all resources
Article

The Evolving Payment Landscape: From ISO to PayFac to Embedded Infrastructure

The payments ecosystem was built on well-defined roles: ISOs referred, acquirers settled, PSPs integrated, PayFacs bundled, ISVs stayed in their software domain. Digital commerce has dissolved those boundaries. This is a look at what each role actually meant, why the lines blurred, and what replaces them.

Paypr.work × Norbr10 min readFree to read and cite

Outgrowing the traditional structure

The structure of the payments ecosystem has historically been based on well-defined roles. Independent Sales Organizations (ISOs), Payment Service Providers (PSPs), Acquirers, Payment Facilitators (PayFacs), and Independent Software Vendors (ISVs) each occupied a distinct position in the value chain.

However, as digital commerce has grown in complexity and scale, these roles are converging. Today, the industry is shifting away from rigid categorisation toward modular, composable infrastructure.

What was once a sequence of handoffs is increasingly becoming a network of interoperable functions.

The legacy roles, and where their boundaries sat

ISO (Independent Sales Organization)
A third-party agent that refers merchants to acquirers and facilitates their onboarding. ISOs historically managed sales relationships but did not own technical infrastructure or compliance. An ISO does not process or collect funds: it is a commercial channel, not a regulated one.
Acquirer (or acquiring bank)
A financial institution that processes card transactions on behalf of a merchant and settles funds into their account. Acquirers are responsible for scheme membership, underwriting, and risk. An acquirer is a settlement entity, though some modern players — Adyen, for example — hold both roles, acquirer and PayFac.
PSP (Payment Service Provider)
A technology provider that enables merchants to accept various payment methods, including cards, wallets, and bank transfers, typically through a single API integration. PSP is also a legal status, allowing an entity to collect funds for third parties under PSD2 in Europe.
PayFac (Payment Facilitator)
An entity that acts as a master merchant, onboarding sub-merchants under its own account to simplify integration and accelerate go-to-market. A PayFac is a role defined by the card schemes, often layered on top of a PSP licence.
ISV (Independent Software Vendor)
A company providing software solutions — for retail, hospitality or fitness, for instance — that embed payments as part of the workflow. ISVs are increasingly influential as distribution and control layers for payment functionality. An ISV may embed payments but doesn't necessarily touch funds.

How small and large merchants bought payments, before the lines blurred

Smaller merchantsLarger merchants
Route to marketBundled or agent-led, via ISOs, ISVs or resellersDirect engagement with providers
Relationships to manageOne, with pre-integrated services beneath itSeveral — acquirers, PSPs and fraud vendors, each negotiated
What was prioritisedSpeed and ease of setup, not controlOptionality and influence over configuration
VisibilityLittle sight of routing, fees or optimisation leversProvider selection and configuration largely their own call
How payments were treatedAs a utilityAs a negotiated commercial arrangement
Degree of customisationPre-integrated, all-in-one, limited flexibilityGreater flexibility, though rarely a fully custom-built stack

Modularity disrupts the chain

Once upon a time, the payments industry was relatively easy to map. ISOs introduced. Acquirers settled. PSPs integrated. PayFacs bundled. ISVs focused on their own software domains. Each actor had a defined title, clear boundaries, and a single function.

But the demands of digital commerce — speed, flexibility, cross-border capability, and embedded experiences — have blurred those lines. As eCommerce matured and platforms expanded across geographies and verticals, the linear logic of traditional roles began to feel out of step with the way modern merchants operate. What once functioned as a clearly segmented path now overlaps in functionality, technology, and merchant expectation. Merchants no longer think in terms of isolated providers, but in terms of end-to-end performance, flexibility, and value.

In response, roles began to overlap

  • PSPs expanded into orchestration, routing, and analytics.
  • Acquirers introduced various value-added services, including fraud modules.
  • ISOs embedded technical dashboards, support layers, and custom integrations.
  • ISVs began embedding full payment stacks into their platforms, becoming payment enablers in their own right.

