PayFac Registration Requirements With Visa and Mastercard
PayFacs must navigate separate Visa and Mastercard registrations with distinct compliance demands.

A payment facilitator is a master merchant that holds its own acquiring agreement and onboards other businesses underneath it as sub-merchants. Square, Toast, and Mindbody all run this model: sub-merchants sign contracts with the PayFac, not with Visa or Mastercard directly, and the PayFac carries the liability for what happens on its portfolio. In exchange, it earns the spread between the wholesale interchange rate its acquirer gives it and whatever it charges the businesses underneath it. Getting to that spread, though, means clearing two separate registration processes, one with Visa and one with Mastercard, and neither one is a formality.
The dual-registration reality: Visa and Mastercard are separate programs
Registering with Visa gets a platform nothing at Mastercard, and vice versa. Each network runs its own documentation requirements, its own compliance programs, and its own set of ongoing obligations once approval comes through, so a platform planning to accept both networks' cards is really running two applications in parallel, not one application with two logos on it.
Both networks also share a non-negotiable prerequisite: a sponsoring acquirer. Neither Visa nor Mastercard will accept a direct application from a software platform with no bank behind it. No acquirer means no application, full stop. Registration fees include about $5,000 to Visa, with Mastercard carrying its own registration costs on top of that, and while these fees sound modest next to everything that follows, they're among the cheaper line items in the entire process.
The shared foundation both registrations require before any application
Before either network looks at an application, a platform needs a few things already built and documented, not promised.
The sponsoring acquirer relationship comes first: a licensed acquiring bank has to agree to sponsor the platform, hold liability alongside it, and submit paperwork to the network on its behalf. Capital reserves come next, typically starting at a substantial sum and moving up or down depending on projected volume and the risk profile of the merchants being boarded. A documented KYC/KYB program for verifying sub-merchant identity and business legitimacy is also required, and it has to meet the card networks' own standards, not whatever internal bar a platform has been using to satisfy its own risk team.
Then there's PCI DSS Level 1 compliance. Card networks treat PayFacs as service providers. A self-assessment questionnaire doesn't cut it. A Qualified Security Assessor has to run the full Level 1 assessment and sign off on it. That's a materially heavier lift than the checkbox compliance most software companies are used to, and it's one of the first places platforms underestimate the timeline.
Visa-specific registration: GARS, VAMP, and the 2026 program changes
Visa's registration path runs through its Global Acquirer Risk Standards (GARS) framework. Once the technology and compliance work is built out, the network review period itself takes roughly 2 to 3 months, and that's before a platform ever processes a live transaction. After Visa signs off, there's another 1 to 3 months of testing with the sponsoring acquirer before go-live.
Visa also consolidated its fraud and dispute monitoring into a single framework: the Visa Acquirer Monitoring Program, or VAMP. VAMP folded five previous programs, including the Visa Fraud Monitoring Program and the Visa Dispute Monitoring Program, into one system. It went into effect June 1, 2025, and enforcement itself has been live since October 1, 2025. Any platform registering as a PayFac today is registering into VAMP from day one, not into the older, more fragmented system some legacy playbooks still describe.
Mastercard-specific registration: the Principal Member path, MATCH, and BRAM
Mastercard doesn't let a platform apply on its own either. Registration has to run through a Principal Member, a Mastercard-licensed acquirer that sponsors the application and submits the required documentation directly to Mastercard.
That documentation package includes legal entity registration, background checks on ownership and principals, financial statements, a KYC/KYB verification program that meets Mastercard's specific standards, a BRAM compliance plan, and proof the platform can manage chargebacks at scale in practice, not just in theory.
MATCH list screening sits inside that package as a hard requirement. MATCH, the industry-wide high-risk merchant list maintained under the card network's merchant monitoring program, holds merchants that other processors have already terminated for fraud, excessive chargebacks, or other program violations. Every PayFac has to screen every sub-merchant applicant against that list before onboarding. Board a MATCH-listed merchant without documented due diligence and sign-off from the sponsoring acquirer, and the platform is looking at fines and a registration status suddenly in question.
BRAM, the Brand Risk and Acquirer Monitoring program, catches platforms off guard because it doesn't end at onboarding. Registered PayFacs have to actively monitor sub-merchant websites, social media, and ad content on an ongoing basis for anything that violates Mastercard's standards, things like misleading health claims, unlicensed pharmacy language, or deceptive marketing copy. BRAM fines can reach $200,000, which turns brand monitoring from a nice-to-have into a budgeted, staffed function.
