Google 5 star rating
Trustpilot 5 star rating
3500 + Expert Advisors

3500

Expert Advisors

50 + Branch Offices

50

Branch Offices

Get Free Expert Consultation

Get Update on Get Update on Whatsapp Whatsapp

Payment Gateway License: An Overview

Are you a passionate entrepreneur or business owner aiming to expand your digital presence and accept online payments? If yes, you are at the right place.

Payment Gateway License is a permit/ certification granted for the transfer of transaction information to acquiring banks and responses from issuing banks. The application for the grant of a certificate of authorization must be made to the Reserve Bank of India (i.e., RBI) under section 5 of the PSS Act (Payment and Settlement Systems Act), 2007.

In simple terms, the issuance of a rbi payment gateway license ensures the establishment of a payment gateway system that facilitates electronic transfer between customers and sellers. Also, consistent growth has been observed in the payment gateway landscape since the inception of the digital payment system in India.

Unsure about meeting RBI’s payment gateway standards? Our seasoned professionals will guide you through every compliance requirement for seamless licensing.

Payment Gateway License
What are Payment Gateways?

What are Payment Gateways?

Payment gateways are intermediary networks providing technology infrastructure to route and facilitate the processing of an online transaction without any involvement in the handling of funds. Further, it works as a tunnel that directly connects the bank account to the portal where you need to transfer the amount.

Simply, the payment gateway acts as a financial service software that produces information from the buyer’s bank and further supplies the same transaction information to the receiving bank.

Benefits of Obtaining a Payment Gateway License in India

Have a look over the key benefits of obtaining a payment gateway license in India, as explained below:

Benefits of Payment Gateway License in India
PCI-DSS Wallet

PCI-DSS Wallet

Compliance with PCI-DSS Wallet provides security to the application users by securing their personal data in the portal or gateway for recurring payments.

White-Label Wallet

White-Label Wallet

According to the latest trend, some payment gateways permit customers to make digital transactions from mobile wallet applications for all their operations and transactions.

Fraud Screening Tools

Fraud Screening Tools

Payment gateways provide their customer with the benefit of FST (Fraud Screening Tools- like Card Code Value, Address Verification Service, Card Verification Value) for the purpose of reducing the risk of losing personal data.

One-Stop Solution

One-Stop Solution

Payment gateways provide one one-stop solution by consolidating a range of digital commerce platforms, shopping carts, and different software systems into a single application programming interface.

Multiple Payment Options

Multiple Payment Options

The payment gateway license in India allows businesses to process multiple payment options like credit/ debit cards, digital wallets, and net banking, enhancing customer satisfaction.

Market Expansion Opportunities

Market Expansion Opportunities

The RBI payment gateway license facilitates international payment processing for businesses expanding their market reach beyond the local borders.

Eligibility Criteria for Obtaining Payment Gateway License

The applicants must comply with the following eligibility criteria required to obtain a payment gateway license in India:

Checklist for Applicants to Apply for Payment Gateway License

    • Company Registered under the Companies Act, 1956/2013
    • Minimum 2 Members
    • Minimum 2 Directors
    • Address Proof of the Business
    • 5 Years’ Business Plan
    • Current Bank Account of the Company
    • System Flow & Code Testing Report by Software Certifying Agency
    • Service Tax Registration Number
    • Compliance with Payment Card Industry Data Security Standard (PCI DSS)
    • Net Worth requirement of at least Rs. 15 crores
    • Net worth of up to Rs. 25 crores within 3 years of business operations
Documents Required for RBI Payment Gateway License

Documents Required for RBI Payment Gateway License

Have a look over the list of documents required for obtaining an RBI Payment Gateway License in India, as below provided:

  • Company’s Certificate of Incorporation (COI)
  • Director’s PAN Card
  • Address Proof of Directors
  • Digital Signature Certificate (DSC) of Directors
  • Director Identification Number (DIN) of Directors
  • Registered Office’s Address Proof
  • Company’s Current Bank Account Details
  • Business Plan for the Next 5 Financial Years
  • Code Testing Report by a Software Agency

How to Apply for Payment Gateway License Online?

