Exclusive Rates From as Low as 0.26%
Choosing between a hosted payment gateway and a self-hosted (or fully integrated) solution is one of the most consequential technical decisions a UK business makes when setting up online payments. The right choice depends on your PCI DSS appetite, in-house development resources, and how much control you need over the checkout experience, with hosted pages offering simplicity and reduced compliance burden, while self-hosted integrations offer a seamless brand experience at the cost of greater technical and regulatory responsibility. This guide breaks down the practical differences so you can make a confident, informed decision for your business.
Key Takeaways
- Hosted payment pages qualify for the simplest PCI DSS self-assessment questionnaire (SAQ A), cutting compliance work to a fraction of what self-hosted requires.
- Self-hosted gateways typically require SAQ D, the most demanding PCI compliance level, involving hundreds of security controls.
- Hosted checkouts can see conversion drop by 5-15% due to the redirect and loss of brand continuity, though this gap is narrowing with modern hosted UI.
- Hosted fields (an iframe-based middle option) let you keep customers on your own page while still avoiding card data touching your servers, often qualifying for SAQ A-EP.
- Most UK SMEs processing under £1 million annually are better served by hosted or hosted-fields solutions, given limited in-house security resources.
- Larger businesses with dedicated development and security teams often justify self-hosted integrations for full checkout control and advanced customisation.
- Providers like Stripe, Worldpay, Opayo (formerly Sage Pay), and Checkout.com all offer hosted, hosted-fields, and fully integrated APIs, so the choice is rarely about provider limitation.
What Is a Hosted Payment Gateway?
A hosted payment gateway works by redirecting the customer away from your website to a secure page controlled entirely by your payment provider. The customer enters their card details on the provider's domain, the transaction is processed, and they are then redirected back to your site to see an order confirmation. Because your servers never receive, transmit, or store cardholder data, the PCI DSS compliance burden on your business is dramatically reduced.
How the Redirect Flow Works
When a customer clicks "pay now" on your checkout, they are sent (via a browser redirect or a pop-up) to a URL hosted by your payment provider, such as Stripe Checkout, Opayo's Payment Pages, or Worldpay's Hosted Payment Page. This page is styled to varying degrees to match your branding, colours, and logo, but it always sits on the provider's domain and infrastructure. Once payment is authorised, the customer is returned to a success or failure URL on your own site.
Why Hosted Pages Simplify Compliance
Because your servers are never in the payment data path, hosted gateways typically qualify for SAQ A, the shortest PCI DSS self-assessment questionnaire, covering as few as 22 questions. This is a major advantage for small and medium UK businesses that lack dedicated IT security staff. For more background on how PCI requirements interact with your gateway choice, see our guide to secure payment gateways.
What Is a Self-Hosted (Fully Integrated) Payment Gateway?
A self-hosted, or fully integrated, payment gateway means the card entry form itself is built and rendered on your own website, with the raw card data passing through your servers (or at minimum your front-end code) before being sent to the payment processor via API. This gives you complete control over the look, feel, and flow of checkout, but it also means your business takes on significant PCI DSS responsibility.
Direct API Integration
With a self-hosted approach, developers use the gateway's API (such as those provided by Worldpay, Checkout.com, or Braintree) to build a custom payment form. Card details are captured directly by your code and transmitted to the processor for authorisation. This level of control allows for entirely bespoke checkout designs, advanced fraud rules, and integration with in-house systems, but it demands rigorous security practices.
The Compliance Cost
Because cardholder data touches your own environment, a fully self-hosted integration usually requires SAQ D, the most extensive PCI DSS questionnaire, covering over 300 controls including network segmentation, encryption key management, vulnerability scanning, and annual penetration testing. For many UK SMEs, the cost of achieving and maintaining this level of compliance, often £5,000-£20,000 a year in security tooling, audits, and staff time, outweighs the benefits of a bespoke checkout.
The Middle Ground: Hosted Fields
Hosted fields (sometimes called an iframe or seamless integration) offer a genuinely useful compromise. The card number, expiry, and CVV fields are rendered inside secure iframes served directly from the payment provider's domain, but they sit visually within your own checkout page. To the customer, it looks and feels like a single, seamless page on your site, yet the sensitive data never actually touches your servers.
Why Hosted Fields Appeal to UK SMEs
This approach typically qualifies for SAQ A-EP, a mid-tier questionnaire that is more demanding than SAQ A but far less onerous than SAQ D. Providers including Stripe (via Stripe Elements), Opayo, and Worldpay all offer hosted fields as standard, making this a realistic option for growing UK ecommerce businesses that want brand consistency without taking on full PCI D compliance. Many businesses researching ecommerce payment gateways ultimately land on hosted fields as the best balance of control and compliance.
