Stored Card on File: Tips for Manufacturers and Distributors

Your customer places a $75,000 order today. Three months later, a different authorized buyer places a $120,000 order using the same card on file. The products, amounts, and people placing the orders are different. It’s not a subscription and it’s not recurring billing, but it’s still a stored card on file transaction. Compliance with card brand rules is different than PCI compliance, which is about accepting and processing a credit card transaction vs security.

That distinction matters. Visa and other card brands have detailed technical requirements for how stored credit cards are saved and used. When merchants don’t send the right transaction information, they risk higher interchange rates, non-compliance assessments, and non-customer initiated chargebacks.

It’s impossible for manufacturers and distributors to manage payment requirements internally. The best payment gateway, whether standalone solution or integrated with ERP or ecommerce, automates compliance. The inability of payment gateways to keep up with changing rules was exploited when merchants were mandated to accept EMV chip cards in October 2015. Virtually none were able to comply day one, some took years, and some went out of business. Merchants using our recommended solution went live the same day acquirers were ready to accept them. This historical perspective is important as the same issues are reoccurring today in the card not present world.

STORED CARD ON FILE: CUSTOMER VS MERCHANT INITIATED PAYMENT

In B2B sales an authorized buyer may log in to a portal, call a sales representative, or approve an invoice payment using the saved card.

Card brands distinguish between customer-initiated transactions and merchant-initiated transactions. A customer-initiated transaction occurs when the customer participates in the purchase. A merchant-initiated transaction is a later charge made without the customer present under a prior agreement. The acquirer needs to receive the correct data. In either case, the initial process for storing the card is critical to compliance for processing all future transactions.

Businesses cannot rely on people to tell the gateway how to code payments. The best B2B payment gateway solution applies the right process automatically based on many factors.

WHY YOUR PAYMENT GATEWAY MAY NO LONGER BE COMPLIANT

Stored-credential rules have changed over time, and card brands continually update their technical requirements. A payment gateway that successfully ran card payments years ago may not send the data now expected for stored-card transactions.

“It’s always worked” or “It’s a public company” is not a compliance test. An approval response only tells you that the transaction was approved at that moment. It does not confirm that the payment was submitted with all of the information required for the particular stored-card use case.

The most common issue is not that a manufacturer or distributor intentionally ignores the rules. It’s that its gateway, ERP connector, or custom integration was designed around an older process and does not automatically manage current requirements across all payment flows.

QUESTIONS TO ASK ABOUT ANY PAYMENT GATEWAY

  • Is the solution compliant with current rules for storing a card, Merchant initiated transactions and customer initiated transactions using a stored card on file?
  • Can it support cards stored on file compliance across order entry, ecommerce, invoice payment, and customer-service workflows?
  • Will compliance handling remain with the gateway if we update our ERP, replace a connector, or change other software?
  • Does the payment gateway system retain the customer stored card authorization records?
  • Can the customer manage their stored cards via a portal?
  • What is the payment gateway past history regarding compliance at the time of new rules going into effect? Merchants are unlikely to get direct answers on this; developer forums are a great place to learn more. For example, the authorize.net developers forum is very active with people asking …”when will it support…”

A SIGN OF NON-COMPLIANCE- $1 AUTHORIZATION

When a card is stored for future payments, the stored card framework requires a merchant send a zero dollar authorization. At that point the card is verified along with whatever the current rules are. Outdated payment gateways use a one dollar authorization, a sure sign either the gateway (or the developer) is not keeping up with continuously changing rules. Shopper alert- if you see a one dollar authorization pending on your credit card, we’d love your referral.

TIP: Is your payment gateway compliance with Zero Dollar Authorization? Search your merchant statements for “Zero Dollar Verification” Fees. Your merchant account portal may let you search for this also. Due to potential abbreviation, try “zero” if you get no results.

WHAT AN AUTOMATED B2B PAYMENT GATEWAY SOLUTION SHOULD DO

The ideal payment gateway makes it easy to store and use cards while managing the complexity in the background. It should tokenize the card, connect the payment to the appropriate order or invoice workflow, and automatically handle transaction classification and the related card-brand data.

That approach matters even more when payments touch multiple systems. ERP software, ecommerce tools, customer portals, and order-entry applications change. The payment gateway should remain the compliance layer—not leave the merchant dependent on every connector or custom software update to keep up with card-brand rules.

WORK WITH A B2B PAYMENT GATEWAY EXPERT

Stored cards on file reduces DSO. The goal is not to turn the credit department into payment-compliance specialists. The goal is to choose a solution that makes payments easy for the customer and automatically manages the technical requirements.

3D Merchant Services specializes in B2B payment gateway solutions for manufacturers, distributors, and dealers, including standalone and ERP-integrated payment technology. We help businesses implement solutions that automate payment processes and reduce the complexity of staying current with stored-card requirements.

For additional background:
https://3dmerchant.com/blog/merchant-processing-services/visa-stored-credential-mandate-overview
https://3dmerchant.com/blog/cenpos/what-is-mastercard-data-integrity-reporting

SOURCES

Visa Acceptance Solutions — Supporting Merchant-Initiated Transactions and Credential-on-File for Visa, Mastercard, and Discover
https://support.visaacceptance.com/knowledgebase/knowledgearticle/?code=000003041

Visa Developer — Getting Started with Card on File Data Inquiry
https://developer.visa.com/capabilities/card-on-file-data-inquiry/docs-getting-started

Bookmark our Card Brand Rules https://3dmerchant.com/blog/merchant-bulletins-downloads

Visa Core Rules and Visa Product and Service Rules, April 2026 edition
https://usa.visa.com/dam/VCOM/download/about-visa/visa-rules-public.pdf

Sign up for our monthly newsletter for news you can use.https://eepurl.com/dIwboT

CISA Vulnerability Review

Fiscal Years 2024 and 2025 Vulnerabilities Report, Publish Date August 26, 2026

Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the risk they pose.

