Payment Gateway vs Payment Orchestration vs Core Fintech Software: How to Choose (2026)
Published · Editorial team, Payment Company for Sale
"Payment platform" is used for three very different kinds of software: payment gateways, payment orchestration layers and core fintech software that runs customer accounts, cards and sometimes crypto. Buyers — especially those considering buying a payment company or a payment platform for sale — often compare them as if they were interchangeable. They solve different problems and depend on different regulated partners.
This guide defines each category, shows what none of them replaces, and gives a practical due-diligence checklist. If you are still deciding whether to acquire an entity, partner with a licensed provider or start a new PSP, read our companion guide on buying a payment company vs BaaS vs starting a new PSP first.
Three categories, defined
Payment gateway
A gateway is the technical connection between where a payment is initiated — a checkout page, an app, a terminal or an API call — and the processor or acquirer that authorises it. It collects payment details securely, formats and sends authorisation requests, returns results, and usually offers refunds, captures and reporting. If it handles card data, it is in scope of the PCI Data Security Standard. A white-label gateway lets a business offer this to its own merchants under its own brand.
Payment orchestration
Orchestration sits one level up. It connects to several gateways, PSPs and alternative payment methods through one integration and decides where each transaction goes, using rules based on cost, country, card type or provider availability. Typical features include provider-agnostic token vaults, retries and fallbacks when a provider fails, fraud and 3-D Secure hooks, and consolidated reconciliation. Orchestration is mainly a merchant- or PSP-side tool for resilience, coverage and cost control.
Core fintech software
Core fintech software runs a financial product for end customers: onboarding and KYC/KYB, customer profiles, multi-currency accounts with an internal ledger, transfers, FX, card management, sometimes crypto wallets and exchange, plus AML workflows, transaction monitoring, CRM and back-office administration. It is closer to what a neobank or e-money business operates than to a checkout tool.
What software does not replace
None of these categories is itself a regulated institution. In the EU, PSD2 Annex I lists regulated payment services, including the execution of payment transactions and the acquiring of payment transactions(Directive (EU) 2015/2366). Running gateway or orchestration code does not authorise you to provide those services. Likewise, core software that displays an IBAN or a card balance relies on a bank or EMI that actually holds the account and on an issuer that is a member of the card scheme or sponsored by one. Crypto custody and exchange in the EU need MiCA authorisation where in scope.
You can verify a European partner's status on the EBA register. In Switzerland, a payment business that is AML-supervised through an SRO (FINMA: SROs) still needs regulated banking and payment providers for accounts, cards and settlement.
Comparison table
| Dimension | Payment gateway | Payment orchestration | Core fintech software |
|---|---|---|---|
| Primary user | Merchants or a PSP serving merchants | Merchants or PSPs with several providers | Fintechs, EMIs, neobanks, payment companies with end customers |
| Main job | Accept and transmit payments | Route and optimise across providers | Run accounts, ledger, cards, transfers, compliance |
| Routing | Usually to one or a few processors | Rules-based across many; fallbacks | Routes to configured banking/issuing providers |
| Integrations | Acquirers, processors, APMs | Many PSPs, fraud tools, vaults | Banks, EMIs, issuers, KYC, custody, monitoring |
| Customer accounts / balances | No (merchant reporting only) | No | Yes, as an internal ledger mirrored on regulated accounts |
| Merchant settlement | Done by acquirer/PSP, reported via gateway | Done by each underlying PSP | Not its core role unless combined with acquiring partners |
| Regulated partner still needed | Acquirer / PSP | Each connected PSP | Bank or EMI, card issuer, custodian where relevant |
| Main compliance touchpoints | PCI DSS, acquirer rules | PCI DSS (vault), data protection | AML/KYC, safeguarding via partner, data protection |
Use cases: merchant acquiring, customer accounts, buying a company
You want to serve merchants (acquiring-side business)
You need a gateway with merchant onboarding, checkout, refunds and reporting, plus one or more acquirers or PSPs to process and settle. Orchestration becomes valuable once you have several acquirers, sell across regions or need resilience. Your regulated dependency is the acquirer.
