PCI DSS SAQ A
Merchants using Watenga.js with the COPY&PAY iframe typically qualify for PCI Self-Assessment Questionnaire A (SAQ A) — the lightest scope when cardholder data never enters your environment.
Not legal advice
Scope
SAQ A applies when your e-commerce channel does not electronically store, process, or transmit cardholder data. Watenga.js loads payment fields in a PCI-scoped iframe; your server only receives tokens and transaction references.
Read the Watenga.js overview before embedding checkout.
Eligibility checklist
Confirm each item applies to your integration (interactive — not stored by Watenga):
Forbidden practices
- Custom HTML card forms posting PAN to your server.
- Logging full webhook bodies that may contain sensitive fields.
- Storing CVV, magnetic stripe, or PIN data in any system.
- Disabling COPY&PAY SRI integrity on the widget script tag.
Webhooks
Watenga webhooks deliver transaction metadata — not PAN. See Webhook configuration and verify signatures before processing.
Terminal / in-person
In-person card acceptance via the Terminal SDK (W57) falls under a different PCI scope (SAQ D-SP for the integrated POS). This page covers e-commerce SAQ A only.
Annual attestation
Last updated: 2026-06-05 · Incident contact: security@watenga.africa