Given below is the brief stepwise guide that will help you know how to apply for payment gateway license online in India -

Apply for Payment Gateway License Online

Step 1. Filing of Registration Application

The applicant must file an application for authorization in the prescribed Form A to the Chief General Manager of the Department of Payment & Settlement Systems at the Central/Regional office of the RBI in Mumbai or at other offices of the RBI, as prescribed under the section 5(1) of the PSS Act, 2007.

Step 2. Authenticity Check By RBI

The RBI is further authorized to check the authenticity and verify the information & credentials furnished by the applicant and hold such types of inquiries as it may consider required for satisfying itself.

Step 3. Compliance with Authorization Conditions

The RBI is further authorized to take conditions into account for the issuance of the certificate of authorization as prescribed under section 7 of the Payment and Settlement Systems Act, 2007.

Step 4. Issuance of Authorization Certificate

The RBI, if satisfied with all requirements laid under section 7(1) of the PSS Act, 2007, must issue the Authorization Certificate in Form B, authorizing the commencement and carrying out of a payment system.

Step 5. Processing of Authorization

Under section 7 (4) of the PSS Act, 2007, the RBI shall process every application for authorization within 6 months from the filing date.

Essentials of Payment Gateway System

Have a look over the essential requirements required for obtaining a payment gateway system in India, as explained below:

Components of Payment Gateway System

  • Merchant Agreement - Merchant Agreement is a contract between a business and the respective payment service provider that provides acceptance, authorization, processing and settlement of payment.
  • Secure Electronic Transactions - Secured Electronic Transactions (SET) are provided by the main payment providers of electronic transactions, such as Visa and MasterCard.

Types of Payment Gateway Providers

  • Second-Party Provider - Second-party providers are payment gateway providers offering services starting at a low TDR (i.e., Transaction Discount Rate) and a high transaction cost.
  • Third-Party Provider - Third-party providers, also known as non-bank payment aggregators, are type of payment gateway providers that have a low system setup cost, i.e., a TDR of around 2 to 4%.

How Does a Payment Gateway Operate in India?

Once a customer has placed his/ her order from an online website, there are a series of operations that are carried out by the Payment Gateway, as explained below:

Encryption

Encryption

Once the browser used by the user encrypts the information that has to be sent to the respective vendor’s server, the payment gateway transmits the transaction data to the specified payment processor.

Request for Authorization

Request for Authorization

Once the data is successfully received by the payment processor, it further transmits the same to the respective card association. Furthermore, the bank that has issued the payment card checks the transaction at this point and then denies or agrees on it accordingly.

Employment Tax & TDS Obligations

Filing of Order

Once the bank agrees to the transaction made, the authorization concerning the customers and merchant is forwarded to the main processor of the payment gateway and further to the portal for the purpose of processing payment for the interpretation of data/ information.

Conditions for Obtaining a Certificate of Authorization

The applicant must comply with the following conditions before obtaining a certificate of authorization as prescribed under section 7 of the Payment and Settlement Systems Act, 2007:

Conditions for Obtaining a Certificate of Authorization
  • The necessity for the proposed payment mechanism or the services that have been declared to be undertaken by it
  • The technical standards that have been decided for the payment mechanism or the structure of the decided payment system
  • The terms and conditions, inclusive of the security procedure, for the operation of the proposed payment system
  • The method in which the transfer of funds is carried within the given payment system
  • The procedure for netting of payment instructions that affect the payment obligations under the payment system
  • The overall management’s financial status, experience, and the integrity of the applicant
  • The terms & conditions that govern and regulate the relationship of the customers with the respective payment providers
  • The credit & monetary policies
  • Time frame for authorization
  • Such other factors may be considered relevant by the RBI

IT Requirements for Obtaining RBI Payment Gateway License

The entities seeking RBI payment gateway license must comply with the following IT systems and security requirements as prescribed in Annexure 2 of the Guidelines on Regulation of Payment Aggregators and Payment Gateways:

Information Security Governance

Information Security Governance

The entities must comply with the comprehensive security risk assessment of their people, IT business process, environment, etc., to identify risk exposures with remedial measures and residual risks.

