How to Choose a Crypto Payment Gateway and Processor: The Due Diligence Nobody Writes About
Every comparison table ranks providers on licensing, settlement and fees. Those are the easy questions. The ones that decide whether the system survives contact with real customers sit a layer below, in operational policy that most providers don’t publish.
Search for guidance on picking a crypto payment gateway and you get the same article about fifteen times over. Eight providers, a comparison table, five criteria: licensing coverage, settlement model, supported assets, integration options, fees. Usually written by one of the eight.
Those criteria are fine. They are simply the part of the decision that is easy to research, which is why everyone researches it. The parts that generate support tickets, reconciliation disputes and the occasional frozen settlement live one layer down – in policy documents that rarely make it to a pricing page, and that most merchants never think to ask for until month three.
What follows is the list of questions I would put in front of a provider before signing anything.
The headline rate is the smallest part of the price
Processing fees in this market cluster between 0.4% and 1.5%. Providers advertise that number because it is comparable, and because it flatters them. It is also rarely what you end up paying.
The real cost accumulates in four places.
The conversion spread. If you settle in fiat, someone converts your crypto, and the rate they use is not the mid-market rate. Another 0.3% to 1% on top of the processing fee is normal, and it is almost never disclosed publicly. Ask for the reference rate and the spread in basis points, in writing.
Payout costs. Network fees on crypto payouts, SEPA or SWIFT charges on fiat ones, sometimes a flat per-payout fee. Settle daily instead of weekly and you pay this five times as often.
Minimum settlement thresholds. Some providers hold funds until a minimum balance accrues. For a merchant with lumpy volume, that is a working capital problem wearing the costume of a policy.
Rolling reserves. Card acquiring exported this practice into crypto, and merchants in higher-risk categories routinely see 5% to 10% withheld for 30 to 180 days. It is negotiable. It also tends to appear only after underwriting, by which point you have already told your board the merger is going ahead.
Stack those together and an advertised 1% can land closer to 2.5% all-in. That may still beat card rates on cross-border volume, which is the comparison that actually matters. But you want the number before you build the business case, not after.
Four failure modes that only show up in production
No vendor comparison prepares you for these. All four are routine.
Underpayment
A customer settles a 100 USDT invoice from an exchange account. The exchange deducts its withdrawal fee from the amount sent rather than adding it on top, so 99.2 USDT arrives. What happens next is entirely a matter of provider policy.
Some providers settle anything inside a tolerance band and absorb the difference. Others mark the invoice partially paid and stop – which means a support ticket, a manual review, and a customer who is fairly sure they have been robbed. At a few thousand transactions a month, the gap between those two policies is a headcount decision.
Ask what the tolerance band is, whether you can configure it, and who covers the shortfall inside it.
Wrong-network deposits
USDT exists on Ethereum, Tron, BNB Chain, Solana, Polygon, Arbitrum and several other chains. Customers pick whichever their wallet defaults to, or whichever is cheapest that week. Send ERC-20 tokens to an address the gateway generated for a different chain and the money is gone, unless the provider controls the key on both networks and is prepared to do manual recovery.
Ask whether recovery is offered at all, what it costs, how long it takes, and which chains are out of scope entirely.
Rate-lock expiry
Providers lock the exchange rate when the invoice is created, usually for 10 to 20 minutes. Bitcoin can move 2% inside that window. If the payment confirms after expiry, one of three things happens: the invoice re-quotes and the customer is now underpaid by definition, the provider settles at the new rate and you absorb the difference, or the whole thing lands in manual review.
Find out which, because at volume it is a line item.
Confirmation policy
This one quietly sets your checkout conversion rate. A provider that waits for three Bitcoin confirmations makes your customer sit through roughly half an hour. Three confirmations on Tron takes under ten seconds.
If you sell digital goods, credit an account balance, or run anything where the customer expects the product immediately, the per-chain confirmation table is a product decision rather than a technical footnote. Ask for it as a table.
