Compare Payment Gateways (Online) Providers UK (2026)
Compare Checkout, Integration, Payment Methods, 3D Secure, Tokenisation, Fraud Controls, Reliability And Gateway Cost
Use this payment gateway comparison UK guide to evaluate hosted checkout, embedded payment components, APIs, plug-ins, payment links, digital wallets, local payment methods, recurring-payment support, Strong Customer Authentication, 3D Secure, tokenisation, fraud tools, uptime, webhooks, reporting, developer support, data portability and complete gateway cost. Give every shortlisted provider the same checkout, market, transaction and technical requirements.

An online payment gateway securely captures payment details, applies authentication and fraud controls, sends the transaction for authorisation, and returns the result to a website or app. UK businesses should compare checkout experience, integration, payment methods, 3D Secure, tokenisation, reliability, reporting, support, portability and full gateway cost before selecting a provider.
Separate The Gateway From The Acquiring Agreement
A payment gateway controls the digital checkout and transaction-message flow. The merchant acquirer or payment processor handles authorisation routing, card-scheme processing and settlement. A single provider may supply both layers, but the responsibilities, pricing and contracts still need to be identified separately.
- Define the checkout and integration model first
- Identify the gateway, processor and acquirer behind the service
- Keep gateway fees separate from acquiring charges
- Document data, token and migration ownership before launch
The gateway is the online technology layer that connects a customer-facing checkout to payment processing services. It can provide hosted payment pages, embedded fields, APIs, software plug-ins, payment links, payment-method presentation, tokenisation, Strong Customer Authentication, 3D Secure, fraud rules, webhooks, reporting and operational controls.
This page evaluates online checkout and gateway capability. It does not compare physical card-payment equipment or EPOS functionality. It also avoids duplicating the detailed underwriting, reserve, settlement and merchant-acquiring analysis covered on the merchant accounts comparison page.
A buyer should nevertheless identify every provider in the transaction chain. Some gateway brands bundle acquiring and processing, while others can connect to more than one acquirer. The integration may also involve an ecommerce platform, subscription system, marketplace, fraud vendor or payment orchestrator. Contract ownership and incident responsibility must remain clear across the complete chain.
Choose The Right Online Payment Integration
The integration model affects checkout control, development effort, PCI DSS scope, conversion testing, resilience and the cost of switching later.
| Gateway Model | What It Usually Provides | Best-Fit Question |
|---|---|---|
| Hosted redirect checkout | The customer moves to a provider-hosted payment page and returns after payment | Does fast deployment and reduced handling of card data outweigh reduced checkout control? |
| Hosted fields or embedded components | Provider-controlled payment fields are embedded within the merchant’s checkout design | Can the business maintain brand continuity while keeping sensitive payment fields with the provider? |
| API or headless integration | The merchant builds a custom web or app experience using payment APIs, SDKs and webhooks | Does the team have the engineering, security, monitoring and release capability to own the integration? |
| Ecommerce-platform plug-in | A supported extension connects the gateway to platforms such as WooCommerce, Adobe Commerce, BigCommerce or other carts | Is the plug-in actively maintained, compatible with the current platform version and supported during incidents? |
| Payment links and hosted requests | The business creates secure links that open a provider-hosted checkout without a full website integration | Are links, expiry, partial payment, customer references, branding, refunds and reconciliation suitable? |
| Recurring and tokenised gateway | Credentials are tokenised for subscriptions, repeat purchases and merchant-initiated transactions | Can tokens, customer consent, account updates and recurring-payment events be managed and migrated safely? |
| Marketplace or platform payments | The gateway supports connected sellers, split payments, onboarding, sub-merchant controls and platform reporting | Are regulatory, safeguarding, onboarding, payout and liability responsibilities suitable for the platform model? |
| Payment orchestration or multi-provider routing | A routing layer connects more than one payment service provider or acquirer and applies routing and retry logic | Will the additional control improve resilience and acceptance enough to justify complexity and cost? |
Eight Areas That Determine Payment Gateway Fit
Use the same checkout journeys, transaction profile, countries, payment methods, technical stack and service expectations for every provider.
