Payment Processing · Industry · Security

Three separate Visa changes are moving through the calendar this year, and the coverage has them in roughly the wrong order of importance. The one being written about is the retirement of a program most merchants have never heard of. The one with a hard deadline you can actually miss is a token service that switches itself on at the end of October unless somebody tells Visa otherwise by 30 September. And the one that decides what you pay has been live since April.
Visa is sunsetting the Digital Authentication Framework 3-D Secure program in September 2026. If you do nothing about it, the practical effect is that repeat customers who used to sail through checkout at your site may start seeing authentication challenges again.
The Visa Credential Enrichment Service is enabled for all card-on-file token requestors on 30 October 2026, and the opt-out closes on 30 September 2026. Visa says it carries no additional product fee. Most merchants will want it on; the point is that the decision expires this month.
The Digital Commerce Authentication Program launched in the United States on 18 April 2026, and it is the only one of the three with money attached. It is also the one most merchants have not finished implementing.
The Digital Authentication Framework is a program inside EMV 3DS, from version 2.1 onward, aimed at card-not-present transactions. Visa's own developer documentation describes the goal as card-not-present transactions with "higher approval rates, lower fraud, and a consistent consumer user experience with low to no friction."
The mechanism is narrower and more useful than that sounds. Once a customer has verified their identity on a first transaction with a merchant, Visa's documentation states that "issuers are not allowed to request a step-up or challenge on subsequent authentication requests from the same merchant, customer, and payment account that meet the DAF requirements." In other words, DAF is the rule that stops your returning customers being challenged over and over.
That is why the sunset is a merchant question and not purely an issuer one. Visa's merchant business news digest announced in October 2025 that it "will sunset the Digital Authentication Framework (DAF) 3 D Secure (3DS) program in September 2026 as it transitions to newer authentication methods such as Visa Payment Passkey," and that no new participants are being accepted. DAF test cases became optional for Visa Secure certification from 30 October 2025.
One thing that is not changing: the Visa Token Service DAF program is separate and stays in place. If your reading of the announcement was that tokenised transactions are affected, they are not.
Visa points to Visa Payment Passkey as the successor. Visa describes it as built to Fast Identity Online (FIDO) standards, replacing "passwords and SMS one-time codes with a secure passkey stored on a cardholder's device," authenticated with a fingerprint, face or device PIN. Visa's own figure for the improvement is a 50% reduction in fraud rates relative to SMS one-time passcodes.
The honest caveat is that this is a credential the cardholder's issuer and device have to support, not a switch on your checkout. For most merchants the migration is something your gateway or processor does on your behalf, which is why the practical version of this step is a question rather than a project. Ask whoever runs your authentication — that is your gateway if you use one, and your processor if you do not — whether you were relying on DAF suppression and what happens to your challenge rate when it goes.
Buried in a May 2026 notice rather than a headline: Visa is enabling the Visa Credential Enrichment Service for all card-on-file token requestors effective 30 October 2026. The purpose is to improve token provisioning success rates — the proportion of attempts to tokenise a stored card that succeed. Visa's notice states there will be "no extra product fees charged for token requestors as VCES is a product service covered as part of DCSF," the Digital Commerce Service Fee you are already paying.
Token requestors wanting to opt out must contact their acquirer by 30 September 2026. This is the only date in this article that removes an option once it passes.
For most merchants the sensible answer is to let it switch on. Better provisioning success means fewer stored cards silently failing to tokenise, which shows up later as declined renewals. But if you run card-on-file at any scale, this is worth a deliberate decision rather than a default, and the window to make it closes this month.
The Digital Commerce Authentication Program is Visa's framework for merchants to share richer data at authorisation. Visa describes it as providing "a clear, standardized framework for how data is collected, validated and shared across the ecosystem." Participating merchants send four enhanced data fields — device ID, IP address, email address and full billing address — through one of Visa's Intelligent Data Exchange solutions.