Hosted vs Self-Hosted: Full Comparison Table
| Factor | Hosted Payment Page | Hosted Fields (iframe) | Self-Hosted (Fully Integrated) |
|---|---|---|---|
| PCI DSS level typically required | SAQ A | SAQ A-EP | SAQ D |
| Customer stays on your domain | No (redirected) | Yes | Yes |
| Development effort | Low - minimal coding | Moderate - some front-end work | High - full API integration and security build |
| Typical conversion impact vs on-page checkout | 5-15% lower conversion due to redirect friction | Minimal impact, near-seamless | No redirect friction, but bugs can hurt conversion |
| Ongoing compliance cost (approx.) | Minimal, often free with provider tools | Low to moderate | £5,000-£20,000+ per year for audits and tooling |
| Design/branding control | Limited (logo, colours, some CSS) | High (full page design, styled fields) | Total control |
| Best suited to | Startups, small ecommerce, low-volume sellers | Growing SMEs wanting brand consistency | Large enterprises with dedicated dev/security teams |
| Example providers offering this option | Stripe Checkout, Opayo Payment Pages, Worldpay HPP | Stripe Elements, Opayo, Worldpay, Checkout.com | Worldpay Direct API, Checkout.com, Braintree, Adyen |
PCI DSS Compliance: The Deciding Factor for Most Businesses
For the majority of UK businesses, PCI DSS compliance burden is the single biggest factor in this decision. Non-compliance can result in fines from your acquiring bank, increased transaction fees, or in serious cases, the loss of your ability to accept card payments altogether.
SAQ A vs SAQ A-EP vs SAQ D in Practice
SAQ A involves confirming that all cardholder data functions are outsourced to PCI-compliant third parties and that your website has no ability to affect the security of the payment transaction. SAQ A-EP adds requirements around your website's security, since your page does host the iframe and JavaScript, but the card data itself remains outside your systems. SAQ D requires a full assessment of firewalls, encryption, access controls, logging, and regular vulnerability scanning across any system that touches, stores, or transmits card data.
What This Means for Smaller Businesses
A sole trader or small ecommerce store processing a few hundred transactions a month rarely has the budget or expertise to maintain SAQ D compliance properly. Choosing hosted or hosted-fields checkout removes this burden almost entirely, letting the payment provider carry the compliance weight. This is one of the clearest reasons hosted solutions dominate the UK SME market.
Conversion Rate: Does Hosted Checkout Really Cost You Sales?
Historically, hosted payment pages carried a real conversion penalty because customers were redirected away from a merchant's site to an unfamiliar-looking page, creating hesitation and cart abandonment. Industry data has suggested this redirect friction can cost 5-15% in conversion versus a fully on-page checkout, particularly on mobile devices where page load times and visual inconsistency are more noticeable.
How Modern Hosted Checkouts Have Closed the Gap
Providers such as Stripe have invested heavily in making hosted checkout pages fast, mobile-optimised, and highly customisable with your logo, brand colours, and even saved payment methods via digital wallets like Apple Pay and Google Pay. For many UK businesses, the conversion gap between a well-designed hosted page and a bespoke self-hosted checkout has narrowed considerably, especially when weighed against the security risk of managing card data in-house.
When On-Page Checkout Genuinely Matters
For high-volume ecommerce brands where every fraction of a percentage point in conversion translates into significant revenue, hosted fields or a self-hosted checkout can be worth the additional investment. Subscription businesses, high-ticket retailers, and marketplaces with complex multi-step checkouts often find the control justifies the extra compliance overhead.
Technical Complexity and Development Resource
Beyond compliance, the practical question of who will build and maintain your integration matters enormously. Hosted pages can often be implemented by a single developer in a day using pre-built plugins for platforms like WooCommerce, Shopify, or Magento. Self-hosted integrations, by contrast, require ongoing engineering investment.
Maintenance Overhead Over Time
A self-hosted integration is not a "build once and forget" project. API versions change, security patches must be applied promptly, and any update to card scheme rules (such as new Strong Customer Authentication requirements) must be implemented by your own team rather than automatically inherited from the provider. This ongoing maintenance is often underestimated by businesses when first weighing up payment gateway integrations.
Platform and Plugin Compatibility
Most UK ecommerce platforms have first-class support for hosted and hosted-fields integrations via official plugins, meaning updates, security patches, and new payment methods (like Klarna or Clearpay) are added automatically. Self-hosted integrations often require custom plugin development to keep pace with these platform updates, adding further ongoing cost.
Which Option Is Right for Your Business?
The right choice depends heavily on your size, sector, technical resources, and appetite for compliance risk. Below is a practical framework based on common UK business profiles.
Startups and Small Ecommerce Businesses
If you are processing under roughly £250,000 a year in online sales and do not have an in-house development team, a hosted payment page is almost always the right choice. It minimises compliance risk, requires little technical investment, and can be set up in hours using platforms like Stripe Checkout or Opayo Payment Pages.
Growing SMEs Focused on Brand Experience
If your business has outgrown a basic hosted page and wants a more seamless checkout without taking on full PCI D obligations, hosted fields are usually the sweet spot. This is common for established UK retailers doing £250,000-£5 million in annual turnover who want their checkout to feel fully on-brand.