Comparison Criterion
Checkout Experience And Integration Control
Compare hosted pages, embedded components, APIs, SDKs, mobile support, payment links, plug-ins, accessibility, localisation, saved details, guest checkout, error handling and custom branding. Test the complete path on desktop and mobile, including validation, authentication, decline, retry and return journeys.
Comparison Criterion
Payment Methods, Countries And Currencies
Assess cards, digital wallets, local methods, instalments, bank-based methods, recurring payments, supported countries, presentment currencies and localised checkout. Prioritise methods justified by customer demand rather than enabling a long list that increases operational and reconciliation complexity.
Comparison Criterion
Strong Customer Authentication And 3D Secure
Review 3D Secure 2 support, exemptions, challenge flows, soft-decline recovery, out-of-scope handling, recurring-payment setup, merchant-initiated transactions and reporting. The objective is compliant authentication with controlled friction, not simply forcing every transaction through the same challenge.
Comparison Criterion
Tokenisation, Saved Payments And Recurring Billing
Compare gateway tokens, network tokens where supported, customer vaults, card updates, subscription events, consent records, credential-on-file indicators, account updater services and token portability. Confirm whether token data can be transferred or forwarded during a provider change.
Comparison Criterion
Fraud Controls And False-Decline Management
Evaluate rules, scoring, device and behavioural signals, velocity checks, allow and block lists, manual review, machine-learning tools, authentication strategy, custom fields, alerts and decision explanations. Measure fraud reduction alongside false declines, checkout abandonment and review workload.
Comparison Criterion
Reliability, Latency And Transaction Recovery
Review published status history, service levels, regional architecture, maintenance, timeout behaviour, idempotency, retries, webhook delivery, queueing, duplicate prevention, failover and incident communications. Test what the application does when the gateway is slow, unavailable or returns an uncertain result.
Comparison Criterion
Reporting, Webhooks And Operational Visibility
Compare transaction search, event timelines, response codes, authentication results, fraud decisions, payment-method detail, refunds, exports, user permissions, audit logs, webhooks and API reporting. Finance, support and engineering teams should be able to investigate one payment without switching between disconnected systems.
Comparison Criterion
Support, Contract, Data Ownership And Exit
Review implementation help, support hours, severity definitions, response targets, named contacts, change notices, version support, data retention, token ownership, export, forwarding services, termination, transition assistance and post-closure access. A technically strong gateway can still create lock-in if migration rights are weak.
Measures To Define Before A Gateway Is Selected
Convert claims about conversion, security and performance into measures that can be tested before launch and monitored afterwards.
| Measure | What It Should Define | Evidence To Request | Common Weakness |
|---|---|---|---|
| Checkout completion | The percentage of eligible checkout sessions that produce a confirmed payment | Device, browser, market, payment method, authentication, error and abandonment stage | A single conversion rate mixes traffic quality, checkout design and payment performance |
| Authorisation success | The percentage of submitted payment attempts approved by the issuer or payment method | Issuer response, payment method, country, card type, 3DS result, retry and routing | Provider claims exclude failed integrations, technical declines or selected markets |
| Authentication performance | The proportion of payments frictionlessly authenticated, challenged, exempted or failed | 3DS version, exemption, challenge, abandonment, soft decline, retry and final outcome | A low challenge rate is presented without showing fraud or issuer-decline effects |
| Gateway latency | The time taken for gateway requests and key checkout components to respond | Median, 95th and 99th percentile, region, endpoint, payment method and peak period | An average hides slow requests that damage the customer experience |
| Service availability | The percentage of time that required checkout, API, webhook and portal functions are available | Status history, incident reports, maintenance, exclusions, region and service-level method | One platform-wide uptime figure excludes critical components or planned maintenance |
| Webhook reliability | Whether payment events reach the merchant application completely, once, in order where required, and within target time | Delivery attempts, signature, retry schedule, duplicate handling, dead-letter process and replay | The integration treats a browser return page as the final payment record |
| Fraud effectiveness | Fraud prevented relative to accepted genuine payments and manual-review effort | Fraud loss, false-positive rate, review rate, decision reason, rule result and authentication | A fraud-block figure is quoted without measuring good customers incorrectly declined |
| Token coverage and portability | Which stored credentials, network tokens and customer references remain usable or transferable | Token type, owner, lifecycle, update service, export, forwarding, consent and migration route | The business discovers during exit that gateway tokens cannot be moved |
| Operational investigation time | How quickly support or finance can explain the status and history of one payment | Search fields, event timeline, response codes, user access, logs, exports and retention | Critical details exist only in developer logs or separate provider portals |
| Change and incident response | How quickly defects, security issues, API changes and provider incidents are detected and controlled | Severity, acknowledgement, workaround, recovery, root cause, notice and remediation tracking | Support response targets do not include restoration or engineering escalation |
Online Payment Gateway Providers UK Businesses Can Consider
Shortlist providers whose checkout model, payment methods, integration, authentication, risk controls, service operations and commercial structure fit the business. Confirm current products, eligibility, regulated entities and complete terms directly before award.
