Join our Newsletter — 33% off our NHI Course

How should merchants evaluate pricing when choosing a payment processor?

Merchants should compare the full pricing structure, not just the advertised headline rate. Tiered pricing can hide higher costs for online transactions, specialty cards, or rewards cards, so the true effective rate may be materially different. Ask for interchange-plus pricing, confirm every fee category, and calculate cost based on your actual transaction mix before committing.

Why headline rates are rarely the real price

The advertised percentage is only one part of processor pricing. Merchants usually pay more when the fee model includes card-brand interchange, processor markup, gateway charges, monthly minimums, statement fees, batch fees, cross-border add-ons, chargeback fees, and penalties tied to card type or transaction channel. The practical question is not “what is the rate?” but “what will this cost for my exact sales profile?”

That distinction matters because online and card-not-present sales often carry different economics than in-person swipes, and premium or rewards cards can push the effective rate higher than the headline suggests. A processor that looks inexpensive on a simple advertised rate can become costly once you add the charges that apply to your actual mix of domestic, international, keyed-in, recurring, and higher-risk transactions.

  • Ask whether pricing is interchange-plus, tiered, or flat-rate.
  • Request a complete fee schedule in writing.
  • Compare total monthly cost, not just percentage rates.

How to compare processors on a like-for-like basis

Start by modelling your own volume, ticket size, card mix, and channel mix, then ask each processor to quote against that same profile. Interchange-plus pricing is usually easier to evaluate because it separates network cost from processor markup, while tiered pricing can make it harder to see where the margin is being added. The goal is to calculate an effective rate from expected spend, not from a generic sales pitch.

For a fair comparison, include the fees that often sit outside the advertised rate: PCI or compliance fees, monthly service charges, gateway fees, early termination fees, chargeback handling, and any minimum processing commitments. If one quote looks cheaper only because it excludes common usage fees, it is not a real apples-to-apples comparison. Merchants should also confirm whether the quoted rate changes by card presentment, channel, region, or settlement timing.

When merchants in payment-heavy sectors are especially sensitive to hidden cost structures and control failures, the same discipline used in secrets and access governance applies to vendors too: demand transparency, verify the operating model, and avoid assumptions based on a headline figure alone. NHIMG’s Ultimate Guide to Non-Human Identities is relevant here because unmanaged third-party exposure and weak visibility are recurring patterns in cost and risk oversights.

Risk and Threat Considerations

Poor pricing review is a commercial risk first, but it can become an operational and control risk when hidden fees, contract traps, or opaque settlement terms distort cash flow and make vendor changes expensive. In payment environments, unclear pricing can also mask broader dependency risk if merchants become locked into a processor that is hard to exit or hard to reconcile.

Failure mechanism: Merchants accept a headline rate without testing the real fee stack against their transaction mix, so higher-cost channels, card types, or add-on fees silently increase the effective rate and reduce margin.

Impact: The merchant overpays, loses pricing certainty, and may discover too late that volume commitments, termination clauses, or per-transaction fees materially erode profitability.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 CIS Control 15 — Service Provider Management Processor selection is third-party payment risk management.
Recommendation — Assess processor fees, terms, and control commitments before onboarding the service provider.
NIST CSF 2.0 GV.SC — Govern Risk and Supply Chain Risk Management Choosing a processor requires supply-chain governance over commercial and operational dependency.
Recommendation — Evaluate payment processors under supply-chain governance and contract-risk review.
PCI DSS v4.0 12 — Support Information Security with Organizational Policies and Programs Payment processing costs and contractual choices affect the control environment around card payments.
Recommendation — Review processor pricing and contract terms alongside card-payment security obligations.

Practitioner Guidance

What to verify: Make the processor quote on your actual mix, then verify how each fee behaves across card-present, online, recurring, international, and premium-card transactions. If the processor will not provide a written fee schedule and a sample invoice walk-through, treat the quote as incomplete.

Decision rule: If two offers have similar headline rates, prefer the one with clearer interchange treatment, fewer add-on fees, and no punitive minimums or termination costs. If your volume is uneven or your card mix skews toward online and rewards cards, prioritise effective-rate analysis over percentage comparisons.

Practitioner takeaway: The best processor is not the one with the lowest advertised rate, it is the one whose total cost is predictable under your real transaction pattern.