We’re rated Excellent on:

trust pilot

Secure Payment Gateways: What UK Businesses Need to Know

Updated July 2026

Exclusive Rates From as Low as 0.26%

A secure payment gateway is the technology layer that encrypts and authorises card and digital payments between your customer, your business, and the banks involved, and choosing one is one of the most important decisions any UK business will make in 2024 and beyond. With card fraud losses across the UK totalling over £570 million in recent years and PSD2 Strong Customer Authentication now mandatory, businesses need gateways that combine PCI DSS compliance, 3D Secure 2 support, and robust encryption without compromising checkout conversion. This guide explains exactly what makes a payment gateway secure, which UK providers lead on security, and how to evaluate your options with confidence.

Key Takeaways

  • All UK payment gateways handling card data must be PCI DSS compliant, and most reputable providers hold Level 1 certification, the highest tier.
  • Strong Customer Authentication (SCA) via 3D Secure 2 is a legal requirement under UK PSD2 rules for most online card transactions above £30.
  • Tokenisation and end-to-end encryption are now industry standard among leading gateways such as Stripe, Worldpay, and Opayo.
  • Poorly configured SCA and fraud tools can cost more in abandoned baskets than fraud itself typically costs, so balance is essential.
  • UK businesses processing under £120,000 annually can usually complete PCI DSS via a simple Self-Assessment Questionnaire (SAQ), not a costly audit.
  • Hosted payment pages shift most security burden to the gateway provider, making them the lowest-risk option for smaller businesses.
  • Always check whether a provider offers UK-based fraud support and GDPR-compliant data storage before signing a contract.

What Makes a Payment Gateway "Secure"?

A secure payment gateway is defined by several overlapping layers of protection rather than a single feature. Understanding these layers helps UK business owners cut through marketing claims and assess providers on substance rather than buzzwords.

PCI DSS Compliance

The Payment Card Industry Data Security Standard (PCI DSS) is the baseline requirement for any business that stores, processes, or transmits cardholder data in the UK. Gateways such as Stripe, Worldpay, Opayo (formerly Sage Pay), and Checkout.com maintain PCI DSS Level 1 certification, the most rigorous tier, which is reassessed annually by an independent Qualified Security Assessor (QSA).

Encryption and Tokenisation

Modern gateways encrypt card data in transit using TLS 1.2 or higher and replace sensitive card numbers with randomly generated tokens for storage. This means that even if a merchant's systems were breached, no usable card data would be exposed, because the actual Primary Account Number (PAN) never touches the merchant's servers.

3D Secure 2 and Strong Customer Authentication

Since the UK's SCA enforcement deadline, most online card payments require an additional authentication step, such as a one-time passcode, biometric confirmation, or banking app approval. 3D Secure 2 (3DS2) is the current standard and is designed to use risk-based analysis so that low-risk transactions can skip friction while higher-risk ones are challenged.

Why Payment Security Matters More for UK Businesses Now

UK Finance reported that unauthorised financial fraud losses reached hundreds of millions of pounds annually, with card-not-present fraud representing the largest single category. E-commerce growth has expanded the attack surface, and the Financial Conduct Authority (FCA) has tightened expectations around SCA enforcement, making gateway security a compliance issue as well as a commercial one.

Regulatory Pressure: PSD2 and the FCA

The revised Payment Services Directive (PSD2), retained in UK law post-Brexit and enforced by the FCA, mandates SCA for most remote electronic transactions. Non-compliant checkouts risk declined transactions from issuing banks, not just fraud exposure, which makes gateway selection a direct revenue issue.

Reputational and Financial Risk of Breaches

A data breach involving cardholder information can trigger fines from card schemes, mandatory forensic investigations, and in some cases the loss of the ability to accept card payments entirely. For small and medium UK businesses, the average cost of a significant breach can run into tens of thousands of pounds once legal, remediation, and reputational costs are included.

Comparing Security Features Across Leading UK Payment Gateways

Not all gateways offer the same depth of security tooling. The table below compares core security features across some of the most widely used providers in the UK market.