Provider Profile
Stripe
Stripe provides hosted Checkout, embedded payment elements, APIs, SDKs, payment links, wallets, local payment methods, tokenisation, recurring-payment tools and fraud services. Include it where a business wants developer-led integration, rapid access to a broad payments platform or a hosted checkout that can be deployed with less custom code. Confirm the UK contracting entity, standard or custom pricing, payment-method coverage, authentication handling, Radar configuration, Billing charges, Connect requirements, payout and acquiring components, data location, support level, API-version policy, token portability, account closure and any separate product fees.
Review official Stripe PaymentsProvider Profile
Worldpay eCommerce
Worldpay provides online payment acceptance through hosted and integrated checkout options, payment links, fraud tools, multiple payment methods and international currency support. Include it where an SME or larger merchant wants an established UK-facing provider with online-payment onboarding and a path to broader processing capability. Confirm the exact Worldpay product and legal entity, gateway and acquiring contracts, integration type, supported plug-ins, currencies, alternative methods, 3D Secure, token services, fraud settings, service levels, portal and reporting, pricing, technical change process, migration support and how the service relates to other companies in the Global Payments group.
Review official Worldpay online paymentsProvider Profile
Adyen
Adyen combines gateway, processing and acquiring capabilities within one platform and supports hosted or component-based web payments, APIs, local payment methods, recurring payments, tokenisation, risk tools and global reporting. Include it where a larger or internationally active business wants one technical platform across markets and channels. Confirm eligibility, implementation model, minimum commercial commitment, payment-method contracts, interchange-plus structure, acquiring countries, authentication optimisation, RevenueProtect configuration, token ownership, platform or marketplace requirements, settlement and finance integration, service governance, regional resilience, data access and exit arrangements.
Review official Adyen online paymentsProvider Profile
Checkout.com
Checkout.com provides online-payment APIs, hosted and embedded checkout options, payment links, multiple payment methods, tokenisation, authentication, fraud and performance tooling for digital businesses. Include it where a growing or enterprise merchant wants a customisable integration and international online-payment capability. Confirm the UK contracting and regulated entities, acquiring coverage, pricing, supported methods and markets, Frames or Flow integration, 3D Secure, fraud product configuration, network-token support, recurring-payment controls, webhook design, reporting, service levels, implementation resources, data protection, token migration, platform services and termination assistance.
Review official Checkout.com online paymentsProvider Profile
Opayo by Elavon
Elavon offers Opayo as an all-in-one gateway and online-payments option with hosted payment pages, API integration, payment links and fraud-management support. Include it where a UK SME wants a recognisable gateway proposition, established ecommerce plug-ins and access to Elavon acquiring where suitable. Confirm whether the quote is gateway-only or bundled, the Elavon entity, integration route, plug-in maintenance, included transaction allowance, additional charges, 3D Secure, token and recurring-payment functions, fraud tools, PCI responsibilities, support, portal reporting, availability commitments, contract term, rate changes, data export and migration from any legacy Opayo configuration.
