9 Trust Signals CEE Merchants Should Look for in a Payment Provider

Before switching payment providers, CEE merchants should verify these nine trust signals, from licensing and PCI DSS evidence to settlement terms and exit
September 25, 2026
watch
3
мин. четене
9 trust signals CEE merchants should check when evaluating a payment provider

Choosing a payment provider means trusting another company with your checkout, your payouts and part of your customers' payment journey. You should not have to base that decision on brand recognition or a sales pitch.

Several of the most useful checks are public: who the company is, which authorised institution provides the regulated payment services and what security standards apply. Others, such as settlement terms, support and contract exit conditions, should be clear before you sign.

For CEE merchants, one extra detail matters. The platform you use and the institution providing the regulated payment services may be based in different EEA countries. That can be entirely normal under EU passporting rules. What matters is being able to see who does what and which terms apply to your business.

Here are nine checks worth making before you add or switch payment providers.

Key takeaways

  • Verify both the company and the licensed institution behind the regulated payment services.
  • An institution licensed elsewhere in the EEA may legally serve your market through passporting.
  • Current PCI DSS evidence matters more than a PCI badge on the website.
  • Compare the full fee stack, settlement terms and payout model before you sign.
  • Keep live features, roadmap promises, support terms and exit conditions separate and in writing.

The three tiers of a provider check

What you can verify independently

1. A named legal entity with a company number

Start with the footer or legal pages, not the homepage headline.

A payment provider or platform should tell you which legal company you are contracting with. Look for the legal name, company number and registered address, then check that information against an official company register.

The European Commission's Business Registers Interconnection System, or BRIS, connects business registers across the EU, Iceland, Liechtenstein and Norway. The company information displayed through the European e-Justice Portal is gathered from the participating national registers in real time.

You are looking for three things:

  • The legal entity exists and is active
  • The registered name and company number match the provider's legal information
  • The registered address is consistent with the company's disclosures

If you would rather go straight to your own national register, these are the ones that matter in this region:

‍

The company register and regulatory register answer different questions. One tells you that the company exists. The other tells you whether the institution providing regulated financial services has the necessary authorisation.

Keep in mind

A mismatch does not automatically mean something is wrong. Brands, subsidiaries and regulated partners can have different names. It does mean you should understand the relationship before signing.

‍

2. A named licensed institution behind the regulated payments

The company whose checkout or dashboard you use is not always the institution providing the regulated payment services.

That is normal in payments. A platform can provide the merchant-facing technology while an authorised payment institution, electronic money institution or bank handles the regulated part. The distinction between a payment service provider and a payment gateway helps explain why different companies can sit at different points in the same payment flow.

What you need to know is:

Which authorised institution provides the regulated payment services, and which authority supervises it?

For payment and electronic money institutions, you can check the answer in the European Banking Authority's central PSD2 register. It shows the institution, the services it is authorised to provide and its cross-border permissions.

For CEE merchants, check the passporting information too. An institution authorised in one EEA state may be allowed to serve merchants in another, so absence from your domestic register does not automatically mean something is wrong.

If anything looks unclear, verify it with the institution's home regulator.

Five-step process for verifying a payment provider’s legal entity, regulated institution, authorisation and EEA market coverage

3. Current PCI DSS evidence, not just a PCI badge

PCI DSS is the industry security standard for organisations that store, process or transmit payment card data. But a PCI logo by itself tells you very little about what was validated, when and for which part of the payment setup.

Start by asking:

  • What PCI DSS validation applies to the service you will use?
  • What scope does that validation cover?
  • When was it last validated?
  • Was an independent Qualified Security Assessor involved, where applicable?
  • Can the provider share its current Attestation of Compliance or equivalent evidence?

PCI DSS v4.0.1 is the current revision, and requirements that were initially future-dated under PCI DSS v4.x became effective on 31 March 2025.