Provider PCI DSS Level 3D Secure 2 Tokenisation Built-in Fraud Tools UK-Based Support
Stripe Level 1 Yes, adaptive Yes Radar (machine learning) Limited, mostly online
Worldpay Level 1 Yes Yes FraudSight Yes
Opayo (Sage Pay) Level 1 Yes Yes Fraud Screening Suite Yes
Checkout.com Level 1 Yes, adaptive Yes Custom risk rules Limited
PayPal / Braintree Level 1 Yes Yes Kount integration Yes

When comparing gateways, it is worth reviewing our detailed breakdown of the best payment gateways in the UK to see how these providers stack up on pricing as well as security.

Hosted vs Self-Hosted Gateways: Security Implications

One of the most consequential decisions for UK businesses is whether to use a hosted payment page or integrate a self-hosted, API-based checkout. This choice has a direct impact on your PCI DSS obligations.

Hosted Payment Pages

With a hosted solution, customers are redirected to the provider's own secure page to enter card details, meaning cardholder data never touches your servers. This significantly reduces your PCI DSS scope, often allowing you to complete the simplest self-assessment questionnaire (SAQ A) rather than more onerous versions.

Self-Hosted and API Integrations

Self-hosted checkouts, where card fields are embedded directly on your website, offer more design control and a smoother user experience but increase your compliance burden. You will typically need to complete SAQ A-EP or SAQ D, which require more extensive security documentation and, in some cases, an annual penetration test.

For a deeper comparison of these two approaches, see our guide on hosted vs self-hosted payment gateways.

PCI DSS Compliance: What UK Businesses Actually Need to Do

Many UK business owners assume PCI DSS compliance requires expensive external audits, but for most small and medium businesses, this is not the case.

Self-Assessment Questionnaires (SAQs)

Businesses processing fewer than approximately 300,000 transactions per year (Level 4 merchants, which covers the vast majority of UK SMEs) can typically self-certify using an SAQ appropriate to their integration type. Your acquiring bank or payment gateway provider will usually specify which SAQ applies and provide the documentation.

Ongoing Requirements

Compliance is not a one-off task. Businesses must renew their SAQ annually, run quarterly vulnerability scans if handling card data directly, and maintain up-to-date firewall and antivirus protections on any systems that touch payment data.

Consequences of Non-Compliance

Failure to maintain PCI DSS compliance can result in monthly non-compliance fines from your acquirer, typically ranging from £20 to £100 per month, escalating in the event of an actual breach where fines can reach thousands of pounds alongside potential loss of card acceptance privileges.

Fraud Prevention Tools and Strong Customer Authentication

Beyond baseline compliance, the strongest UK payment gateways offer proactive fraud prevention tools that can be configured to your risk appetite.

Address Verification Service (AVS) and CVV Checks

AVS matches the billing address provided at checkout against the address held by the card issuer, while CVV checks confirm the three or four-digit security code. Both are basic but effective first-line defences against card-not-present fraud and are supported by virtually all UK gateways.

Velocity Checks and Machine Learning

More sophisticated gateways like Stripe Radar and Checkout.com's risk engine analyse transaction velocity, device fingerprints, and behavioural patterns in real time to flag suspicious activity before it completes. These tools use machine learning models trained on billions of transactions globally, giving smaller UK merchants access to fraud detection capability that would otherwise be unaffordable to build in-house.

Balancing Security with Conversion

Overly aggressive fraud rules and unnecessary SCA challenges can suppress legitimate sales, with some studies suggesting basket abandonment can rise significantly when checkout friction increases. The most effective approach is to use risk-based authentication, where low-value or trusted repeat transactions are exempted from full 3DS2 challenges wherever the gateway and issuing bank support it.

Choosing a Secure Gateway for Different Business Types

Security requirements vary considerably depending on how and where your business takes payments.

E-commerce Businesses

Online-only businesses face the highest exposure to card-not-present fraud and should prioritise gateways with strong 3DS2 implementation and real-time fraud scoring. Our dedicated guide to e-commerce payment gateways covers this in more depth.

Mail Order and Telephone Order (MOTO) Businesses

MOTO transactions are exempt from SCA under UK regulations but carry their own security considerations, since card details are typically entered manually by staff rather than the customer. Businesses taking payments this way should use PCI-compliant virtual terminals and avoid ever writing card numbers down; our MOTO payments guide explains the compliant approach in detail.

Businesses Integrating Multiple Systems

Businesses connecting their gateway to accounting software, CRMs, or booking systems introduce additional integration points that must each be secured. Reviewing our article on payment gateway integrations can help you understand where responsibility for security sits across your tech stack.