Review official Elavon online paymentsProvider Profile
Trust Payments
Trust Payments provides online payment pages, APIs, mobile and wallet acceptance, payment links, fraud controls and acquiring services. Include it where a merchant wants a UK-focused payments partner with configurable gateway technology, international capability or a combined gateway and acquiring proposition. Confirm the contracting and regulated entity, gateway-only or full-service scope, integration model, payment methods, currencies, 3D Secure, tokenisation, fraud rules, manual review, PCI support, account-reference ownership, reporting, webhook behaviour, uptime and incident support, pricing, minimum term, implementation responsibilities, data retention and transition support.
Review official Trust Payments online gatewayProvider Profile
PayPal Checkout And Braintree
PayPal offers branded PayPal checkout, card and wallet acceptance, payment links and enterprise payment processing, while Braintree provides developer-focused gateway and payment services within the PayPal group. Include the proposition where customer demand for PayPal is material or where a business wants PayPal and card methods through one integration. Confirm which PayPal or Braintree product is proposed, guest-card availability, checkout customisation, pricing, payment-method eligibility, 3D Secure, fraud and Seller Protection conditions, recurring payments, Fastlane availability, token and vault ownership, reporting, account holds, support, data export, migration and the legal entity supplying each service.
Review official PayPal CheckoutProvider Profile
Revolut Business Payment Gateway
Revolut Business provides a payment gateway with hosted, pop-up, embedded and API integration options, one-off and subscription payments, digital wallets and business-account connectivity. Include it where an eligible business wants online payments and business financial operations within the wider Revolut Business environment. Confirm eligibility, required business account, legal and regulated entities, accepted cards and payment methods, supported countries and currencies, pricing, 3D Secure and exemptions, fraud support, settlement and account dependency, plug-in maintenance, API limits, uptime commitments, reporting, chargeback support, token ownership, data export, account restrictions and the effect of ending the wider business relationship.
Review official Revolut Payment GatewayWhat Changes Online Payment Gateway Cost
Gateway pricing may be bundled into payment processing or charged separately. Compare the complete annual technology and transaction cost, then keep acquiring charges identifiable.
| Cost Driver | Why It Changes Spend | What A Comparable Quote Should Show |
|---|---|---|
| Gateway subscription or minimum | Some services charge a monthly platform fee, minimum transaction commitment or included allowance | Monthly fee, included transactions, overage, VAT, minimum, annual total and cancellation treatment |
| Per-transaction gateway fee | A fixed charge may apply for authorisation attempts, successful payments or gateway use | Fee trigger, successful and failed attempts, refunds, reversals, retries, verification and volume tiers |
| Bundled payment-processing rate | Full-stack providers can combine gateway, processing, acquiring and payment-method costs | Each component, card and method categories, fixed fee, percentage, cross-border cost and provider margin |
| Integration and implementation | Custom APIs, migrations, plug-ins, mobile apps, testing and security work create project cost | Provider setup, internal engineering, agency work, certification, test environments, project support and change budget |
| Payment methods and wallets | Local methods, wallets, instalments and alternative methods can have different charges and commercial contracts | Method, country, currency, provider fee, third-party fee, refund treatment, dispute treatment and settlement route |
| 3D Secure and authentication | Authentication requests, exemption tools or optimisation products may be included or separately priced | 3DS fee, exemption service, challenge handling, soft-decline retry, reporting and liability treatment |
| Fraud and risk services | Advanced scoring, custom rules, device signals, alerts and manual review can add transaction or subscription fees | Included controls, premium product, per-screening fee, review fee, data retention and internal review effort |
| Tokenisation and recurring payments | Vaulting, network tokens, billing platforms, account updater and subscription features can carry separate charges | Token fee, storage, update service, recurring engine, retries, invoices, migration and forwarding |
| International and currency capability | Presentment, settlement, cross-border processing and conversion can affect both gateway and acquiring cost | Currency list, FX margin, cross-border fee, local acquiring, payment method, conversion owner and reporting |
| Support, resilience and exit | Premium support, service levels, additional environments, orchestration, data export and migration assistance may cost more | Support tier, response, service credit, environment, routing, export, token transfer, termination and transition charge |
How Checkout Complexity Changes The Shortlist
The right gateway depends on technical capability, sales model, customer geography, payment methods, recurring requirements, risk and the cost of operational ownership.