Compliance moved in 2026, and it moved toward the merchant
Two changes are worth re-checking your shortlist against.
MiCA’s transitional window closed on 1 July 2026. Grandfathering under Article 143(3) has ended across all 30 EEA states, and ESMA confirmed in April that there would be no extension. Any provider still operating in the EU on a legacy national registration is doing so outside the law. Verifying this takes two minutes and should be done against the ESMA register rather than the provider’s own website, where “licensed” does a great deal of quiet work.
The second is transfer-of-funds reporting. Under Regulation 2023/1113, transfers between regulated crypto firms now carry originator and beneficiary data, and transfers involving self-custody wallets above the threshold require verification of who owns the wallet. For a merchant this surfaces as customers paying from their own wallets getting held for extra checks. That is not an argument against accepting crypto. It is an argument for knowing the policy before your customers find it for you.
Related, and more consequential day to day: every serious provider screens incoming deposits against blockchain analytics. A payment arriving from an address with exposure to a sanctioned entity or a mixing service gets frozen. The questions are who carries that loss, what the appeal path looks like, and what risk score triggers a hold. Most contracts assign the loss to the merchant by default. That clause is negotiable, and remarkably few merchants try.
Your provider might not be here in eighteen months
Coinbase Commerce shut down for merchants outside the United States and Singapore on 31 March 2026, with no extension offered. Impacted businesses had to export transaction history, move funds off the platform and rebuild their checkout on a deadline they had no part in setting.
Plan for that scenario rather than assuming it away. Three concrete checks:
-
Can you export complete transaction history, including cost basis at the moment of receipt, in a format your accounting system actually ingests?
-
Is the integration system abstracted well enough that swapping providers is a configuration change rather than a rebuild?
-
If the provider holds funds, are client assets segregated from operating capital, and can you verify that independently?
Running two providers in parallel is overkill for most merchants. Keeping the system integration portable is not.
If you operate in a high-risk vertical, the shortlist is a different shortlist
Most of the providers that dominate these comparison articles maintain prohibited-business lists covering gambling, forex, adult content and a long tail of adjacent categories. You typically discover this several weeks into underwriting.
For iGaming operators, brokers and other high-frequency businesses the relevant set is much narrower, and the evaluation criteria shift with it. Throughput, payout automation and deposit-withdrawal cycle handling matter more than checkout polish. Specialists in this segment – CoinsPaid in Europe, or a crypto payment processor such as 0xProcessing, which works with gaming and trading platforms – underwrite and price these flows on different assumptions than a mainstream e-commerce gateway does, and they are built around recurring deposits and withdrawals rather than one-off purchases.
The practical advice is dull but saves weeks: qualify providers on vertical acceptance first, before evaluating anything else.
The ten questions to put in the RFP
Phrase them so the answers are comparable across vendors:
- All-in cost on a €10,000 crypto-to-EUR settlement, with the conversion spread stated in basis points and payout fees itemised.
- Underpayment tolerance band, whether it is configurable, and who covers shortfalls inside it.
- Confirmation requirements per supported chain.
- Rate-lock duration and precise behaviour on expiry.
- Wrong-network recovery: scope, fee, turnaround, excluded chains.
- Deposit screening: which analytics provider, what threshold triggers a hold, how loss is allocated, what the appeal process is.
- Rolling reserve: percentage, duration, release schedule.
- Settlement timing, including weekends and public holidays.
- Data export: available fields, formats, whether cost basis at receipt is included.
- Current regulatory authorisations, with links to the relevant public registers.
Any provider worth signing with will answer all ten without much resistance. The ones that deflect have told you something useful for free.
The point
The comparison tables are not wrong. They are answering the question that is easy to answer, and they will get you to a shortlist of three or four providers perfectly well.
What separates those three or four is operational policy – and operational policy only becomes visible if you ask for it in writing while you are still a prospect rather than a customer. After that, you get whatever the default was.