Information Security Governance

The entities must comply with the comprehensive security risk assessment of their people, IT business process, environment, etc., to identify risk exposures with remedial measures and residual risks.

Data Security Standards

Data Security Standards

The entities must implement data security standards and best practices like PCI-DSS, PA-DSS, the latest encryption standards, transport channel security, etc.

Data Security Standards

The entities must implement data security standards and best practices like PCI-DSS, PA-DSS, the latest encryption standards, transport channel security, etc.

Security Incident Reporting

Security Incident Reporting

The entities shall ensure the reporting of security incidents/cardholder data breaches and cyber security incident reports within the time period stipulated by the RBI.

Security Incident Reporting

The entities shall ensure the reporting of security incidents/cardholder data breaches and cyber security incident reports within the time period stipulated by the RBI.

Merchant Onboarding

Merchant Onboarding

The entities are authorized to undertake comprehensive security assessments during the process of merchant onboarding to maintain minimum baseline security controls.

Merchant Onboarding

The entities are authorized to undertake comprehensive security assessments during the process of merchant onboarding to maintain minimum baseline security controls.

Cyber Security Audit and Reports

Cyber Security Audit and Reports

The entities are authorized to submit quarterly, internal annual external audit reports, bi-annual vulnerability assessment penetration test (VAPT) reports, PCI-DSS, reports of compliance (ROC), etc., to the IT Committee.

Cyber Security Audit and Reports

The entities are authorized to submit quarterly, internal annual external audit reports, bi-annual vulnerability assessment penetration test (VAPT) reports, PCI-DSS, reports of compliance (ROC), etc., to the IT Committee.

IT Governance

IT Governance

Furthermore, the Board must frame an IT policy for regular management of IT functions & detailed documentation in terms of procedure and guidelines implemented.

IT Governance

Furthermore, the Board must frame an IT policy for regular management of IT functions & detailed documentation in terms of procedure and guidelines implemented.

Enterprise Data Dictionary

Enterprise Data Dictionary

The entities must maintain an enterprise data dictionary for incorporating the organization’s data syntax rules which enables sharing of data across applications and systems.

Enterprise Data Dictionary

The entities must maintain an enterprise data dictionary for incorporating the organization’s data syntax rules which enables sharing of data across applications and systems.

Cryptographic Requirement

Cryptographic Requirement

The entities must select a well-established international standards encrypted algorithm, subject to rigorous scrutiny by an international community of cryptographers or approved by authoritative professional bodies, reputable security vendors or government agencies.

Cryptographic Requirement

The entities must select a well-established international standards encrypted algorithm, subject to rigorous scrutiny by an international community of cryptographers or approved by authoritative professional bodies, reputable security vendors or government agencies.

Forensic Readiness

Forensic Readiness

All the security events from the entity's infrastructure, like applications, servers, middleware, endpoints, networks, authentication events, databases, web services, cryptographic events, etc., must be collected, investigated and analyzed for the purpose of proactive identification of security alerts.

Forensic Readiness

All the security events from the entity's infrastructure, like applications, servers, middleware, endpoints, networks, authentication events, databases, web services, cryptographic events, etc., must be collected, investigated and analyzed for the purpose of proactive identification of security alerts.

Points to Know before Obtaining a License for Payment Gateway

If you are a business owner, you must understand these key points or essential requirements to obtain a RBI license for payment gateway in India.

PCI Audit and Final Certification Exercise

  • PCI DSS Scoping and Gap Assessment
  • PCI DSS Formal Risk Assessment
  • PCI DSS Policy & Procedure Review
  • PCI DSS Final Audit and Certification
  • Report Attestation and Issuance (AOC, ROC, COC)
  • Template Sharing
  • Application Security Testing
  • Application Secure Code Review
  • ASV Scan for Up to 5 IPs
  • Internal VA for Up to 10 IPs
  • External Penetration Test for 5 IPs
  • Internal Penetration Test for 10 IPs

Network Architecture Diagram Documentation

  • Antivirus Policy
  • Firewall Configuration Policy
  • DMZ and Internal Policy
  • Patch Management Policy
  • DB Access Policy
  • Asset Inventory Information
  • Change Control Policy
  • Data Retention and Disposal Policy
  • Physical Security Policy
  • Data Control and Access Control Policy
  • PCI DSS Awareness Training Policy
  • Password Policy
  • Security Logs and Events Policy

