Incident response plan — Have a documented plan for what to do if you suspect a breach.
  • No cardholder data storage — Explicitly verify that no card numbers appear in your database, logs, or backups.

Learn More

Key Takeaways

  • SAQ A applies when all card data functions are outsourced to Paystack and your pages only link or redirect to Paystack's checkout.
  • SAQ A-EP applies when your page loads scripts that could access card data (e.g., custom Inline JS implementations on your own domain).
  • SAQ D requires a QSA-led audit — only if you store, process, or transmit raw card data. Paystack prevents this.
  • Your residual PCI responsibilities: annual SAQ completion, quarterly vulnerability scans, keeping your server software patched.
  • Do not store cardholder data (full PAN, CVV, or PIN) in any system — databases, logs, or backups.
  • Paystack is itself PCI DSS Level 1 certified — the highest level. Their infrastructure handles the heavy compliance burden.

Frequently Asked Questions

Do I need to be PCI DSS certified to use Paystack?
No certification is required — PCI DSS for most merchants is a self-assessment (SAQ), not a third-party audit. As a Paystack merchant, fill out the appropriate SAQ annually. Certification by a QSA (Qualified Security Assessor) is only required at the highest merchant tiers (processing over 6 million transactions per year).
What is a QSA and do I need one?
A QSA (Qualified Security Assessor) is a company certified by the PCI Council to conduct formal PCI DSS audits. Most small to mid-size merchants using Paystack do not need a QSA — the self-assessment questionnaire is sufficient. QSAs are required for Level 1 merchants (very high volume) or when card networks specifically require a formal audit.
If Paystack is PCI Level 1, does that cover me?
Paystack's PCI Level 1 certification covers their infrastructure — not yours. You benefit from not having to handle card data, but you still have your own PCI scope (your servers, your code, your access controls). Paystack being Level 1 means the payment processing pipeline is secure, not that your entire system is compliant by proxy.
Can I get a letter from Paystack confirming they are PCI compliant?
Yes. Contact Paystack support or your account manager to request their Attestation of Compliance (AOC). This document confirms Paystack's PCI Level 1 status and is what you share with banks, enterprise clients, or auditors who ask about the compliance of your payment processor.

Ready to build real-world apps?

Join the McTaba Labs full-stack marathon (4 months full-time · 6 months part-time). Learn M-Pesa, USSD, and WhatsApp engineering while shipping 8 production apps.

Apply to the McTaba Marathon