Redsys Servicios de Procesamiento, S.L.
Spain · owned by Independent (Spain) · www.redsys.es · 10 vendors
Redsys is Spain's leading payment processing infrastructure, providing advanced payment services to financial institutions, merchants, and payment service providers. The company operates as a central hub connecting banks, cardholders, merchants, and international card schemes (Visa, Mastercard, UPI, etc.), processing over 21,500 million transactions annually. Its services span acquiring, interbank, and issuing solutions, including POS terminals, e-commerce payments, mobile wallets, and open finance (PSD2) connectivity.
Resilience scores
- Digital Sovereignty: 0
- Digital Resilience: 9
- Financial Resilience: 7
Disruption prediction
Redsys Servicios de Procesamiento, S.L. has an estimated 40% probability of disruption in the next 6 months.
5 of Redsys Servicios de Procesamiento, S.L.'s 10 vendors monitored for disruptions.
Technology vendors
- Google LLC — Technology — United States
- Open Text Corporation — Technology — Canada
- Samsung Electronics Co., Ltd. — Technology — South Korea
- and 8 more
Services catalogue
2 services in catalogue across 2 categories; runs on 10 sub-vendors.
- Payment Gateway
- Single Sign On
Insights
Last updated 2026-07-30 · revision 3
10 direct vendors, 140 subvendors
Direct vendors by controlling owner country (sample)
- Norway: 1
- United States: 7
- South Korea: 1
Subvendors by controlling owner country (sample)
- Germany: 3
- China: 1
- Canada: 7
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Redsys exhibits medium migration readiness. On one hand, the presence of modern technologies like Docker, Kubernetes, Apache Kafka, Spring Framework, Ansible, Terraform, and a Microservices Architecture, along with strong financial health, provides a solid foundation and capacity for migration. The adoption of API Gateway and PSD2-compliant APIs also indicates a modular approach. However, significant challenges arise from the core legacy infrastructure, including IBM z/OS mainframes, IBM WebSphere, and Oracle Database. Migrating these deeply embedded, mission-critical systems in a financial services context is inherently complex, costly, and time-consuming, often requiring extensive re-platforming or re-architecting. The stringent regulatory environment (PCI DSS, GDPR, PSD2, NIS2) imposes strict requirements for data security, integrity, and operational continuity, which can complicate cloud adoption and data migration strategies. The lack of specified data residency requirements is a critical gap, as these would heavily influence cloud provider selection and architectural design. While vendor geographic diversity is noted, the "Vendor Lock-in Risk: Unknown" combined with the reliance on proprietary legacy systems (IBM, Oracle) suggests a potentially high degree of vendor lock-in, which could significantly impede a flexible migration strategy. The "Total Vendors: 0" data point is confusing, but the implied vendor relationships through the tech stack indicate potential lock-in. A full-scale, rapid migration would be challenging; a phased, hybrid approach is more probable.
Compliance
12 in-scope frameworks identified; showing 3.
DORA (source) — Assessment Required
DORA entered into application on January 17, 2025, and directly targets financial entities and their ICT third-party service providers. Redsys, as a payment processing infrastructure provider serving regulated financial institutions (banks, payment service providers), is highly likely to be classified as a 'critical ICT third-party service provider' under DORA. Risk is High because: (1) DORA imposes direct obligations on ICT providers to financial entities, not just the financial entities themselves; (2) the European Supervisory Authorities (EBA, ESMA, EIOPA) have direct oversight powers over critical ICT third-party providers; (3) non-compliance can result in fines up to 1% of average daily worldwide turnover for up to 6 months; (4) Redsys's clients (banks, payment institutions) are themselves required to ensure their ICT providers comply with DORA, creating contractual pressure; (5) DORA requires ICT risk management frameworks, incident reporting, digital operational resilience testing (including TLPT - Threat-Led Penetration Testing), and information sharing.