Infrastructure Setupn

  • DB Hardening
  • DMZ and Internal Zone
  • OS Hardening
  • Centralized Antivirus Server
  • Patches Update
  • NTP Server
  • MFA Server
  • VPN Setup
  • FIM Server
  • Firewall Rules

Difference Between Payment Gateway and Payment Aggregator

The difference between payment gateway and payment aggregator is as explained below:

S.no. Aspects Payment Gateway Payment Aggregator
1. Meaning An online e-commerce software that facilitates online payment transactions without handling funds. It simply provides technology. An e-commerce platform or interface that aggregates multiple payment applications together on one single platform. It simply handles funds.
2. Examples ICICI Bank, Visa, SBI, MasterCard, RuPay, etc. Razorpay, CC Avenue, PayUMoney, Billdesk, Instamojo, Citrus, etc.
3. Role Acts as an intermediary between banks & websites. An interface not responsible for the transfer of payments.
4. Scope Only online transactions Both online and offline transactions
5. Payment Options Restricted payment option Multiple payment options
6. Payment Success Rate (PSR) As much as the gateway can manage Significantly higher payment success rate.
7. Ownership Owned by public and private banks, merchants, vendors, and payment aggregators. Owned by Fintech players like Paytm.
8. Permissions Authorization from RBI under PSS Act, 2007. License from the Payment Card Industry (Data Security Standards/ PCI DSS).

Services Offered by Payment Gateways

Besides the facility of quick payments, the payment gateways offer additional services/ facilities, as provided below:

  • Delivery address verification
  • Advanced visual system checks
  • Computer fingerprinting technology
  • Velocity pattern analysis
  • Identity morphing detection
  • Calculation of tax for authorization of request forwarded to the respective processor
business operations and strategic

Why is Corpbiz the Top Choice for a Payment Gateway License?

Business Model

Business Model

We begin our services by providing a business model best suited according to the types of transactions handled and the need for the payment gateway system.

Network of 200+ Regulatory Experts

Network of 200+ Regulatory Experts

Corpbiz comprises a network of 10,000+ experienced regulatory experts with understanding and knowledge regarding the registration of payment gateway license in India.

99% Approval Rate

99% Approval Rate

Our seasoned regulatory experts ensure a 99% success rate for processing payment gateway license applications without any hassle in the process.

 Assists in Documentation

Assists in Documentation

Corpbiz assists you in the preparation of essential documents, like a draft application, business plan, financial statement, and other documents required for obtaining a payment gateway license in India.

Manage Application

Manage Application

We ensure that the entire application procedure is managed in accordance with the provisions laid out under the Payment and Settlement Systems Act, 2007.

Legal Advisory Services

Legal Advisory Services

We offer simplified legal advisory services concerning the registration of payment gateway license and matters associated there with.

Compliance Management

Compliance Management

Our services for compliance management ensure business compliance with regulatory standards and other legal standards, providing for dispute resolution, risk management, contract drafting, etc.

Seamless Payment Processing System

Seamless Payment Processing System

We ensure that we provide a seamless and efficient payment processing system, which assists in revolutionizing your transactions and expanding your customer base.

Transparent Pricing

Transparent Pricing

We at Corpbiz offer transparent pricing to businesses and entities seeking payment gateway license in India. Our prices are affordable and the lowest in the trade.

Conduct Follow Up

Conduct Follow Up

We conduct thorough follow-up of your application to ensure on-time delivery of payment gateway licenses to the entities applying for registration under the PSS Act, 2007.

Solutions for 20+ Industries

Solutions for 20+ Industries

At Corpbiz, we are extending our licensing solutions to 20+ industries and helping entities secure the payment gateway license from the place of their comfort.

24/7 Availability

24/7 Availability

Our experts at Corpbiz ensure round-the-clock assistance to resolve your queries and handle the documentation work to help you apply for payment gateway license in India.

Frequently Asked Questions

Have a look at the answers to the most asked questions.