You want to serve end customers (accounts, cards, crypto)
You need core fintech software and regulated partners for accounts, issuing and, where relevant, custody. A gateway may be added later for pay-ins. Your main work is onboarding, ledger accuracy, AML monitoring and customer support.
You are buying a payment company
Start from the business model the entity is approved for and the providers it can actually use, then choose software to match. A Swiss payment company for sale with a fiat-and-crypto business model points towards core fintech software; a merchant-services strategy points towards a gateway and, later, orchestration. Buying an entity and licensing software are separate contracts with separate risks.
Illustrative products (not a ranking)
The products below show how vendors position themselves. Descriptions summarise each vendor's own website as accessed on 11 October 2026. They are vendor claims, not independent tests, and no product is presented as better than another.
- Spreedly (unaffiliated) describes itself as a payments orchestration platform with modules for connecting payment methods, a vault for stored credentials and token portability, workflow-driven routing optimisation, and fraud and 3-D Secure tooling.
- Primer (unaffiliated) describes checkout, a centralised vault, no-code payment workflows, network tokenisation, fallbacks to secondary processors, 3-D Secure, observability and reconciliation across providers.
- SAMFPay (affiliated) is described by its vendor as standalone payment gateway and orchestration software, separate from and independently licensed from SAMFCore, covering pay-in, orchestration and payout workflows under the licensee's brand, with configurable provider priorities, fee rules and approval workflows within an agreed scope. The vendor page describes a proposed perpetual licence with optional source code where authorised, and states that commercial availability, white-label and licensing rights are subject to final contractual authorisation. It is software, not an acquirer.
- SAMFCore (affiliated) is described by its vendor as a modular platform for onboarding and KYC/KYB, multi-currency accounts and internal ledger, payments through selected banking-provider connections, card management through issuing-provider connections, crypto wallets through custody connections, AML workflows and transaction monitoring, CRM and back office. It is software connected to providers the customer selects; it is not a bank, EMI or card issuer.
Hosted service vs licensed or proprietary code
Most gateway and orchestration products are offered as hosted services: the vendor runs the infrastructure, carries much of the PCI scope for the vault and charges ongoing fees. Some vendors license software you deploy yourself, and a few offer source-code access. Owning or licensing code gives control over roadmap, data location and vendor exit, but moves hosting, security testing, upgrades, incident response and compliance evidence to your team.
- Hosted: faster integration, shared security responsibility, recurring fees, less control over roadmap and data residency.
- Licensed deployment: more control and possibly lower variable cost, but you operate it; PCI and security obligations increase.
- Source code: only valuable if you have engineers to maintain it; check exactly what is delivered, escrow terms and IP ownership.
Merchant settlement and funds flow
Draw the funds flow before choosing software. In card acquiring, the acquirer receives scheme settlement and pays the merchant, net of fees; the gateway reports it. With orchestration, each underlying PSP settles separately, so reconciliation across providers becomes a core requirement. In a customer-account model, the bank or EMI holds funds and your ledger must reconcile to its statements every day. If your company would ever hold merchant or customer money itself, that is a legal question — safeguarding in the EEA, deposit-taking rules in Switzerland — not a software setting.
Cost-of-ownership matrix
We do not publish or compare vendor prices. Use this matrix to collect comparable quotes and internal estimates.
| Cost category | Hosted gateway / orchestration | Licensed gateway / orchestration | Core fintech software |
|---|---|---|---|
| Initial | Integration effort; setup fees if any | Licence fee; deployment; configuration | Licence or subscription; implementation; provider integrations |
| Recurring software | Per-transaction or platform fees | Maintenance and support, if contracted | Maintenance, support or subscription |
| Infrastructure | Included in service | Hosting, monitoring, backups | Hosting, monitoring, backups |
| Security and compliance | Shared with vendor | PCI assessment, penetration tests | Penetration tests, data protection, AML tooling |
| Regulated partners | Acquirer / PSP fees | Acquirer / PSP fees | Bank/EMI, issuer, custodian, KYC fees |
| People | Integration and payments ops | Engineers to operate and upgrade | Engineers, compliance and support staff |
| Exit | Token migration; contract notice | Low vendor lock-in if rights are clear | Data migration; provider re-contracting |
Pros and cons
| Category | Strengths | Limitations |
|---|---|---|
| Gateway | Focused; well-understood; fastest path to accepting payments with one acquirer | Single-provider dependency; limited optimisation; no customer accounts |
| Orchestration | Resilience, coverage and routing control across providers; token portability | Adds a layer to operate; value depends on having multiple providers and volume |
| Core fintech software | Runs full customer financial products; one system for onboarding, ledger, cards and compliance | Broad scope; heavy partner integration; ledger and compliance quality are critical |
Technical due-diligence checklist
- Write down which regulated partner provides each service (acquiring, accounts, issuing, custody) and confirm the software has a working, maintained integration with it.
