Processor compatibility comes first
- Confirm the gateway supports the intended processor and acquiring route.
- Features can vary by processor connection even when the gateway name is the same.
- Do not assume an existing token vault can be moved automatically.
- Review settlement and reporting before migration.
Security should reduce unnecessary exposure
- Use tokenization and hosted payment components where appropriate.
- Avoid storing raw card data when secure alternatives are available.
- Use role-based access for administrative users.
- Review PCI scope based on the actual checkout architecture.
Fraud tools should match the business
- Address verification and velocity controls can help reduce certain fraud patterns.
- Higher-risk products may require additional screening.
- Fraud rules should not unnecessarily block legitimate customers.
- Review chargeback data to improve controls over time.
Recurring and stored credentials need planning
- Confirm recurring billing support.
- Account updater services can help reduce avoidable declines where available.
- Document stored-credential rules and customer authorization.
- Make cancellation and refund workflows easy for staff.
Support matters when checkout is revenue-critical
- Know who supports the gateway, processor and ecommerce integration.
- Test API or plugin updates before deployment.
- Use transaction logs for troubleshooting.
- Review the complete payment path, not only the gateway account.