As platforms and APIs matured, the old distinction between how small and large merchants bought payments began to dissolve too. Today, even small or mid-sized players can access modular tools, orchestrate across providers, and compose a stack that reflects their operational needs, without building everything from scratch.

A new class of infrastructure provider

A new wave of infrastructure providers has also entered the payments space, designed from the ground up with modularity and flexibility in mind. Unlike legacy players, these entrants are cloud-native, API-first, and built to be embedded seamlessly into modern digital ecosystems.

  • Core processing
    Some focus on core processing, offering alternatives to traditional acquirers with real-time settlement capabilities and simplified scheme connectivity.
  • Orchestration
    Others specialise in orchestration, acting as middleware that intelligently routes transactions, manages retries, and connects multiple service layers without the need for custom code.
  • Data and compliance infrastructure
    Another group is emerging around data and compliance infrastructure, offering token vaults, identity verification, and secure handling of sensitive payment credentials. Their role is to abstract risk and reduce the compliance burden for platforms.

The ISO and ISV repositioned as operators

ISOs are worth a closer look, because their evolution encapsulates the broader shift. Traditionally seen as distribution arms focused on merchant acquisition and referral, ISOs operated at the periphery of the payment stack. As technology became more accessible and infrastructure more modular, they moved closer to the centre — and their repositioning reveals how non-technical actors are now stepping into technical roles.

  • Middle-layer builders
    Developing white-label or proprietary platforms that sit between the merchant and the processor.
  • Relationship owners
    Offering onboarding support, operational insights, and escalation pathways.
  • Strategic enablers
    Providing advice on stack configuration, payment performance, and compliance requirements.

The age of the modular stack

ISVs, in particular, are shifting from pure software distribution to revenue-sharing partners and orchestration layers. Many embed PayFac capabilities or route through multiple PSPs while maintaining ownership of the merchant relationship. With deep industry knowledge and proximity to merchant pain points, both ISOs and ISVs are becoming ecosystem integrators — adding value through specialisation, service, and embedded infrastructure.

Building an end-to-end payment stack used to be a badge of honour, and a costly one. Today, platforms and merchants no longer need to choose between building everything or outsourcing it all. Instead, they compose what they need, combining ownership and partnership in ways that align with strategy, speed, and cost.

Payment infrastructure is unbundling. From tokenisation to compliance to transaction monitoring, nearly every component is now available as a service:

  • Startups can launch with a light footprint.
  • Enterprises can test and swap layers without overhauling entire architectures.
  • Mid-sized platforms can compete on experience without bearing the full cost of ownership.

Rather than buying monolithic stacks or building everything in-house, businesses now plug into onboarding engines, use third-party fraud tools, layer token vaults without managing scheme certification, and route across PSPs using orchestration engines.

This modularity marks a fundamental shift: payment providers are no longer defined by what they were traditionally licensed to do, but by the capabilities they offer.

The third wave: Infrastructure-as-a-Service

Payment is no longer just a checkout feature. It is foundational infrastructure — modular by design, and embedded across product, operations, finance, and customer experience.

As the payments landscape matures, a new category is emerging: Infrastructure-as-a-Service. Unlike PayFac-as-a-Service, which simplifies merchant onboarding and compliance under a shared master MID, IaaS unbundles deeper layers — routing, tokenisation, FX and more — into configurable components. These infrastructure providers operate largely behind the scenes, with no merchant-facing role, and without requiring ownership of licensing or scheme relationships.

This model allows platforms to plug into advanced payment capabilities without owning the full stack, enabling more flexibility, scalability, and control over the user experience:

  • Smart routing across PSPs and acquirers
  • Tokenisation vaults
  • Unified reconciliation
  • Embedded FX and payout engines

Three shifts accelerating the demand

  • Platformisation of commerce
    Marketplaces, SaaS platforms, and aggregators want to own the commercial and user experience without being constrained by legacy acquirer logic.
  • Hyper-regionalisation
    Merchants selling cross-border need local acquiring, acceptance, and compliance support. Infrastructure partners can abstract this through a single integration.
  • The need for differentiation
    Payments are no longer passive. Smart routing, real-time monitoring, and tokenisation strategies have become competitive differentiators.