New Or Low-Complexity Online Seller
Prioritise a hosted checkout or maintained plug-in, clear pay-as-you-go pricing, straightforward onboarding, digital wallets, standard reporting, understandable PCI validation and responsive setup support. Avoid custom development that the business cannot maintain.
Growing Ecommerce Business
Prioritise mobile checkout, local methods justified by customer data, tokenised repeat payments, conversion reporting, fraud controls, reliable webhooks, platform compatibility, stronger support and a migration path that will remain workable as order volume increases.
Subscription Or SaaS Business
Prioritise credential-on-file controls, recurring authentication, merchant-initiated transactions, network tokens where relevant, account updater, retry logic, subscription events, customer self-service, invoice integration, lifecycle reporting and token portability.
International Or Enterprise Platform
Prioritise local acquiring and methods, multi-currency checkout, orchestration, regional resilience, advanced authentication and fraud, granular permissions, data warehouse integration, service governance, contract transparency, platform capabilities and controlled multi-provider exit.
How To Compare Payment Gateway Proposals
Give every provider the same website or application architecture, countries, currencies, payment methods, transaction counts, average value, recurring-payment profile, authentication needs, fraud controls, reporting, availability and support requirements. Require one standardised response.
- The gateway, processor, acquirer and other service providers are identified
- The same checkout journeys and integration model are priced
- Payment methods and country eligibility are confirmed in writing
- PCI DSS and Strong Customer Authentication responsibilities are mapped
- Reliability, webhooks, support and incident procedures are testable
- Token, data, contract and migration rights are documented before launch
Make Every Provider Test The Same Checkout Journey
Use the same device, browser, payment method, authentication, failure, retry, refund and recurring-payment scenarios.
Compare customer experience, operational control and complete annual cost before comparing one headline rate.
Six Questions To Put To Every Gateway Provider
The answers expose unclear transaction chains, incomplete integrations, security gaps, weak service commitments and costly lock-in.
Which Legal Entities And Payment Layers Are Included?
Request the gateway, processor, acquirer, payment facilitator, fraud provider, subcontractors, regulated entities, contracts, support owner and complaint route.
Which Checkout And Integration Will We Operate?
Confirm hosted, embedded, API, mobile, plug-in and payment-link options, ownership, updates, browser support, accessibility, testing and PCI implications.
Which Payment Methods And Markets Are Live For Us?
Confirm eligibility, onboarding, countries, currencies, local methods, wallets, recurring use, refunds, disputes, settlement dependencies and launch dates.
How Are Authentication And Fraud Decisions Controlled?
Review 3D Secure, exemptions, soft declines, recurring payments, rules, scoring, manual review, false positives, liability, reporting and change authority.
What Happens During Failure Or An Incident?
Confirm uptime method, status communication, API timeouts, idempotency, retries, webhook recovery, failover, severity, escalation, restoration and root-cause reporting.
Can We Move Our Data And Tokens?
Confirm token ownership, export, forwarding, network tokens, customer references, consent, retention, notice, transition support, fees and post-closure access.
A Seven-Stage Payment Gateway Evaluation
Move from measured checkout requirements to controlled implementation and ongoing payment operations rather than choosing a provider from a plug-in list or rate card alone.
- Collect current checkout data, payment methods, authorisation outcomes, authentication, fraud, incidents, support cases, integration diagrams, contracts, PCI status and accountable owners.
- Define target customer journeys, countries, currencies, recurring requirements, accessibility, performance, availability, reporting, security, data and support requirements.
- Choose the preferred integration model and map the gateway, processor, acquirer, ecommerce platform, fraud services, subscription system and internal applications.
- Issue one written requirements pack and obtain comparable provider responses covering functionality, legal entities, architecture, implementation, security, service levels, pricing and exit.
- Run sandbox and proof-of-concept testing across successful, declined, challenged, abandoned, duplicated, timed-out, refunded, webhook, recurring and incident scenarios.
- Contract only after data processing, PCI scope, SCA, token ownership, service support, pricing, change control, incident response, migration and termination provisions are accepted.