- Ask for a live demonstration on test data of the exact flows you need, including refunds, chargebacks or returns, and failure handling.
- Get the licence in writing: scope, term, territories, white-label rights, IP ownership, and precisely what source code (if any) is delivered and when.
- Review security evidence: PCI DSS status where card data is handled, recent penetration tests, encryption and key management.
- Check ledger design: double-entry, reconciliation against partner statements, audit trail and reporting exports.
- Confirm AML/KYC tooling and how it maps to your obligations and your SRO or regulator's expectations.
- Clarify hosting, data residency, uptime responsibilities, support hours and escalation.
- Plan the exit: data and token export, notice periods and transition assistance.
For the corporate and regulatory side of a transaction, combine this with the acquisition checklist.
Frequently asked questions
What is the difference between a payment gateway and payment orchestration?
A gateway connects a merchant's checkout to a processor or acquirer and passes transactions securely. An orchestration layer sits above one or more gateways or PSPs and decides where each transaction goes, adding routing rules, fallbacks, tokenisation across providers and consolidated reporting.
Does gateway or orchestration software make me an acquirer or PSP?
No. Software routes and records transactions. Acquiring payment transactions is a regulated payment service in the EU under PSD2, and card acceptance also requires scheme membership or a sponsoring acquirer. You still need a regulated acquirer or PSP to process and settle funds.
What is core fintech software?
Core fintech software runs customer-facing financial products: onboarding and KYC, multi-currency accounts and a ledger, transfers, card management, sometimes crypto wallets, plus compliance and back-office tools. It connects to banks, EMIs, card issuers and custodians that provide the regulated services.
Are SAMFPay and SAMFCore the same product?
No. According to the vendor, SAMFPay is standalone payment gateway and orchestration software, separately licensed, while SAMFCore is a modular platform for accounts, payments, cards, crypto, compliance and administration. Neither is a regulated acquiring bank or e-money institution.
Is source code included with SAMFPay?
The vendor page describes a proposed perpetual licence with optional source code where authorised, and states that commercial availability and licensing rights are subject to final contractual authorisation. Source-code rights should therefore be treated as a negotiated contract term, not a given.
Hosted gateway or licensed software: which is cheaper?
It depends on volume, team and scope. Hosted services shift infrastructure and PCI scope to the provider in exchange for ongoing fees; licensed software shifts hosting, security, upgrades and compliance work to you. Compare quotes and internal costs over the same multi-year period rather than headline prices.
How does this relate to buying a payment company?
An acquired company provides a legal entity and regulatory status; software provides the operating system. You typically need both, plus regulated partners. Decide which business you are building first, then choose the software category that fits it.
Sources and method
Legal statements are drawn from regulators and official legal texts; product descriptions come from each vendor's own public website as accessed on 11 October 2026 and are vendor claims, not independent test results. This guide is general information, not legal, tax or investment advice. Obtain qualified advice for your jurisdiction and transaction.
- Directive (EU) 2015/2366 on payment services (PSD2), incl. Annex I — EUR-Lex, Official Journal of the EU
- PCI Security Standards Council (PCI DSS) — PCI SSC
- Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA) — EUR-Lex
- Register of payment and electronic money institutions — European Banking Authority
- Self-regulatory organisations (SROs) — FINMA
- SAMFPay – payment gateway and orchestration software (vendor page) — Swiss AMF AG (affiliated vendor)
- SAMFCore – platform overview (vendor page) — Swiss AMF AG (affiliated vendor)
- Spreedly – payments orchestration platform (vendor page) — Spreedly (unaffiliated)
- Primer – payments platform (vendor page) — Primer (unaffiliated)