The 2026 Mastercard Specialty Merchant Registration overhaul's impact on PayFac portfolios
On October 28, 2025, Mastercard published Bulletin AP/LAC/MEA/US 12568.1, which rewrites the Specialty Merchant Registration Program from the ground up. New fees, higher existing fees, and for the first time, charges tied to transaction-level codes that flag high-risk merchants directly at the network layer.
The fee schedule rolls out in stages. On May 1, 2026, the updated Specialty Merchant Registration Fee takes effect alongside a brand-new High-Risk Acquirer License Fee, and the annual specialty merchant registration fee itself doubles, from $500 to $1,000. Then on June 3, 2026, two new per-transaction charges arrive: a flat Specialty Merchant Transaction Fee and a basis-point Specialty Merchant Volume Fee, both applied to every transaction a specialty merchant runs.
The merchant category codes that trigger specialty registration cover a specific list: adult content and services (MCC 5967, 7841), online gambling and betting (MCC 7995, 7801, 7802), online pharmacies primarily selling prescriptions remotely (MCC 5122, 5912), tobacco and vape products sold online (MCC 5993), and government-owned lotteries (MCC 7800 in one major market, MCC 9406 elsewhere). Any PayFac with sub-merchants in these categories needs to know now whether its registration and pricing model account for the new fee stack. Board one of these merchants without proper specialty registration, and the penalty starts at $10,000 and climbs to $25,000.
Ongoing obligations after both registrations are approved
Approval isn't the finish line. Every obligation attached to registration is a condition of keeping it, and both networks treat lapses accordingly.
On the Visa side, that means active VAMP compliance across the whole portfolio, not just at the individual merchant level, so fraud and dispute ratios have to stay managed on an ongoing basis. PCI DSS Level 1 certification has to be renewed on schedule, and the newer v4.x requirements are now mandatory, not optional upgrades. Material business changes need to get reported to the sponsoring acquirer as they happen.
Mastercard's list runs longer. Periodic reporting on processing volume and sub-merchant activity, continuous BRAM monitoring with prompt responses to violation notices, current PCI DSS certification, timely reporting of material business changes, and MATCH screening that never stops, because every new sub-merchant added to the portfolio has to clear that check regardless of how long the PayFac has been registered.
None of this scales down as a portfolio grows. It scales up. More sub-merchants means more surface area for BRAM to monitor, more volume running through MATCH screening, and a wider set of accounts whose fraud and dispute ratios feed into VAMP. A platform that registers a modest number of sub-merchants and grows to a much larger base is running the same compliance obligations against orders of magnitude more risk exposure.
What the full cost and timeline picture looks like
Full registration with both networks runs somewhere between $600,000 and $2,000,000 or more, spread across 12 to 24 months. That range isn't padding: it reflects real, sequential work.
The technology build takes 3 to 6 months. Compliance and legal preparation, running in parallel or close to it, takes another 3 to 6 months. Card network review adds 3 to 6 months on top of that, and testing with the sponsoring acquirer before go-live adds another 1 to 3 months. Registration fees themselves are around $10,000 total, split evenly between Visa and Mastercard, which is almost a rounding error against the technology and compliance spend surrounding it. Platforms operating nationally also need state money transmission licenses in most cases, which run roughly $150,000 on their own.
None of this counts the ongoing headcount for BRAM monitoring, MATCH screening, and VAMP ratio management once the doors open. The number on the door is the entry fee. The obligations described above are the rent.
How PayFac-as-a-Service lets platforms capture most of the economics without carrying the registration burden
Given that cost and timeline, most software platforms never touch direct registration. PayFac-as-a-Service (PFaaS) lets a platform keep control of merchant pricing, the onboarding experience, and the merchant relationship, while a licensed provider handles the sponsor bank relationship, the regulatory compliance work, the card network registration itself, and the underwriting infrastructure that supports it.
The distinction that matters is between PFaaS and a plain referral arrangement. In a referral model, the platform sends merchants to a processor and collects a share of whatever that processor charges. True PFaaS is different: the platform negotiates its own buy rate from the underlying provider and sets its own sell rate to sub-merchants, keeping the spread between the two as actual payment revenue rather than a percentage cut of someone else's pricing.
That difference is the entire economic argument for the model. A platform that never builds VAMP monitoring, never runs its own MATCH screening, and never manages its own card network compliance obligations can still capture most of the revenue a fully registered PayFac earns, because the revenue was never really about holding the registration. It was about owning the merchant relationship and the pricing on top of it. Given that a large share of businesses (82%, per available survey data) say they'd consider switching software platforms for better payment features, the pressure to embed payments somehow isn't going away. What's changed is that a platform no longer has to choose between building a $2 million compliance operation and sitting out the payments revenue.


