Acquiring

What is Payment gateway?

A technical layer that encrypts card data, forwards authorisation requests to an acquirer, and returns the result to the merchant.

A payment gateway is the secure technology layer that acts as a digital equivalent of a physical point-of-sale terminal for online transactions.

Its primary function is to securely capture, encrypt, and transmit sensitive payment information from the merchant's Checkout environment to an acquiring bank or payment processor.

When a customer submits their card details, the gateway encrypts this data using standards like Transport Layer Security (TLS) before sending it onward.

This crucial step ensures that raw cardholder data does not pass through the merchant's own servers, significantly reducing their PCI DSS compliance burden.

The gateway manages the communication flow for the authorisation process, sending the request to the acquirer, which then routes it via the card schemes to the cardholder's issuing bank for approval or decline.

The gateway is also responsible for interpreting the response from the bank and relaying it back to the merchant's website to either confirm the order or ask the customer to try again.

Critically, it also facilitates processes required by regulation, such as presenting 3D Secure challenges to comply with Strong Customer Authentication (SCA) mandates like PSD2 in Europe. A common misconception is that the payment gateway holds or moves the merchant's funds; it does not.

The gateway is purely a data conduit, transmitting authorisation messages and, later, settlement instruction files to the acquirer, who is responsible for the actual movement of money.

Worked example

An online retailer in Ireland sells a product for €150. A customer on their website proceeds to Checkout and enters their Visa card details.

  1. The customer clicks 'Pay'. The web browser sends the card data directly to the payment gateway's servers, not the merchant's.
  2. The gateway encrypts the data and constructs an authorisation request, forwarding it to the merchant's chosen acquirer. This takes approximately 100-200 milliseconds.
  3. The acquirer routes the request to Visa, which identifies the issuing bank from the card's BIN and sends it on. This leg takes 200-300ms.
  4. The issuer's systems check for funds, apply fraud rules, and return an 'Approved' response code (00) back through the scheme and acquirer. This return trip takes another 300-400ms.
  5. The gateway receives the 'Approved' response and forwards a success message to the merchant's e-commerce platform, which then displays an order confirmation page. Total time elapsed is under one second. Later that day, the gateway will batch this approved transaction with others into a settlement file submitted to the acquirer.

Scheme notes

From a scheme perspective, the gateway's most critical function is the correct handling of security protocols. All gateways must be certified as PCI DSS Level 1 service providers.

They are responsible for the technical implementation of 3D Secure, which differs slightly between schemes. For Visa Secure and Mastercard Identity Check, the gateway's Merchant Plug-In (MPI) must collect and format device and browser data correctly to be passed to the scheme's Directory Server.

If this data is incomplete or improperly formatted, the issuer is more likely to 'step-up' the transaction to a full authentication challenge, increasing friction for the cardholder and potentially leading to abandonment, even if the transaction would otherwise have been approved frictionless.

Why it matters for merchants

The choice of payment gateway directly impacts a merchant's security, compliance burden, and user experience. A reliable gateway minimises latency and downtime, preventing lost sales.

By using a modern gateway with built-in tokenisation, merchants can offer returning customers a one-click Checkout experience without storing sensitive card data, which simplifies PCI DSS compliance to filling out a basic Self-Assessment Questionnaire (SAQ A).

For merchants operating with multiple acquirers, an independent gateway, often part of a payment orchestration platform like Cardflo, provides the flexibility to route transactions to different processors without being locked into the proprietary gateway of a single PSP.

Frequently asked

What is the difference between a standalone gateway and a full-stack PSP?

A standalone gateway provides the technical connection but requires the merchant to have a separate Merchant Identification Number (MID) from an acquiring bank.

In contrast, a full-stack Payment Service Provider (PSP) bundles both the gateway technology and the acquiring services into a single contract and technical integration.

How does a gateway impact transaction speed and latency?

The gateway introduces a processing leap where it must validate signatures, perform anti-fraud checks, and wait for the acquirer's response.

While this typically occurs in under two seconds, latency can increase if the gateway's server location is distant from the merchant's customer base or if multiple third-party API calls are required for risk scoring.

Does the payment gateway store my customers' card numbers?

A gateway's primary role is transmission, not storage. However, most modern gateways offer a tokenisation or 'vault' service.

In this model, the gateway captures the card number, exchanges it for a secure token, and stores the original card data in its own highly secure, PCI DSS compliant environment.

The merchant then stores only the non-sensitive token, which can be used for future or recurring payments without the risk and compliance cost of handling raw card data.

What's the difference between a gateway and an acquirer?

The gateway is the technology that securely moves the transaction *data*. The acquirer is the financial institution (a bank) that holds the merchant's account, receives the transaction data from the gateway, and manages the *settlement of funds* from the issuer via the card schemes.

Some companies, known as full-stack PSPs, provide both the gateway technology and the acquiring service under one roof.

Can a payment gateway help reduce my fraud and chargebacks?

Yes, many modern gateways integrate pre-processing fraud detection tools. These tools can screen transactions against blacklists, velocity rules, and geolocation data before the authorisation request is even sent to the acquirer.

This helps to block obviously fraudulent attempts early. They also manage the 3D Secure process, which can shift liability for certain types of fraud-related chargebacks from the merchant back to the issuing bank.

I have multiple MIDs with different acquirers. Can I use one gateway for all of them?

Yes, this is a primary use case for an independent or 'agnostic' payment gateway, which is a core component of payment orchestration. An agnostic gateway allows you to connect multiple acquirer accounts through a single integration.

You can then use a routing engine to decide which acquirer to use for each transaction based on factors like cost, currency, or card type, all while maintaining a consistent technical connection.

How much does a payment gateway cost?

Gateway pricing models vary. Some PSPs bundle the gateway fee into their blended transaction rate.

Standalone gateways often charge a monthly fee (e. g. , £10-£50) plus a small per-transaction fee (e. g. , 3p-10p). These fees are separate from the interchange, scheme, and acquirer fees associated with actually processing the payment.

The cost depends on the provider and the included features, such as tokenisation and fraud tools.

See how Payment gateway plays out in practice

Industries and regions where this term drives real acquiring, routing, or dispute decisions.

Related terms

Apply with Cardflo

Ready to improve your payments setup?

Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.

Apply now