For service providers registered with Visa, the Visa Global Registry of Service Providers is another useful check. Visa says listed service providers must revalidate their PCI DSS compliance every 12 months. Mastercard also publishes a list of registered service providers compliant with its Level 1 Site Data Protection requirements. 

Not appearing on one card scheme's public list does not by itself prove non-compliance. The provider's role and validation route matter. 

The useful test is whether it can explain the scope of its current PCI status and provide appropriate evidence when you ask.

What you should get in writing

4. Pricing that lets you model the real cost 

Published pricing is useful because it gives you something concrete to compare before you have a sales conversation.

Start with the card-pricing structure.

EU rules cap interchange fees for many consumer card transactions at 0.2% for debit and 0.3% for credit, while categories such as commercial cards fall outside those caps. But interchange is only one component of what a merchant ultimately pays. Those percentages are not a cap on your provider's total transaction fee.

A useful pricing page or written quote should let you identify:

‍

CEE gives you a useful example of how pricing models differ.

Barion publishes standard online card-acceptance packages and the conditions attached to them. Its current Hungarian terms are valid from 22 April 2026. SimplePay, by contrast, states that the specific cost of card acceptance is determined from the merchant information supplied during online registration and detailed in the resulting offer. 

Both models can be legitimate; they simply require a different comparison process.

If pricing is quoted rather than published, ask for the full offer in writing. You want enough detail to run your actual transaction mix through it rather than comparing headline percentages.

5. A clear explanation of what happens to funds before settlement

Ask one direct question:

Which licensed institution receives the funds involved in my payments, and what protection applies before settlement reaches me?

The setup can also differ depending on whether you have a dedicated merchant account or use a payment platform that handles the acquiring relationship on your behalf. Check the contractual arrangement rather than assuming every provider handles funds in the same way.

Eligible bank deposits in the EU are generally protected through national deposit guarantee schemes up to €100,000 per depositor, per bank, subject to the scheme's eligibility rules.

For funds received by a payment institution for the execution of payment transactions, Article 10 of PSD2 instead requires safeguarding. It provides two routes:

  • Segregation. Relevant funds are kept separate from the institution's own funds and protected under national law against claims from other creditors, particularly in insolvency.
  • Insurance or a comparable guarantee. Coverage is provided by an insurer or credit institution outside the payment institution's own group.

If your setup involves an electronic money institution or credit institution, ask which legal framework and protection applies to your particular flow rather than assuming the answer is identical.

For you, the practical question is not simply “are my funds safe?” It is who is legally responsible for them before settlement and where that responsibility is documented.

‍

Comparison of deposit guarantee protection for eligible bank deposits and PSD2 safeguarding for payment institution funds

6. A settlement schedule you can state in days

“Fast payouts” are difficult to compare. A settlement schedule is not.

Before signing, get these points in writing:

  1. The standard settlement or payout schedule, stated as a number of days
  2. Whether a reserve applies to your business model and under what conditions
  3. Whether payouts carry a separate fee
  4. Where the money goes, whether directly to your existing business bank account or first into a provider-held balance
  5. Which settlement currencies are available for your market

The payout model is not a minor operational detail. A provider-held balance creates an extra withdrawal and reconciliation step. Direct settlement to an existing bank account removes that step, although the settlement timetable still matters.

The payment mix also changes by market, so the currencies and settlement setup you need in Hungary may look different from the setup you need in Romania.

Bulgaria adopted the euro on 1 January 2026, becoming the twenty-first euro-area member, while Hungary, Poland, Czechia and Romania continue to use their national currencies.

If you sell across several markets, ask about collection currency, settlement currency and FX during onboarding. They are three separate questions.

7. Documentation and a sandbox you can access before going live

Good documentation should let your technical team understand the integration before production credentials arrive.

Open the docs yourself and check:

  • Which integration methods are documented, whether that is a plugin, API, checkout solution or payment link
  • Whether API references and examples are current
  • When plugins or integrations were last updated
  • Who maintains the plugins
  • Whether testing, authentication, errors and webhooks are documented
  • Whether there is a sandbox or test environment

Then ask when you can access it.