Evidence: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554, https://www.eba.europa.eu/regulation-and-policy/digital-operational-resilience-act-dora, https://www.bde.es/wbe/es/, https://www.esma.europa.eu/convergence/digital-operational-resilience-act
ENS — Assessment Required
The Esquema Nacional de Seguridad (ENS) is Spain's national security framework mandatory for public administrations and their technology providers. Redsys provides payment processing services to Spanish public sector entities (including government payment systems, tax payments, and public administration card acceptance). Risk is High because: (1) any entity providing ICT services to Spanish public administrations must comply with ENS at the appropriate level (Basic, Medium, or High); (2) Royal Decree 311/2022 updated ENS requirements and aligned them with NIS2; (3) non-compliance with ENS can result in loss of public sector contracts; (4) CCN-CERT (Centro Criptológico Nacional) enforces ENS compliance; (5) given Redsys's role in processing payments for public entities, ENS High or Medium level certification is likely required.
Evidence: https://ens.ccn.cni.es/, https://www.boe.es/buscar/act.php?id=BOE-A-2022-7191, https://www.ccn-cert.cni.es/en/, https://www.redsys.es
LOPDGDD — Assessment Required
LOPDGDD is Spain's national implementation of GDPR, adding specific national requirements beyond the GDPR baseline. Risk is High for the same reasons as GDPR, with additional Spanish-specific obligations including: (1) specific provisions on employee data processing; (2) digital rights provisions (right to digital disconnection, digital privacy in the workplace); (3) specific requirements for data processing in the financial sector; (4) AEPD enforcement powers under both GDPR and LOPDGDD; (5) Spain has one of the highest rates of GDPR/LOPDGDD enforcement actions in the EU.
Evidence: https://www.boe.es/buscar/act.php?id=BOE-A-2018-16673, https://www.aepd.es/es, https://sedeagpd.gob.es/sede-electronica-web/vistas/infoSede/registroDPD.jsf, https://www.aepd.es/es/resoluciones
Financials
Three-year financials
- 2023:
- 2022:
- 2021:
Financial Resilience Score: 7/10
Redsys operates as a critical payments infrastructure utility in Spain, jointly owned by the country's largest banks (CaixaBank, Santander, BBVA, Sabadell and others). This ownership structure provides captive demand, implicit financial backing from systemically important shareholders, and extremely high switching costs. Its role in card authorization, POS processing, e-commerce gateways, ATM services, and Bizum infrastructure makes it embedded in Spanish financial plumbing, supporting stable, recurring, transaction-based revenue with tailwinds from cashless payment adoption and e-commerce growth. However, resilience is tempered by structural constraints. The utility/cost-recovery model limits pricing power and margins are structurally thin. Revenue is heavily concentrated among a small number of Spanish bank shareholders, and regulatory pressure on interchange and payment fees (PSD2, upcoming PSD3, EU interchange caps) continues to compress economics. Competitive threats from international schemes (Visa, Mastercard), fintech PSPs (Adyen, Stripe), bank in-house platforms, and the prospective ECB digital euro create long-term disintermediation risk. Operational and cybersecurity risk is elevated given its systemic role, and multi-bank governance can slow strategic decision-making.
Key strengths: Owned by Spain's largest banks providing captive demand and implicit backing, Systemic role in Spanish payments infrastructure with very high switching costs, Recurring transaction-based revenue with cashless/e-commerce tailwinds, Operates Bizum infrastructure - Spain's dominant mobile P2P scheme, Regulated stable market with PSD2-driven demand for compliant processing
Risk factors: Customer concentration among a small number of Spanish bank shareholders, Utility/cost-recovery model limits pricing power and margins, Regulatory pressure on interchange and payment fees (PSD2/PSD3, EU caps), Competition from Visa/Mastercard, fintech PSPs (Adyen, Stripe), and ECB digital euro, Cybersecurity and operational risk given critical infrastructure role, Governance complexity from multi-bank ownership slowing strategic decisions
Revenue by geography
- Spain: 90%
- International: 10%
Workforce by country
- Spain: 1250
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.