Every comparison table ranks providers on licensing, settlement and fees. Those are the easy questions. The ones that decide whether the system survives contact with real customers sit a layer below, in operational policy that most providers don’t publish.
Search for guidance on picking a crypto payment gateway and you get the same article about fifteen times over. Eight providers, a comparison table, five criteria: licensing coverage, settlement model, supported assets, integration options, fees. Usually written by one of the eight.
Those criteria are fine. They are simply the part of the decision that is easy to research, which is why everyone researches it. The parts that generate support tickets, reconciliation disputes and the occasional frozen settlement live one layer down – in policy documents that rarely make it to a pricing page, and that most merchants never think to ask for until month three.
What follows is the list of questions I would put in front of a provider before signing anything.
The headline rate is the smallest part of the price
Processing fees in this market cluster between 0.4% and 1.5%. Providers advertise that number because it is comparable, and because it flatters them. It is also rarely what you end up paying.
The real cost accumulates in four places.
The conversion spread. If you settle in fiat, someone converts your crypto, and the rate they use is not the mid-market rate. Another 0.3% to 1% on top of the processing fee is normal, and it is almost never disclosed publicly. Ask for the reference rate and the spread in basis points, in writing.
Payout costs. Network fees on crypto payouts, SEPA or SWIFT charges on fiat ones, sometimes a flat per-payout fee. Settle daily instead of weekly and you pay this five times as often.
Minimum settlement thresholds. Some providers hold funds until a minimum balance accrues. For a merchant with lumpy volume, that is a working capital problem wearing the costume of a policy.
Rolling reserves. Card acquiring exported this practice into crypto, and merchants in higher-risk categories routinely see 5% to 10% withheld for 30 to 180 days. It is negotiable. It also tends to appear only after underwriting, by which point you have already told your board the merger is going ahead.
Stack those together and an advertised 1% can land closer to 2.5% all-in. That may still beat card rates on cross-border volume, which is the comparison that actually matters. But you want the number before you build the business case, not after.
Four failure modes that only show up in production
No vendor comparison prepares you for these. All four are routine.
Underpayment
A customer settles a 100 USDT invoice from an exchange account. The exchange deducts its withdrawal fee from the amount sent rather than adding it on top, so 99.2 USDT arrives. What happens next is entirely a matter of provider policy.
Some providers settle anything inside a tolerance band and absorb the difference. Others mark the invoice partially paid and stop – which means a support ticket, a manual review, and a customer who is fairly sure they have been robbed. At a few thousand transactions a month, the gap between those two policies is a headcount decision.
Ask what the tolerance band is, whether you can configure it, and who covers the shortfall inside it.
Wrong-network deposits
USDT exists on Ethereum, Tron, BNB Chain, Solana, Polygon, Arbitrum and several other chains. Customers pick whichever their wallet defaults to, or whichever is cheapest that week. Send ERC-20 tokens to an address the gateway generated for a different chain and the money is gone, unless the provider controls the key on both networks and is prepared to do manual recovery.
Ask whether recovery is offered at all, what it costs, how long it takes, and which chains are out of scope entirely.
Rate-lock expiry
Providers lock the exchange rate when the invoice is created, usually for 10 to 20 minutes. Bitcoin can move 2% inside that window. If the payment confirms after expiry, one of three things happens: the invoice re-quotes and the customer is now underpaid by definition, the provider settles at the new rate and you absorb the difference, or the whole thing lands in manual review.
Find out which, because at volume it is a line item.
Confirmation policy
This one quietly sets your checkout conversion rate. A provider that waits for three Bitcoin confirmations makes your customer sit through roughly half an hour. Three confirmations on Tron takes under ten seconds.
If you sell digital goods, credit an account balance, or run anything where the customer expects the product immediately, the per-chain confirmation table is a product decision rather than a technical footnote. Ask for it as a table.