Payment gateways are intermediary elements providing technology infrastructure to route and facilitate the processing of an online transaction without any involvement in the handling of funds. Furthermore, it acts as a link between the banks and the websites, promoting the delivery of transaction reports.

A payment gateway license is a mandatory requirement for a business venture to perform digital transactions on its platform. Thus, we can conclude with the fact that a business cannot perform digital transactions without a payment gateway license.

The governing security standards, as prescribed under the Guidelines on Regulation of Payment Aggregators and Payment Gateways, 2020, are crucially important for the protection of sensitive information from any fraud and misrepresentation. It ensures eliminating unauthorized access to debit/ credit card information, internet banking IDs & passwords.

Second-party providers like HDFC, ICIIC, and Axis are types of payment gateway providers that offer services starting at a low TDR (i.e., Transaction Discount Rate) and a high transaction cost.

Third-party providers such as EBS, CC Avenue, Payzippy, PayU, and Direct Pay, also known as non-bank payment aggregators, are types of payment gateway providers that have a low system setup cost, i.e., a TDR of around 2 to 4%.

PCI DSS, which stands for Payment Card Industry Data Security Standard, contains rules and regulations that optimize the security of credit, debit, and cash transactions for the protection of cardholders facing scams.

A separate Website Privacy Policy and Terms and Conditions Policy must be secured to ensure compliance with IT regulations for the portal.

The authorization certificate in Form B is a certificate or license granted by the RBI for commencing and carrying on a payment gateway system, as provided under section 7(1) of the Payment and Settlement Systems Act, 2007.

Yes, a mandatory license/ authorization from RBI is required for operating a payment gateway system in India in a legally compliant manner.

In order to start your own payment gateway, the applicant companies are required to comply with the following steps needed to obtain a RBI payment gateway license in India:
  • Step 1: Filing of Registration Application
  • Step 2: Authenticity Check By RBI
  • Step 3: Compliance with Authorization Conditions
  • Step 4: Issuance of Authorization Certificate
  • Step 5: Processing of Authorization

A payment gateway license is a legal authorization granted by the RBI to operate a payment gateway system, safeguarding the interests of both merchants and customers.

Let’s understand the requirements for obtaining a payment gateway license in India. It must include entities registered under the Companies Act, 1956/ 2013, have a minimum of 2 members/ directors, address of the business and 5 years business plan. Besides this, the current bank account of the company, system flow & code testing report by a software certifying agency is required. In addition to this, service tax registration number and compliance with payment card industry data security standard (PCI DSS) are essential. Another significant requirement is having a net worth of at least Rs. 15 crores, which must reach up to Rs. 25 crores within 3 years of business operations.

No, GSTIN is not a mandatory requirement for obtaining a RBI payment gateway license for businesses having an annual turnover of less than Rs. 20 lakhs.

Some of the payment gateways might have a low transaction fee but relatively charge a higher monthly fee, more suitable for businesses with high transactions. However, some payment gateways charge no monthly fees but relatively have a higher transaction cost, which is more economical for businesses with low sales volume.

Since payment gateways do not come under a brokerage, no TDS/ further deduction is applicable on payment gateways in India.

E-commerce stores need a payment gateway system to take/ accept online credit/ debit card payments to run their business ventures successfully.

PayU is among the best online payment gateways, leading and empowering 5 lakhs+ businesses.

Yes, HDFC Banks’ SmartGATEWAY is a payment gateway that provides a one-stop platform designed to maximize conversion with a smooth payment experience for your customers.

About the Author


NE
Neha Dawra

Legal Researcher

Written by Neha Dawra. Last updated on Jun 3 2026, 10:16 PM

Neha Dawra has 4+ years of experience in legal research and intellectual property advisory. Her expertise lies in analyzing IP laws, drafting structured legal content, and simplifying complex registration procedures into clear, simple insights.

 

Testimonials

Updated testimonials from our customers

Trusted by thousands of businesses across India for seamless compliance, registrations, and advisory services.

100% Verified Reviews
Confidential & Secure
ISO 9001:2015 Certified
100000+
Happy Customers
4.9 / 5
Average Rating
98%
Satisfaction Rate
6+ Yrs
Industry Experience

Other similar services

Request a call back