Back to the library
Payment Processing
2026-07-24 9 min read

What Is a Payment Gateway? (And How It Differs From a Processor)

A payment gateway encrypts and routes card data. A processor moves the money. Here is the real difference, and why merchants confuse the two.

GM

By Gray Merchants Team

what is a payment gatewaypayment gateway vs processortokenizationPCI compliancepayment facilitator
What Is a Payment Gateway? (And How It Differs From a Processor)
Key takeaways
  • A payment gateway encrypts and routes transaction data at checkout; a payment processor is what actually moves money through authorization, clearing, and settlement. They're different systems often sold under one bundled product.
  • A fully-hosted payment page can qualify a merchant for SAQ A, the narrowest PCI DSS tier, because cardholder data never touches the merchant's own servers, and the PCI Council removed three requirements from that path in 2025.
  • Tokenization replaces the actual card number with a meaningless token before it goes anywhere else, so a data breach downstream exposes nothing usable.
  • A payment facilitator (PayFac) pools many businesses under one master merchant account for fast onboarding, but shares risk across all sub-merchants, unlike a standalone gateway paired with a dedicated merchant account underwritten to one business.
  • US e-commerce sales hit $1,233.7 billion in 2025, and global card transactions reached 776 billion in 2024 on track for 1.1 trillion by 2029, meaning gateway reliability and scale matter more every year.

So what is a payment gateway? It's the technology that captures a card payment at checkout, encrypts it, and routes it to the payment processor for approval. Think of it as the digital equivalent of a physical card terminal. It doesn't move money and it doesn't hold funds. It just gets the transaction data safely from your customer's card to the systems that decide whether the payment goes through.

Payment Gateway vs. Payment Processor: The Difference That Confuses Everyone

These two terms get used interchangeably constantly, and it causes real confusion when merchants shop for a provider. Here's the actual split.

A payment gateway captures the transaction at the point of sale, whether that's a checkout page, an app, or a physical terminal. It encrypts the card data and passes it along. That's it. The gateway's job ends once the data is safely in transit.

A payment processor is what happens next. It's the infrastructure that submits the transaction to the card network, gets a response from the card-issuing bank, and handles the actual movement of funds through authorization, clearing, and settlement, the three formal stages every card transaction goes through under the card networks' own rules (Visa Core Rules and Visa Product and Service Rules, 2026 edition).

A lot of providers bundle both functions under one product name, which is exactly why the terms blur together in practice. But structurally, they're different jobs: one moves data, the other moves money.

Where the Merchant Account Fits In

Neither the gateway nor the processor is where your money actually lands. That's the merchant account, the banking relationship with an acquiring bank that holds the settled funds before they transfer to your regular business account. A gateway without a merchant account behind it can't actually get you paid. It's just the front door. The processor and acquiring bank are what make the transaction real.

How a Transaction Actually Moves Through the System

  1. Capture. The gateway collects card data at checkout and encrypts it immediately.
  2. Authorization request. The gateway sends the encrypted data to the payment processor, which forwards it to the card network and on to the card-issuing bank.
  3. Approval or decline. The issuing bank checks the account and responds in real time, and that response travels back through the same chain to the gateway.
  4. Clearing. Approved transactions get batched. The acquirer delivers final transaction data to the issuer through the card network.
  5. Settlement. The net financial position transfers between the issuing and acquiring banks, and funds land in the merchant account, typically the next business day or faster.

That whole sequence usually takes a second or two from the customer's perspective, even though it touches four or five separate systems.

Why Tokenization Matters More Than It Sounds Like It Should

A gateway's most important security job is tokenization: replacing the actual card number with a random, meaningless token before the data goes anywhere else. Visa describes it directly: a token is a secure equivalent of sensitive account data, and it carries no usable value on its own if it's ever intercepted (Visa). If a database gets breached, tokens are useless to whoever stole them. The actual card number never left the gateway's secure environment in the first place.

This is also why a merchant's own systems stay cleaner from a compliance standpoint. If the raw card number never touches your servers, your PCI DSS burden drops significantly.

Why This Cuts Your PCI Compliance Burden

This is one of the most underrated reasons to use a gateway-hosted checkout instead of building your own payment form. A fully-hosted payment page, where the customer enters card details directly into a page served by the gateway, not your own site, can qualify a merchant for SAQ A, the narrowest and lowest-burden PCI DSS self-assessment tier (PCI Security Standards Council, 2025).

The PCI Council tightened this further in early 2025: as of the effective date in that year, merchants using a fully-outsourced hosted payment page had three specific requirements (6.4.3, 11.6.1, and 12.3.1) removed from their SAQ A obligations entirely, replacing a more complex eligibility test with a simpler confirmation that the site isn't vulnerable to script-based attacks (PCI Security Standards Council, 2025). A hosted payment page that keeps card data off your servers entirely is the most direct way to take advantage of that scope reduction.