- Launch through controlled cutover, monitoring, reconciliation, fraud review, authentication optimisation, release management, incident testing, provider reviews and a maintained exit plan.
Online Payment Gateway Comparison Checklist
Use this table before approving a hosted checkout, embedded integration, API gateway, recurring-payment service, platform solution or provider migration.
| No. | Requirement | Evidence To Obtain Before Award | Confirmed |
|---|---|---|---|
| 01 | Online-payment scope and owners agreed | Business owner, product, engineering, security, finance, fraud, support, data protection and approver | |
| 02 | Current transaction chain mapped | Gateway, processor, acquirer, platform, fraud, subscription, data flows, contracts and support | |
| 03 | Customer journeys documented | Device, browser, market, payment method, guest, saved, recurring, authentication, decline and retry | |
| 04 | Integration model approved | Hosted, embedded, API, SDK, plug-in, mobile, payment links, ownership, testing and update route | |
| 05 | Payment methods and markets confirmed | Cards, wallets, local methods, countries, currencies, eligibility, recurring use and launch timetable | |
| 06 | SCA and 3D Secure design accepted | 3DS2, exemptions, challenge, soft decline, recurring setup, MIT, reporting and liability | |
| 07 | PCI DSS responsibilities mapped | Data flow, SAQ or ROC route, hosted fields, scripts, vulnerability controls, provider evidence and renewal | |
| 08 | Token and recurring-payment controls agreed | Gateway token, network token, consent, updater, retries, lifecycle, export, forwarding and migration | |
| 09 | Fraud-control outcomes defined | Rules, scoring, signals, manual review, fraud loss, false positives, authority and reporting | |
| 10 | Reliability and recovery tested | Latency, uptime, timeout, idempotency, retries, webhooks, failover, status and incident procedure | |
| 11 | Reporting and access validated | Transaction timeline, response codes, 3DS, fraud, refunds, exports, APIs, users, MFA and audit logs | |
| 12 | Data protection and processor terms accepted | Roles, contract, subprocessors, transfers, retention, security, breach notification and deletion | |
| 13 | Support and change governance approved | Hours, severity, response, restoration, escalation, status, API versions, notice and service review | |
| 14 | Complete annual cost compared | Gateway, transactions, methods, authentication, fraud, tokens, support, implementation, monitoring and tax | |
| 15 | Migration and exit plan agreed | Notice, dual running, tokens, data, recurring payments, webhooks, refunds, access, transition and deletion |
Common Online Payment Gateway Buying Mistakes
Most avoidable failures begin with an integration chosen too early, incomplete security ownership, weak incident testing or no workable token-migration route.
| Mistake | Why It Creates Risk | Better Control |
|---|---|---|
| Choosing from the ecommerce plug-in list alone | A plug-in can be available but poorly maintained, limited or unsuitable for the required checkout | Evaluate the underlying gateway and support |
| Comparing one transaction rate | The figure may combine or exclude gateway, processing, authentication, fraud and payment-method costs | Build a complete annual model |
| Assuming hosted checkout removes all PCI duties | The merchant still controls its website, scripts, access, provider oversight and validation route | Map the real PCI scope |
| Enabling every payment method | Extra methods create operational, refund, dispute, reporting and customer-support complexity | Use customer and market evidence |
| Ignoring failed and uncertain transactions | Timeouts and duplicate retries can create lost orders, duplicate payments or manual investigation | Test idempotency and webhook recovery |
| Optimising fraud without measuring false declines | Strict rules can block genuine customers and damage conversion | Track fraud and good-customer outcomes |
| Relying on browser return pages as payment truth | Customers can close the browser or redirects can fail after a completed payment | Use signed server-side events and reconciliation |
| Not testing 3D Secure edge cases | Soft declines, failed challenges and recurring-payment setup can break checkout | Run full authentication scenarios |
| Leaving token ownership until contract exit | Saved cards and subscriptions can become difficult to migrate | Agree export and forwarding before launch |
| Launching without an outage playbook | Teams cannot distinguish provider failure, issuer decline or integration defects | Define monitoring, escalation and fallback |
Frequently Asked Questions
Answers to common questions from UK businesses comparing hosted checkout, embedded fields, payment APIs, plug-ins and full-stack online-payment providers.
