Payment Gateway

Your gateway isn't just a technical detail. It determines your PCI scope, your features, and what happens when something breaks.

CambridgeCommerce helps merchants select, configure, and integrate the right payment gateway; one that fits their processor, their platform, and the features they actually need.

Talk to us about your gateway Apply for a merchant account

Many merchants inherit a gateway from their first processor without evaluating whether it's the right fit. Gateway lock-in can complicate future processor switches, limit access to features like recurring billing and Level 2/3 data, and in some cases expand your PCI compliance scope unnecessarily. The gateway decision deserves the same attention as the processor decision.

What a payment gateway actually does

A gateway is the technology layer that sits between your checkout and your payment processor. When a customer enters card details, the gateway encrypts that data, routes the authorization request to the processor, receives the response, and returns an approval or decline to your checkout in seconds. It handles the transport and security of the transaction; the processor handles the banking relationship and settlement.

That distinction matters because the gateway and processor can be separate vendors. Many merchants use one gateway across multiple processors, which is why gateway selection affects processor flexibility. A gateway tied exclusively to one processor locks you in. A gateway that supports multiple processors gives you the ability to switch processors or add a backup account without rebuilding your checkout.

What gateway selection actually determines

PCI scope

How cardholder data flows through your system determines your PCI compliance burden. A gateway with hosted payment fields or an iFrame keeps card data off your servers entirely, reducing your PCI scope to SAQ A. Direct API integrations that handle raw card data require SAQ D compliance; significantly more work and cost.

Feature availability

Recurring billing, Level 2 and Level 3 data, customer vaulting, partial authorizations, and surcharging capabilities vary significantly across gateways. A gateway that doesn't support the features your business model requires forces workarounds or a rebuild later.

Processor flexibility

Gateways that support multiple processor integrations give you the ability to switch processors or add a redundant account without touching your checkout code. Proprietary gateways tied to one processor mean a processor switch requires a gateway migration as well.

Platform integrations

Shopify, WooCommerce, Salesforce, HubSpot, and most major ecommerce and CRM platforms have native gateway integrations for a short list of providers. Choosing a gateway your platform supports natively avoids custom development and reduces ongoing maintenance.

Redundancy and failover

A single gateway with no failover means gateway downtime becomes revenue downtime. Multi-processor gateways can route transactions to a backup processor if the primary is unavailable. For merchants with meaningful daily volume, this is worth designing for explicitly.

Gateway cost

Gateway fees vary from $0 (bundled with processor) to $25 or more per month plus per-transaction fees. For merchants processing multiple payment methods or using advanced features, gateway cost can be a meaningful line item. We review whether what you're paying is competitive.

Why Cambridge uses NMI for many of our clients: NMI (Network Merchants, Inc.) is a payment gateway that supports connections to hundreds of processors, meaning your gateway relationship stays intact when your processor changes. It offers a robust feature set including recurring billing, customer vaulting, Level 2/3 data, ACH, and surcharging. For merchants who want flexibility to move between processors without a checkout rebuild; or who want to add a redundant processor later; NMI provides that foundation. It's also the gateway behind our own merchant portal, which clients can access directly. Not every merchant needs NMI; but for those who do, it's the right tool.

“We had issues working with Stripe and Squareup, so we moved to Authorize.net and it was a very outdated and confusing system to work with; especially with our recurring payments. Then a friend recommended Cambridge and they made everything so easy to understand. Anytime I've had issues or concerns, I had the support I needed to find and decide on the best solution. CambridgeCommerce helped us set up an easy to use system which can be adapted whenever challenges arise. They allow me to stop worrying about the complex world of payment processing and focus on growing my business.”
Health and wellness subscription business Gateway migration from three prior platforms; one stable setup

Common gateway problems we solve

Frequently asked questions

Do I have to use my processor's gateway?
No. Most processors support multiple third-party gateways in addition to any proprietary gateway they offer. Some processors provide their own gateway at no additional cost, which can simplify the stack. Others integrate well with independent gateways like NMI, Authorize.net, or Braintree. The right answer depends on your platform integrations, feature needs, and whether processor flexibility matters to you.
What does gateway tokenization mean for PCI compliance?
Tokenization replaces a cardholder's actual card number with a surrogate value (the token) that can be stored and used for future transactions without exposing the real card data. When your gateway handles tokenization, card data never reaches your servers in a usable form. This is one of the most effective tools for reducing PCI scope and the data security risk that comes with storing payment credentials.
What happens if my gateway goes down?
If your gateway is down and you have no failover, transactions fail until it comes back up. For merchants processing significant daily volume, even a two-hour outage can be a material revenue event. Gateways with multiple processor connections can route around a processor issue; but a gateway-level outage requires a backup gateway or a manual processing fallback. We help merchants design for this explicitly rather than discovering it during an incident.
Can you help migrate from my current gateway?
Yes. Gateway migrations involve moving tokenized card data (where the vault allows it), updating integrations, and coordinating the cutover timing to avoid a transaction gap. For merchants with active recurring billing, the migration plan for stored tokens is the most critical piece. We've coordinated gateway migrations for merchants with complex recurring billing setups and know where the risks are.
Get the foundation right

Talk through your gateway setup before you build on the wrong foundation.

Gateway decisions affect PCI scope, feature access, and processor flexibility for years. We'll help you choose the right one before the choice gets expensive to reverse.