Payment Service Provider
A payment service provider (PSP) is a third-party company that helps merchants accept electronic payments, such as credit and debit card transactions, from their customers. It acts as an intermediary connecting the parties involved in a payment, including customers, businesses, and banks. Some PSPs bundle multiple payment functions together so a merchant can work with a single provider instead of contracting each service separately.
A PSP is a third-party entity that facilitates electronic payment transactions between parties such as cardholders, merchants, acquirers, and payment networks. Depending on the provider, a PSP may combine functions that are otherwise distinct, for example acting as both a payment gateway and a payment processor, and may connect to multiple acquiring and payment networks. The specific services offered, the connections supported, and the contractual and compliance responsibilities assumed vary by provider and by implementation; the term itself describes a role in the payment flow rather than a fixed set of functions. Because a PSP handles or transmits payment data, its involvement can affect the PCI DSS scope and validation obligations of both the PSP and the merchants it serves, but the precise impact depends on the transaction and data flows rather than on the label alone.
Why it matters
Payment service providers occupy a central position in the payment flow, connecting cardholders, merchants, acquirers, and payment networks. Because many merchants rely on a single PSP to bundle functions that would otherwise be contracted separately, the PSP becomes a concentration point for both operational dependency and payment data handling. Understanding what a specific PSP actually does, rather than assuming a fixed set of functions from the label, is essential for scoping security and compliance obligations correctly.
Since a PSP handles or transmits payment data, its involvement can affect the PCI DSS scope and validation obligations of both the PSP itself and the merchants it serves. The precise impact depends on the transaction and data flows in a given implementation, not on the term alone. Two merchants using nominally similar PSP arrangements may face different scoping outcomes depending on how payment data is captured, transmitted, and where it comes to rest. Compliance teams should confirm responsibilities against the current published PCI DSS standard and the contractual allocation of duties between the parties rather than assuming the PSP absorbs all obligations.
Because the term describes a role in the payment flow rather than a specific product, misunderstanding the division of responsibility between a merchant and its PSP is a common source of compliance gaps. A merchant that treats a PSP relationship as fully outsourcing its own obligations may leave portions of its environment unassessed. Clear documentation of which entity performs which function, and where cardholder data is handled, helps both parties define and validate their respective scope.
Who it's relevant to
Inside PSP
Common questions
Answers to the questions practitioners most commonly ask about PSP.