Compliance moved in 2026, and it moved toward the merchant
Two changes are worth re-checking your shortlist against.
MiCA’s transitional window closed on 1 July 2026. Grandfathering under Article 143(3) has ended across all 30 EEA states, and ESMA confirmed in April that there would be no extension. Any provider still operating in the EU on a legacy national registration is doing so outside the law. Verifying this takes two minutes and should be done against the ESMA register rather than the provider’s own website, where “licensed” does a great deal of quiet work.
The second is transfer-of-funds reporting. Under Regulation 2023/1113, transfers between regulated crypto firms now carry originator and beneficiary data, and transfers involving self-custody wallets above the threshold require verification of who owns the wallet. For a merchant this surfaces as customers paying from their own wallets getting held for extra checks. That is not an argument against accepting crypto. It is an argument for knowing the policy before your customers find it for you.
Related, and more consequential day to day: every serious provider screens incoming deposits against blockchain analytics. A payment arriving from an address with exposure to a sanctioned entity or a mixing service gets frozen. The questions are who carries that loss, what the appeal path looks like, and what risk score triggers a hold. Most contracts assign the loss to the merchant by default. That clause is negotiable, and remarkably few merchants try.
Your provider might not be here in eighteen months
Coinbase Commerce shut down for merchants outside the United States and Singapore on 31 March 2026, with no extension offered. Impacted businesses had to export transaction history, move funds off the platform and rebuild their checkout on a deadline they had no part in setting.
Plan for that scenario rather than assuming it away. Three concrete checks:
-
Can you export complete transaction history, including cost basis at the moment of receipt, in a format your accounting system actually ingests?
-
Is the integration system abstracted well enough that swapping providers is a configuration change rather than a rebuild?
-
If the provider holds funds, are client assets segregated from operating capital, and can you verify that independently?
Running two providers in parallel is overkill for most merchants. Keeping the system integration portable is not.
If you operate in a high-risk vertical, the shortlist is a different shortlist
Most of the providers that dominate these comparison articles maintain prohibited-business lists covering gambling, forex, adult content and a long tail of adjacent categories. You typically discover this several weeks into underwriting.
For iGaming operators, brokers and other high-frequency businesses the relevant set is much narrower, and the evaluation criteria shift with it. Throughput, payout automation and deposit-withdrawal cycle handling matter more than checkout polish. Specialists in this segment – CoinsPaid in Europe, or a crypto payment processor such as 0xProcessing, which works with gaming and trading platforms – underwrite and price these flows on different assumptions than a mainstream e-commerce gateway does, and they are built around recurring deposits and withdrawals rather than one-off purchases.
The practical advice is dull but saves weeks: qualify providers on vertical acceptance first, before evaluating anything else.
The ten questions to put in the RFP
Phrase them so the answers are comparable across vendors:
- All-in cost on a €10,000 crypto-to-EUR settlement, with the conversion spread stated in basis points and payout fees itemised.
- Underpayment tolerance band, whether it is configurable, and who covers shortfalls inside it.
- Confirmation requirements per supported chain.
- Rate-lock duration and precise behaviour on expiry.
- Wrong-network recovery: scope, fee, turnaround, excluded chains.
- Deposit screening: which analytics provider, what threshold triggers a hold, how loss is allocated, what the appeal process is.
- Rolling reserve: percentage, duration, release schedule.
- Settlement timing, including weekends and public holidays.
- Data export: available fields, formats, whether cost basis at receipt is included.
- Current regulatory authorisations, with links to the relevant public registers.
Any provider worth signing with will answer all ten without much resistance. The ones that deflect have told you something useful for free.
The point
The comparison tables are not wrong. They are answering the question that is easy to answer, and they will get you to a shortlist of three or four providers perfectly well.
What separates those three or four is operational policy – and operational policy only becomes visible if you ask for it in writing while you are still a prospect rather than a customer. After that, you get whatever the default was.