Access over ownership

What began as a channel play (ISO) and transitioned into a product-led model (PayFac) is now evolving into a service-first, infrastructure-centric world. As the lines between acquirers, PSPs, ISOs, and orchestrators blur, control, modularity, and integration flexibility are becoming the guiding design principles for modern payment strategies.

Rather than asking who owns the stack, the more relevant question is who can configure it, and how fast. This shift doesn't require every player to become an infrastructure provider. On the contrary, the emergence of Infrastructure-as-a-Service and PayFac-as-a-Service models reflects a growing demand for access over ownership. Platforms and intermediaries no longer need to build or license everything themselves; they can assemble high-performing payment capabilities from interoperable services.

ISOs, for example, are repositioning themselves as value-added partners, bringing underwriting experience, vertical knowledge — healthcare, B2B, high-risk — and localised onboarding to the table. Their relevance lies in their ability to navigate complexity: not in owning the rails, but in knowing how to orchestrate them.

Those who remain static risk losing touch with market expectations. Those who evolve, whether as builders, connectors, or advisors, will shape the next generation of embedded commerce.

Frequently asked questions

What is the difference between an ISO and a PSP?
An ISO is a commercial channel; a PSP is a technical and regulated one. An Independent Sales Organization refers merchants to acquirers and handles the sales relationship, but does not own technical infrastructure or compliance and never processes or collects funds. A Payment Service Provider supplies the technology that lets a merchant accept cards, wallets and bank transfers through a single API — and PSP is also a legal status, allowing an entity to collect funds for third parties under PSD2 in Europe.
What does a PayFac actually do?
A Payment Facilitator acts as a master merchant, onboarding sub-merchants under its own account so they don't each need a direct acquiring relationship. That simplifies integration and accelerates go-to-market. PayFac is a role defined by the card schemes rather than a licence in itself, and it is often layered on top of a PSP licence.
Is an acquirer the same as a PSP?
No, though the distinction is eroding. An acquirer is a financial institution and a settlement entity: it processes card transactions, settles funds into the merchant's account, and carries scheme membership, underwriting and risk. A PSP is a technology provider enabling acceptance across payment methods. Some modern players hold both roles at once — Adyen, for example, is both acquirer and PayFac.
What is Infrastructure-as-a-Service in payments?
An emerging category in which deeper layers of the payment stack — routing, tokenisation, FX and more — are unbundled into configurable components that a platform can plug into. IaaS providers operate largely behind the scenes, with no merchant-facing role, and without requiring the platform to own licensing or scheme relationships. It lets a business access advanced payment capabilities without owning the full stack.
How is IaaS different from PayFac-as-a-Service?
PayFac-as-a-Service simplifies merchant onboarding and compliance under a shared master MID. Infrastructure-as-a-Service goes further down the stack, unbundling routing, tokenisation, FX and reconciliation into components you configure independently. Both reflect the same underlying demand — access over ownership — but PayFac-as-a-Service addresses the onboarding layer while IaaS addresses the infrastructure beneath it.
Do I still need to build my own payment stack?
Rarely, and that is the substantive change. Building end to end used to be a badge of honour and a costly one; the choice is no longer between building everything and outsourcing it all. Nearly every component — tokenisation, compliance, transaction monitoring, onboarding, fraud tooling, orchestration — is available as a service, so startups can launch with a light footprint, enterprises can swap layers without overhauling their architecture, and mid-sized platforms can compete on experience without carrying the full cost of ownership.
Are ISOs still relevant?
Yes, but in a different position. ISOs have moved from the periphery of the stack towards its centre, becoming middle-layer builders of white-label platforms, owners of the merchant relationship, and strategic advisers on stack configuration and compliance. Their relevance now comes from underwriting experience, vertical knowledge in areas like healthcare, B2B and high-risk, and localised onboarding — not from owning the rails, but from knowing how to orchestrate them.