Payment Gateway vs Merchant Account: Where Security Responsibility Sits

It is worth clarifying that a payment gateway and a merchant account are distinct components of your payment infrastructure, and security responsibilities differ between them. The gateway handles encryption, tokenisation, and authentication at the point of transaction, while the merchant account, held with an acquiring bank, is responsible for settlement and holds its own compliance obligations. Our guide to payment gateways vs merchant accounts explains how these two elements work together and where liability typically sits if something goes wrong.

Practical Checklist: Evaluating a Gateway's Security Before You Sign

Before committing to a provider, UK businesses should verify the following points directly with the gateway or via their contract documentation.

  • Confirm the provider holds current PCI DSS Level 1 certification and ask for evidence such as an Attestation of Compliance (AoC).
  • Check that 3D Secure 2 is supported and enabled by default, not as a paid add-on.
  • Ask whether card data is tokenised and never stored in plain text on your own systems.
  • Establish what fraud monitoring tools are included as standard versus charged as extras.
  • Confirm where customer data is stored and whether this satisfies UK GDPR requirements, particularly post-Brexit data adequacy rules.
  • Check the provider's incident response process and typical response times in the event of a suspected breach.
  • Review whether UK-based technical and fraud support is available, particularly important for urgent issues outside standard hours.

Common Mistakes UK Businesses Make with Payment Security

Many otherwise well-run businesses undermine their own security posture through avoidable errors. Storing card numbers in spreadsheets or CRM notes fields remains surprisingly common among smaller MOTO businesses despite being a clear PCI DSS violation. Similarly, businesses sometimes disable 3D Secure challenges entirely to improve conversion rates, unaware this can shift fraud liability back onto the merchant under card scheme rules. Finally, many businesses fail to update their SAQ annually or ignore vulnerability scan requirements, leaving them technically non-compliant even while believing they are protected.

Frequently Asked Questions

Is Stripe more secure than Worldpay for UK businesses?

Both Stripe and Worldpay hold PCI DSS Level 1 certification and support 3D Secure 2, meaning they offer comparable baseline security. The choice between them typically comes down to integration style, UK-based support availability, and pricing rather than a meaningful security gap.

Do small UK businesses need to complete a PCI DSS audit?

Most small UK businesses fall into Level 4 merchant status and can self-certify using a Self-Assessment Questionnaire rather than undergo a formal external audit. A full audit by a Qualified Security Assessor is generally only required for very large merchants processing millions of transactions annually.

What happens if my business suffers a data breach involving card details?

You must notify your acquiring bank and payment gateway provider immediately, as they will typically require a forensic investigation to determine the scope of the breach. Depending on severity, this can result in card scheme fines, mandatory remediation costs, and temporary or permanent loss of card processing privileges.

Is 3D Secure 2 mandatory for all UK online payments?

3D Secure 2 is required for most card-not-present transactions under UK PSD2 Strong Customer Authentication rules, though certain exemptions exist for low-value transactions, recurring payments, and trusted merchant arrangements. Your payment gateway should be configured to apply these exemptions automatically where eligible to minimise unnecessary checkout friction.

Are hosted payment pages safer than embedded checkouts?

Hosted payment pages generally reduce your security burden because cardholder data is entered and processed entirely on the provider's servers rather than your own. This typically qualifies your business for a simpler PCI DSS self-assessment, making hosted pages a lower-risk option particularly for smaller businesses without dedicated technical security resources.

Can I be fined for not maintaining PCI DSS compliance in the UK?

Yes, acquiring banks and payment gateway providers can apply monthly non-compliance fees, typically between £20 and £100, if your PCI DSS certification lapses. These fines can escalate significantly, and in the event of an actual data breach while non-compliant, costs and penalties can run into thousands of pounds.

What is the difference between tokenisation and encryption?

Encryption scrambles card data using a mathematical algorithm that can be reversed with the correct key, whereas tokenisation replaces the card number entirely with a randomly generated token that has no mathematical relationship to the original data. Tokenisation is generally considered more secure for storage purposes because even a compromised token database provides no path back to real card numbers.

How Compare Card Fees Can Help

Compare Card Fees is a free, independent advisory service. We compare rates from leading UK payment providers to find you the best deal available - no fee, no obligation.

Whether you are looking to reduce your card processing costs, switch provider, or understand what you are currently paying, our experts can help. Tell us about your business and we will find the best rates available.