What Is An Online Payment Gateway?
An online payment gateway is the technology layer that securely captures payment details from a website or app, applies required checks, sends the payment request into the processing chain and returns an authorisation result. It can also provide hosted checkout, tokenisation, 3D Secure, fraud controls, payment methods, webhooks and reporting.
Is A Payment Gateway The Same As A Merchant Account?
No. The gateway manages the online checkout and transaction-message flow. A merchant account is the acquiring arrangement used to process card transactions and settle funds. Some providers supply both services in one package, but buyers should still identify each layer, legal entity, fee and contract.
Which Payment Gateway Integration Is Best For A Small Business?
A maintained ecommerce plug-in, hosted payment page or embedded provider component is often practical for a smaller business because it can reduce development effort. The correct choice depends on platform compatibility, checkout control, payment methods, PCI scope, support, cost and the business’s ability to maintain custom code.
How Much Does An Online Payment Gateway Cost?
Cost can include a monthly gateway fee, per-transaction charge, bundled processing rate, setup, payment-method charges, 3D Secure, fraud tools, token services, recurring billing, premium support and integration work. Compare a full twelve-month scenario and separate gateway technology from acquiring and payment-method costs.
Does A Hosted Payment Page Remove PCI DSS Responsibility?
No. Outsourcing payment fields can reduce the number of systems handling card data and may simplify validation, but the merchant still has responsibilities for its website, access, scripts, provider oversight, policies and the correct PCI DSS validation route. Confirm the exact data flow and eligibility with the acquirer or qualified adviser.
What Is Strong Customer Authentication For Online Payments?
Strong Customer Authentication is a security requirement that can require customers to authenticate an electronic payment using independent factors. Online card payments commonly use 3D Secure 2. The gateway should support challenges, exemptions, soft-decline recovery, recurring-payment setup and clear authentication reporting.
Why Are Tokens Important When Comparing Gateways?
Tokens replace stored payment credentials with provider or network references used for repeat and recurring payments. Buyers should confirm token type, ownership, lifecycle, account updater, consent, network-token support, export and forwarding. Weak portability can make subscriptions and saved cards difficult to migrate.
How Should A Business Compare Gateway Reliability?
Review status history, availability definitions, latency percentiles, maintenance, regional resilience, timeout behaviour, idempotency, webhook retries, incident communications and support escalation. Test failed and uncertain transactions in a sandbox or proof of concept rather than relying only on a headline uptime figure.
Can A Business Use More Than One Payment Gateway?
Yes. Larger businesses sometimes use payment orchestration or direct integrations to more than one provider for resilience, local coverage or routing. The benefits must be balanced against extra integration, reconciliation, fraud, token, support and governance complexity. A clear source of payment truth is essential.
How Should A UK Business Compare Payment Gateway Providers?
Give every provider the same checkout journeys, markets, payment methods, transaction profile, recurring requirements, security, reliability, reporting and support needs. Compare integration, authentication, tokenisation, fraud outcomes, operational evidence, complete cost, data ownership and migration rights—not only a transaction percentage.
Official Guidance And Online-Payment Resources
Reviewed by Bhav Giva, Founder & Lead Analyst at CompareServices.co.uk, on 29 July 2026.
Use the FCA, UK legislation, PCI Security Standards Council, Information Commissioner’s Office and official provider documentation to confirm current authentication, security, data-protection, product, pricing, eligibility and contract requirements. Provider features, legal entities and commercial terms can change.
- Financial Conduct Authority — Strong Customer Authentication
- UK Legislation — Payment Services Regulations 2017
- PCI Security Standards Council — Merchant Resources
- PCI Security Standards Council — PCI DSS Standards
- Information Commissioner’s Office — Guide To Data Security
- Stripe — Payments
- Worldpay — Online Payments
- Adyen — Online Payments
- Checkout.com — Accept Online Payments
- Elavon — Opayo And Online Payments
- Trust Payments — Online Payment Gateway
- PayPal — Online Checkout
- Revolut Business — Payment Gateway
