---
title: What Is an Acquirer in PCI DSS?
description: PCI-DSS acquirer definition
---

[Skip to content](https://knowledge.adoptech.co.uk/what-is-an-acquirer-in-pci-dss#main-content)

[![Adoptech-logo-GreyWithoutStrapline-1.png\]](https://knowledge.adoptech.co.uk/hs-fs/hubfs/Adoptech-logo-GreyWithoutStrapline-1.png?height=39&name=Adoptech-logo-GreyWithoutStrapline-1.png)](https://knowledge.adoptech.co.uk/?hsLang=en)

Open main navigation

Close main navigation

 Adoptech Help Centre

- There are no suggestions because the search field is empty.

1. [Knowledge base](https://knowledge.adoptech.co.uk/?hsLang=en)
2. [Frameworks & Certifications](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en)
3. [PCI-DSS](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#pci-dss)

# What Is an Acquirer in PCI DSS?

## “acquirer” is one of the most common PCI DSS terms that causes confusion - we explain what it means

#### In PCI DSS, an **acquirer** (also called an **acquiring bank**) is the organisation that enables your business to accept card payments and connects you to the card payment networks such as Visa and Mastercard.

If you accept card payments, you have an acquirer — even if you never interact with them directly.

---

#### What does an acquirer do?

An acquirer is responsible for supporting merchants in the card payment ecosystem. This typically includes:

- Sponsoring your organisation to accept card payments
- Processing transactions through the card networks
- Settling funds into your business bank account
- Enforcing PCI DSS compliance requirements
- Requesting validation documents such as SAQs or Attestations of Compliance (AoCs)

In simple terms:

- **You** accept card payments
- **The acquirer** makes that possible
- **PCI DSS compliance** is part of the agreement

---

#### Why acquirers matter for PCI DSS compliance

Your acquirer is usually the organisation that determines:

- Your PCI DSS merchant level
- Which Self-Assessment Questionnaire (SAQ) applies
- Whether an external audit (Report on Compliance) is required
- How often compliance must be validated
- What documentation must be submitted

This is why PCI guidance often states:

> Your acquirer is the final authority on PCI DSS validation requirements.

---

#### Do you still have an acquirer if you use Stripe or PayPal?

Yes.

Even if you use a payment provider like Stripe or PayPal, there is still an acquiring bank involved behind the scenes.

For example:

- Stripe provides the payment platform
- Stripe partners with acquiring banks
- Those banks act as the acquirer supporting card transactions

So while you may not have a direct relationship with the acquirer, PCI DSS obligations still apply.

---

#### Acquirer vs payment processor (common confusion)

These terms are often used together but refer to different roles:

| Term | Meaning |
| --- | --- |
| **Acquirer** | The bank that enables card acceptance and settles funds |
| **Processor** | The service that handles transaction processing technology |
| **Payment Service Provider (PSP)** | A provider (e.g. Stripe) that bundles payment services together |

In many modern setups, PSPs combine multiple roles, which is why the distinction can be unclear.

---

#### Example (UK business)

A UK SaaS company accepts card payments using Stripe:

- Merchant: The SaaS company
- Payment Service Provider: Stripe
- Acquirer: Stripe’s partner acquiring bank
- Card schemes: Visa / Mastercard

PCI DSS validation still applies, typically through an SAQ.

---

#### Key takeaway

An **acquirer** is the organisation that ultimately ensures merchants validate PCI DSS compliance.

Even if you don’t communicate with them directly, they are a core reason PCI DSS requirements exist.

- [Getting Started](https://knowledge.adoptech.co.uk/getting-started?hsLang=en#main-content)

    - [Getting Started](https://knowledge.adoptech.co.uk/getting-started?hsLang=en#getting-started)
    - [Accounts & Billing](https://knowledge.adoptech.co.uk/getting-started?hsLang=en#accounts-billing)
- [FAQ's on Adoptech](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#main-content)

    - [Frameworks](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#frameworks)
    - [Policies & Documents](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#policies-documents)
    - [Risk Management](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#risk-management)
    - [Supplier Management](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#supplier-management)
    - [Audit Preparation](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#audit-preparation)
    - [Trust Centre](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#trust-centre)
    - [User Management](https://knowledge.adoptech.co.uk/faqs-on-adoptech?hsLang=en#user-management)
- [Frameworks & Certifications](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#main-content)

    - [ISO 27001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-27001)
    - [ISO 42001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-42001)
    - [Cyber Essentials](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#cyber-essentials)
    - [CAF](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#caf)
    - [PCI-DSS](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#pci-dss)
    - [SOC2](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#soc2)
    - [Data Privacy (GDPR)](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#data-privacy-gdpr)
    - [DORA](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#dora)
    - [ISO 9001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-9001)
    - [ISO 22301](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-22301)
    - [ISO 14001](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-14001)
    - [NIST 800-53](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#nist-800-53)
    - [NIST-CSF](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#nist-csf)
    - [NIS2](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#nis2)
    - [ISO 20000-1](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#iso-20000-1)
    - [HIPAA](https://knowledge.adoptech.co.uk/frameworks-certifications?hsLang=en#hipaa)
- [Integrations](https://knowledge.adoptech.co.uk/integrations?hsLang=en#main-content)

    - [Cloud Infrastructure](https://knowledge.adoptech.co.uk/integrations?hsLang=en#cloud-infrastructure)
    - [Identity & Access](https://knowledge.adoptech.co.uk/integrations?hsLang=en#identity-access)
    - [DevOps & Code](https://knowledge.adoptech.co.uk/integrations?hsLang=en#devops-code)
    - [Project Management](https://knowledge.adoptech.co.uk/integrations?hsLang=en#project-management)
    - [HR & People Systems](https://knowledge.adoptech.co.uk/integrations?hsLang=en#hr-people-systems)
    - [Security & Devices](https://knowledge.adoptech.co.uk/integrations?hsLang=en#security-devices)
    - [Communication & Collaboration](https://knowledge.adoptech.co.uk/integrations?hsLang=en#communication-collaboration)
- [Legal & Regulations](https://knowledge.adoptech.co.uk/legal-regulations?hsLang=en)
- [Security Guidance](https://knowledge.adoptech.co.uk/security-guidance?hsLang=en)
- [Troubleshooting](https://knowledge.adoptech.co.uk/troubleshooting?hsLang=en)

[![Chill listening crop-3](https://knowledge.adoptech.co.uk/hs-fs/hubfs/adoptech-logo-1.png?width=209&height=54&name=adoptech-logo-1.png "Chill listening crop-3")](https://adoptech.co.uk/)

<https://uk.linkedin.com/company/adoptech>

Copyright © 2026, Adoptech Ltd.