A sandbox that is available before live activation lets technical work and account verification happen in parallel. Your team can build the checkout, test authentication and failure scenarios, configure webhooks and fix integration issues while the live merchant account is still being reviewed.

A sandbox is not proof that a provider is trustworthy on its own. It is evidence you can actually test.

What tells you how the relationship will work

8. A clear distinction between what is live and what is on the roadmap

Every payment platform has features that are still being built or expanded into new markets.

The useful question is which capabilities are available to your business today.

Ask for a written, dated list of the features and payment methods currently live for merchants in your country. If something you need is not available, ask what your current alternative is.

A good answer can be as simple as:

“Not available today. It is on our roadmap, and this is the option you can use in the meantime.”

That is more useful than treating a planned feature as though it were already part of the checkout.

Keep live capabilities and roadmap items separate when you compare providers. A roadmap can matter to your longer-term choice, but your launch plan should be based on what you can actually use now.

9. A support path you understand and an exit you have read

“Great support” is not a comparison point.

A named contact during onboarding, clear support channels after launch and a documented escalation process are.

Ask:

  • Who helps you during onboarding?
  • Which channel do you use after go-live?
  • Is support available in your language or market?
  • What happens when a payment or integration issue needs escalation?
  • Are response-time commitments included anywhere in your agreement?

When checkout is unavailable, response time becomes a commercial issue rather than a customer-service extra.

Then read the exit terms before you join.

Check:

  • Minimum contract period, if any
  • Required termination notice
  • Early termination charges, if any
  • What happens to pending settlements or disputes
  • Whether you can export the transaction data you need before the account closes

You do not need to expect the relationship to fail to ask how it ends. You are simply checking the full commercial commitment before making it.

How Paypercut answers the basics

If Paypercut is on your shortlist, you can run the same checks before you commit.

Start taking payments in your market

Register in a few minutes with fully digital onboarding. The dashboard and sandbox open at signup, so you can build and test your checkout while verification runs.

FAQs

Why does published pricing matter when evaluating a payment provider?

Published pricing lets you estimate your costs before a sales call. Check the card-rate categories, chargeback fee, refund treatment, FX costs and any payout or recurring fees. If pricing is quoted instead, get the full offer in writing so you can compare providers on the same terms.

What security certifications should a legitimate payment provider have?

For card payments, PCI DSS validation is the baseline. Ask what the provider’s current validation covers, when it was last completed and whether it can provide supporting evidence such as an Attestation of Compliance. PCI DSS v4.0.1 is the current revision, with the previously future-dated requirements effective since 31 March 2025.

How can I check if a payment provider’s company information is legitimate?

Find the legal company name and registration number, then check them through the European Commission’s BRIS company search or the relevant national business register. BRIS connects company registers across the EU, Iceland, Liechtenstein and Norway and pulls company information from the participating national registers in real time.

What should I know about how a provider holds and settles my funds?

Ask which licensed institution receives the funds, what protection applies and how long settlement takes. Funds received by payment and electronic money institutions for payment transactions are subject to safeguarding rules, which can involve segregation or insurance/a comparable guarantee. That is different from the deposit-guarantee protection that applies to eligible bank deposits.

How do I verify a payment provider’s regulatory licensing?

Ask which authorised institution provides the regulated payment services, then verify it through the appropriate regulator. For payment and electronic money institutions, the EBA’s central PSD2 register shows their authorisation and cross-border activity. An institution authorised in one EEA country may serve another where its permissions cover the relevant services and market.

Свързани статии.
Изпробвайте демото за онлайн плащания на Paypercut
Предоставяме ви възможността да разгледате как вашите клиентите ще плащат с карти, дигитални портфейли, платежни линкове и QR кодове, преди да започнете регистрация