What is Tokenisation?
Replacing sensitive card data with a non-sensitive surrogate value that can be stored and reused without PCI scope.
Tokenisation is a fundamental data security process that replaces a sensitive data element, such as a 16-digit Primary Account Number (PAN), with a non-sensitive equivalent known as a 'token'.
This token has no extrinsic or exploitable value; it is simply a reference to the original data, which is stored securely in a PCI DSS compliant environment called a vault.
By using tokens to initiate payments, merchants can avoid handling and storing raw cardholder data on their own systems. This dramatically reduces their PCI DSS compliance scope, mitigates the risk associated with a data breach, and removes hazardous information from their environment.
There are two main types of tokenisation. The first is gateway (or PSP) tokenisation, where the payment provider creates a proprietary token that can only be used within its own processing ecosystem.
This is effective for security but can lead to vendor lock-in. The second, more advanced form is network tokenisation.
Here, the card schemes themselves (Visa, Mastercard) issue the token. These network tokens are interoperable across different payment providers and, crucially, are automatically updated by the issuing bank when a customer's physical card is replaced or expires.
This persistence is a key advantage, directly improving authorisation rates for recurring and card-on-file transactions. A common misconception is that tokenisation is the same as encryption.
Encryption uses a key to scramble data and can be reversed with the same key, whereas a properly tokenised value cannot be reverse-engineered back to the original PAN.
Worked example
A customer makes a £75 purchase on an e-commerce website for the first time. At Checkout, they enter their card details.
The merchant's payment gateway uses tokenisation. The raw card data is sent directly to the gateway's secure vault, never touching the merchant's server.
The gateway's vault responds with a token, for example `gtwy_tok_123abc`, which the merchant stores against the customer's account for future use. A month later, the customer returns.
They see their 'Saved Card ending in 4242' and choose to pay with it. The merchant's site sends the token `gtwy_tok_123abc` and the new purchase amount to the gateway.
The gateway retrieves the real card number from its vault and processes the payment. The merchant facilitated a fast, convenient Checkout without ever storing the risky PAN.
Scheme notes
While the general concept of tokenisation is not scheme-specific, the most advanced form, network tokenisation, is driven directly by the schemes. Visa's VTS (Visa Token Service) and Mastercard's MDES (Mastercard Digital Enablement Service) are the two largest platforms for creating and managing network tokens.
They work with issuers to provision tokens and keep them synchronised with the underlying card details. Using network tokens can sometimes result in lower interchange rates, as the schemes view these transactions as more secure due to the inclusion of a dynamic cryptogram.
In contrast, gateway tokens are proprietary to the PSP that created them and offer no direct interchange benefits, although they remain an essential tool for PCI DSS scope reduction.
Why it matters for merchants
For merchants, tokenisation is not optional; it is an essential component of modern payment processing. The primary impact is a significant reduction in PCI DSS compliance burden, saving time, money, and resources that would otherwise be spent on stringent security controls and audits.
It is also a critical security measure against data breaches. By using network tokenisation, merchants can also directly improve their bottom line.
The automatic card updates provided by network tokens increase authorisation rates for card-on-file transactions, reducing Involuntary churn and preserving revenue streams, a feature particularly valuable for subscription businesses.
Utilising a PSP like Cardflo that supports multiple token types gives merchants security and the flexibility to optimise their payment routing.
Frequently asked
How does tokenisation differ from encryption in a payment environment?
Encryption uses an algorithm to hide data that can be decrypted with a key, whereas tokenisation replaces the data entirely with a non-mathematical placeholder.
This means that if a database of tokens is breached, the values are useless to an attacker as they cannot be reversed to reveal the original PAN without access to the secure token vault.
What is the primary advantage of using network tokens over gateway-specific tokens?
Network tokens offer greater portability and longevity because they are recognised across the entire payment ecosystem rather than being tied to a single Payment Service Provider.
They automatically update when a bank issues a new card, reducing the likelihood of transaction declines due to outdated card details and ensuring the merchant can maintain a seamless recurring billing cycle.
What's the difference between tokenisation and encryption?
Encryption is a two-way process that uses a mathematical algorithm and a key to scramble data. Anyone with the key can decrypt the data back to its original form.
Tokenisation is a one-way process where sensitive data is replaced by a non-sensitive token. There is no mathematical relationship between the token and the original data, meaning it cannot be reversed.
This makes tokenisation a more secure method for protecting stored payment data.
If I use tokenisation, am I still in scope for PCI DSS?
Using tokenisation via a certified third-party provider drastically reduces your PCI DSS scope, but does not entirely eliminate it. You are still required to validate your compliance annually, typically by completing the simplest Self-Assessment Questionnaire (SAQ A).
This confirms that you are not storing, processing, or transmitting any cardholder data and are relying on a compliant service provider.
Can I tokenise payment methods other than credit cards?
Yes. While most commonly associated with card payments, the principle of tokenisation can be applied to other payment instruments.
For example, bank account numbers used for direct debit schemes (like SEPA or ACH) can be tokenised to allow merchants to initiate future payments without storing the actual bank details. This provides a similar security and compliance benefit.
What happens to my tokens if I want to change my payment provider?
If you are using proprietary gateway tokens, changing providers requires a secure token migration process. This involves your old provider transferring the vaulted card details to your new provider, who will then re-tokenise them.
This can be complex and may involve fees. If you are using network tokens, they are portable, and you can simply start processing them through a new provider that is also connected to the scheme's token service.
Does tokenisation prevent fraud?
Tokenisation is primarily a tool to protect stored data and prevent it from being compromised in a data breach. It does not prevent transaction fraud, such as someone using stolen card details to make a purchase.
However, network tokenisation adds a layer of security through the use of a transaction-specific cryptogram, which makes transactions more secure and helps issuers approve more legitimate payments.
See how Tokenisation plays out in practice
Industries and regions where this term drives real acquiring, routing, or dispute decisions.
Related terms
A PCI DSS compliant store of tokenised card credentials that lets a merchant charge a card again without holding the PAN.
A scheme-issued token that replaces the PAN end-to-end and is automatically updated when the underlying card is reissued.
The Payment Card Industry Data Security Standard, the scheme-mandated framework for handling cardholder data.
A technical layer that encrypts card data, forwards authorisation requests to an acquirer, and returns the result to the merchant.
Related guides.
Ready to improve your payments setup?
Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.