Visa's stated results are a 280 basis point increase in authorisation rates for enhanced-data transactions — measured against non-authenticated ecommerce, which is a generous baseline — with a further 50 basis points when DCAP standards are actually met rather than merely attempted. Visa's published case studies name two providers this site reviews. It credits Square with approval rates 200 basis points higher than its other card-not-present transactions alongside a 29% reduction in fraud, and Adyen with a 190 basis point increase in US authorisation rates — though Visa's own footnote narrows that considerably: it comes from an Adyen-run pilot for a single enterprise travel merchant, measured across a subset of optimised issuers. Read the footnotes before quoting either number in a business case. These are Visa's figures about Visa's own program, and the Adyen one in particular is not a general result.
The data quality requirement is the part that catches merchants out. Visa's March 2026 notice states that transactions which do not meet the standards "will not qualify for DCAP and may be subject to compliance enforcement." Sending the four fields is not the same as sending them correctly, and a billing address captured loosely at checkout is the usual culprit. If you tightened your checkout to meet the eligibility criteria in the current SAQ A rules, the same audit of what your payment page actually collects will answer this question too.
The incentives are not marketing numbers; they are in Visa's U.S.A. Interchange Reimbursement Fees schedule, in the edition effective 18 April 2026. The schedule sets three card-not-present incentive tiers, applied as a deduction from the interchange rate:
The schedule is explicit that these "require CPS qualification and are subject to change." So the ceiling on what better data can save you, on a Visa consumer credit card-not-present sale, is fifteen basis points — and you only reach it by doing both tokenisation and DCAP.
Put that against a real line from the same schedule. A card-not-present sale on the Services 1 program, on Visa's "All Other Products" tier, is 1.65% + $0.10. Tokenised and DCAP-qualified, it becomes 1.50% + $0.10. On $100,000 of annual card-not-present volume that is $150 a year. It is real, it is not transformative, and the authorisation-rate lift is very likely worth more to you than the interchange deduction — a declined sale costs the whole sale, not fifteen basis points of it.
The same schedule carries a separate Small Merchant Fee Program, with its own card-not-present incentive tiers at the same minus 0.05%, minus 0.10% and minus 0.15%. The qualifying ceiling is $280,000 of gross Visa consumer credit sales, measured on twelve months of Visa system activity ending 30 September 2024.
The qualification logic differs in a way worth knowing. On the small merchant sheet, DCAP transactions generally qualify for Type 1 rather than Type 2 — except on Small Merchant Product 1, where EMV Token earns Type 1, DCAP earns Type 2, and DCAP plus EMV Token earns Type 3. The schedule also warns that a small merchant transaction which disqualifies from the program "will be assessed at next applicable rate."
The practical reading: if you are under that threshold, DCAP on its own is worth half of what it is worth to a larger merchant on most programs, and the case for doing it rests on the authorisation lift rather than the interchange line.
The schedule excludes Charity 1 and CPS/Utility from the incentives. EMV Token, DCAP, and DCAP plus EMV Token all qualify for their respective tiers "except for Charity 1 and CPS/Utility." There is one narrow exception written back in: "Charity 1 DCAP transactions qualify for Card Not Present Incentive Type 1."
So a registered charity taking online donations gets minus 0.05% for doing DCAP and nothing at all for tokenisation, where an ordinary online merchant doing both gets minus 0.15%. Charities start from a much lower interchange rate, so they are still ahead — but the gap narrows, and any projection built on the standard incentive tiers will overstate what a nonprofit saves.
The answers to all of this sit with whoever owns your authentication and tokenisation, and for many merchants that is a gateway rather than the acquirer whose name appears on the statement. If you run on a dedicated gateway such as Authorize.net or NMI, the DCAP field mapping is a gateway configuration question and your acquirer may not be able to answer it. If you are on a full-stack platform such as Stripe, Braintree or Shopify Payments, most of this is handled for you and the useful question is narrower: confirm what is already enabled on your account rather than assuming either way.
One more thing worth checking while you have their attention. The incentives above all require CPS qualification, and a transaction that downgrades earns none of them. If you have never audited what proportion of your volume is downgrading, that is a larger number than fifteen basis points and it is visible on your statement — our guide to reading one covers where to look. B2B merchants should also check they are on the right side of Visa's retirement of Level 2, which moves considerably more money than DCAP does.
None of this is a reason to change processor on its own. It is a reason to find out what yours has already done on your behalf, and to notice that the only irreversible date in the set is the one nobody is writing about.