PCI DSS SAQ A

Merchants using Watenga.js with the COPY&PAY iframe typically qualify for PCI Self-Assessment Questionnaire A (SAQ A) — the lightest scope when cardholder data never enters your environment.

Not legal advice

This documentation summarizes Watenga's integration and compliance posture for developers and merchants. It does not constitute legal, tax, or regulatory advice. Canonical policies live in our security documentation repository. Consult qualified counsel for jurisdiction-specific obligations.

Scope

SAQ A applies when your e-commerce channel does not electronically store, process, or transmit cardholder data. Watenga.js loads payment fields in a PCI-scoped iframe; your server only receives tokens and transaction references.

Read the Watenga.js overview before embedding checkout.

Eligibility checklist

Confirm each item applies to your integration (interactive — not stored by Watenga):

Forbidden practices

  • Custom HTML card forms posting PAN to your server.
  • Logging full webhook bodies that may contain sensitive fields.
  • Storing CVV, magnetic stripe, or PIN data in any system.
  • Disabling COPY&PAY SRI integrity on the widget script tag.

Webhooks

Watenga webhooks deliver transaction metadata — not PAN. See Webhook configuration and verify signatures before processing.

Terminal / in-person

In-person card acceptance via the Terminal SDK (W57) falls under a different PCI scope (SAQ D-SP for the integrated POS). This page covers e-commerce SAQ A only.

Annual attestation

SAQ A must be completed annually (or per your acquirer program). Watenga infrastructure undergoes separate platform assessments; your attestation covers your website and integration practices.

Last updated: 2026-06-05 · Incident contact: security@watenga.africa