Payment Gateway vs. Payment Facilitator (PayFac): A Different Kind of Confusion

A payment facilitator is a different structure entirely, and it's worth separating from a standard gateway setup. A PayFac is a registered sub-merchant aggregator, sponsored by an acquiring bank, that lets many small businesses process under one master merchant account instead of each one holding its own dedicated account (Visa Payment Facilitator and Marketplace Risk Guide). Onboarding is fast because there's no individual underwriting per business. The tradeoff is that a PayFac's sub-merchants share the aggregator's overall risk tolerance, which is why aggregator accounts freeze faster during a dispute spike than a business processing under its own dedicated merchant account.

A standalone gateway paired with a dedicated merchant account works differently. The gateway only handles routing and encryption. The merchant account is underwritten specifically to that one business. That structure costs more setup effort upfront but gives a business its own risk profile instead of sharing one with every other merchant on a shared platform.

Why This Scale Matters for Choosing a Gateway

The volume behind all of this is real and growing. US retail e-commerce sales hit $1,233.7 billion in 2025, up 5.4% from the year before, and made up 16.4% of all retail sales (US Census Bureau, 2026). Fourth quarter 2025 alone saw $316.1 billion in e-commerce sales, a 5.3% jump over the same quarter the year before (US Census Bureau, 2026). Globally, card transactions hit 776 billion in 2024 and are projected to grow 43% to top 1.1 trillion annually by 2029 (The Nilson Report, 2025). A gateway built to handle that kind of volume reliably, with uptime and fraud tools that scale, is a different product than one built for a low-volume storefront.

What to Actually Check Before Choosing a Gateway

Does it support tokenization and a fully-hosted checkout option, for the PCI scope reduction described above? Does it integrate with the specific processor and acquiring bank your merchant account runs on, since not every gateway connects to every acquirer? What's the actual uptime history, since a gateway outage during a sales spike costs real revenue? And critically for a high-risk merchant account, does the gateway support the acquirer's specific underwriting and monitoring requirements for your industry, since a generic low-risk gateway setup often can't handle a high-risk account's reserve or reporting needs.

Frequently Asked Questions

Can I use any payment gateway with any merchant account?

Not always. Gateways connect to specific processors and acquiring banks. Confirm compatibility before committing to either one, especially for a high-risk merchant account, where the acquirer often requires a gateway it already has an established integration with.

Does a payment gateway cost extra on top of processing fees?

Usually, yes. Most gateways charge a separate monthly or per-transaction fee on top of whatever the processor and acquiring bank charge for actually moving the money.

Is a hosted payment page less flexible than a custom checkout?

It can look and feel more limited in styling options, but the tradeoff is a meaningfully lower PCI compliance burden, since cardholder data never touches your own servers.

What's the difference between a gateway and a virtual terminal?

A gateway processes online or app-based transactions automatically at checkout. A virtual terminal lets staff manually key in a card number for a phone or mail order sale, using many of the same underlying gateway and processor infrastructure.

Do I need a payment gateway if I only sell in person?

Usually not for basic card-present sales through a physical terminal, since the terminal itself typically handles that role. A gateway becomes necessary the moment a business adds online, phone, or app-based payments.

Why do some gateways decline high-risk businesses outright?

Many mainstream gateways are built around low-risk retail assumptions and simply aren't configured to support the underwriting, reserve structures, or monitoring that high-risk merchant accounts require, which is why a dedicated high-risk provider typically pairs its own vetted gateway options with the account.

Setting up a new merchant account and need a gateway that actually supports your industry? Apply free for a 24 to 48 hour decision, or talk to a specialist about which gateway fits your specific setup.

GM

Gray Merchants Team

Gray Merchants is a payment ISO that places merchant accounts across every risk level — from low-risk retail and e-commerce to 67+ high-risk verticals. The editorial team writes on high-risk merchant accounts, chargeback defense, MATCH/TMF remediation, and ACH processing — whether you are new, scaling, switching processors, or rebuilding after a decline.

Talk to a specialist

Tell us about your business

Share a few details and a specialist reviews your industry, volume, and processing history, then comes back with the right path — no obligation.

  • Underwriting decision in 24–48 hours
  • $0 setup fee, dedicated MID
  • Specialist replies within 4 business hours
  • Every term disclosed in writing before you sign

Request a call from a specialist

Are you currently processing?

No obligation. A specialist replies within 4 business hours, Mon–Fri 9:00–18:00 EST.

What Is a Payment Gateway? (And How It Differs From a Processor) | Gray Merchants