Enterprises and High-Volume Platforms
Large retailers, marketplaces, and subscription businesses with dedicated security and development teams may justify a fully self-hosted integration, particularly where highly customised checkout flows, complex tokenisation strategies, or bespoke fraud rules are business-critical. These businesses typically have compliance and security budgets that make SAQ D a manageable, ongoing cost of doing business.
Regulated or High-Risk Sectors
Businesses in regulated sectors, or those processing telephone and mail order payments alongside online sales, should also weigh how their gateway choice interacts with other channels. Our guide to MOTO payments in the UK covers how card-not-present risk factors differ from standard ecommerce checkout.
Choosing a Provider: What to Look For
Whichever integration type you choose, the underlying provider matters just as much as the technical model. UK businesses should compare providers on transaction fees, settlement times, support for Strong Customer Authentication, and the breadth of payment methods supported (including Apple Pay, Google Pay, and buy-now-pay-later options).
Comparing Leading UK Providers
Stripe is popular with startups and developers for its strong documentation and flexible API across all three integration types. Worldpay and Opayo have deep roots in UK retail and offer robust hosted and hosted-fields options well suited to established SMEs. Checkout.com and Adyen are often chosen by larger enterprises needing global reach and highly customisable self-hosted integrations. For a fuller breakdown, see our comparison of the best payment gateways in the UK.
Understanding the Gateway vs Merchant Account Relationship
It is worth remembering that your payment gateway is distinct from your merchant account, the underlying facility that actually holds and settles your funds. Some providers bundle both together, while others require you to arrange a separate merchant account. Our guide on payment gateways vs merchant accounts explains this distinction in more detail, which is particularly relevant when comparing overall costs between hosted and self-hosted setups.
Making the Final Decision: A Practical Checklist
Before committing to a hosted, hosted-fields, or self-hosted approach, UK businesses should work through a few key questions. First, what is your realistic in-house technical capability, both now and over the next two to three years? Second, how much genuine conversion uplift would a fully branded checkout deliver for your specific customer base and average order value? Third, what is your appetite and budget for ongoing PCI DSS compliance, including annual audits and penetration testing if SAQ D applies? Finally, does your ecommerce platform have strong native support for your preferred integration type, or will custom development be required?
Answering these honestly will point most UK SMEs towards hosted or hosted-fields solutions, while larger, well-resourced businesses may find the investment in a self-hosted integration justified by the control and customisation it delivers.
Frequently Asked Questions
Is a hosted payment gateway less secure than a self-hosted one?
No, a hosted payment gateway is generally considered more secure for most businesses because card data never touches your own servers, removing a major source of risk. The payment provider carries the responsibility for maintaining PCI DSS Level 1 compliance and robust security infrastructure, which most SMEs could not replicate cost-effectively in-house.
Do hosted payment pages really hurt conversion rates?
Older hosted pages did sometimes reduce conversion by 5-15% due to redirect friction and inconsistent branding, but modern hosted checkouts from providers like Stripe are fast, mobile-optimised, and closely mirror your brand. For most UK SMEs, the conversion gap has narrowed significantly and rarely justifies the added compliance burden of a self-hosted alternative.
What is the difference between hosted fields and a self-hosted gateway?
Hosted fields use secure iframes served by your payment provider, so card data never touches your servers even though it appears to sit within your own checkout page. A self-hosted gateway means your own code captures and transmits the card data directly, which requires far more extensive PCI DSS compliance (SAQ D) and technical resource.
Which PCI DSS level applies to my business?
The applicable PCI DSS self-assessment questionnaire depends on how your checkout is built, with hosted pages typically qualifying for SAQ A, hosted fields for SAQ A-EP, and self-hosted integrations for SAQ D. Your acquiring bank or payment provider can confirm exactly which level applies based on your specific integration.
Can I switch from a hosted to a self-hosted gateway later?
Yes, most UK payment providers, including Stripe, Worldpay, and Opayo, support all three integration types on the same underlying account, so you can start with a hosted page and migrate to hosted fields or a self-hosted integration as your business grows. This makes it low-risk to start simple and upgrade once you have clearer data on conversion and the in-house resource to manage a more complex setup.
Are hosted payment pages suitable for subscription or recurring billing businesses?
Yes, most hosted payment gateways support tokenisation and recurring billing setups, allowing customers to save card details securely for future payments without your business handling the underlying card data. This makes hosted or hosted-fields options viable even for subscription-based UK businesses that need to bill customers regularly.
Does my choice of gateway type affect my transaction fees?
Generally, the integration type itself (hosted, hosted fields, or self-hosted) does not directly change the interchange or scheme fees you pay, as these are set by card networks and your acquirer. However, the total cost of ownership differs significantly once you factor in development time and PCI DSS compliance costs, which are typically much higher for self-hosted setups.
How Compare Card Fees Can Help
Compare Card Fees is a free, independent advisory service. We compare rates from leading UK payment providers to find you the best deal available - no fee, no obligation.
Whether you are looking to reduce your card processing costs, switch provider, or understand what you are currently paying, our experts can help. Tell us about your business and we will find the best rates available.