The CISA Vulnerability Reviewprovides organizations with critical insights into the root causes of insecure software and practical steps they can take to address these flaws to prevent exploitation. Analyzing CISA and open source data from fiscal years 2024 and 2025, the review establishes a baseline of today’s vulnerability landscape before AI-enabled vulnerability discovery becomes more widespread. The review demonstrates the importance of Secure by Design principles in shifting cybersecurity efforts from reacting to threat actors to proactively fixing preventable software flaws.

The review also identifies common software weaknesses that contribute to exploitable vulnerabilities and details practices software producers can use to prevent these weaknesses from recurring. By examining the patterns across vulnerability data, the review helps organizations focus on systemic improvements that can reduce entire classes of vulnerabilities rather than addressing individual vulnerabilities only after they are discovered.

Additionally, the review shows organizations how to prioritize vulnerabilities for action using the framework outlined in Binding Operational Directive 26-04: Prioritizing Security Based on Risk. This framework evaluates vulnerabilities using four key criteria: exposure status, Known Exploited Vulnerability (KEV) Catalog status, potential for automated exploitation, and technical impact.

PDF CISA Vulnerability Review Fiscal Years 2024 and 2025

Source: https://www.cisa.gov/resources-tools/resources/cisa-vulnerability-reviewhttps://www.cisa.gov/resources-tools/resources/cisa-vulnerability-review

2026 Credit Card Surcharge Laws Update

What are 2026 surcharge regulations?

Business to business (B2B) credit card surcharge article includes specifics for companies, not government or education, and in particular for B2B and automotive, truck, and related dealers. Merchants must consider Federal and state laws as well as merchant account, Visa, MasterCard and other card networks compliance rules.

Since our Feburary 2025 credit card surcharge update there have been no changes to surcharge, but plenty of other changes that will affect merchants, including Visa VAMP. Most notably, on July 1, 2024, when a new California law called Senate Bill 478 went into effect.

Which states prohibit merchants surcharging?

States with other surcharge regulations

  • Colorado allows credit card surcharging up to 2%. 
  • New York, New Jersey, Nevada, and South Dakota prohibit surcharges from exceeding the cost that the merchant pays to accept the card. (See also Visa merchant surcharge rules.)
  • The legislative intent in many states was to protect consumers, and not to restrict B2B surcharging, therefore, B2B companies may have exceptions. 

Can a B2B company use surcharge to offset fees?

The rules vary across multiple card brands and terms of acceptance. Here’s a 2025 updated review of who can surcharge, what card types, and checklist of how to roll out credit card surcharge at your company. The answers are targeted for business to business merchants, our area of expertise. Historically if a merchant complies with Visa surcharge rules, they’d be compliant with other brands, so we often cite that as the standard. A B2B company that wishes to surcharge in every state should contact an attorney.

What is a credit card surcharge?

Surcharge is any fee charged by a merchant for the use of a card.These disclosure requirements include advance notice to both Mastercard and the merchant’s acquirer of the merchant’s intention to impose a surcharge no less than thirty days before the merchant implements a surcharge.

These disclosure requirements include advance notice to both Mastercard and the merchant’s acquirer of the merchant’s intention to impose a surcharge no less than thirty days before the merchant implements a surcharge.

What’s the difference between a surcharge and convenience fee? Convenience fees can only be charged for a bona fide convenience in the form of an alternative payment channel outside the Merchant’s customary payment channels and not charged solely for the acceptance of a Card. If a merchant only accepts credit cards, it’s prohibited. If a merchant is 100% card absent, merchant cannot charge a convenience fee.

Card brands agree on this for surcharging:

  1. Merchant Discount Rate is the fee, expressed as a percentage of the total transaction amount that a Merchant pays to its Acquirer or Service Provider for transacting on a Credit Card brand. In short, it’s typically all the fees on your merchant statement EXCEPT PCI compliance, terminal rental fees or any other special fee that is not paid via the mechanism of the per-transaction merchant discount fee. Per Visa, merchants must “Limit the amount to your merchant discount rate (MDR) for the applicable credit card or 3% whichever is lowest.” This is the reason merchants can get in trouble if their surcharge solution provider charges a flat amount for every card type.
  2. The Surcharge amount must be submitted separately (in the defined surcharge field) from the Transaction amount in the authorization and clearing message.
  3. The receipt must list the surcharge amount separately.
  4. If the original transaction has a partial or full refund, the surcharge amount must all be refunded proportionally.
  5. Surcharge on debit or prepaid cards is prohibited for all merchants.To ensure compliance use a payment gateway that can identify the card brand and type of card to allow surcharges only on eligible cards.
  6. The fee must be relative to their average cost of card acceptance.
  7. Any surcharge amount, if allowed, must be included in the Transaction amount and not collected separately.

How much can a merchant surcharge?

In short, surcharging is allowed to cover costs, not to make a profit. Let’s face it, based on the rules above, to simplify implementation, merchants will surcharge at the brand level because they lack the technology to discern between product types on a per transaction basis. Taking all that into account what can you surcharge?

  • Cannot exceed Maximum Surcharge Cap, which for Visa is currently 3%, effective April 15, 2023, and MasterCard remains at 4% in 2025.

Just because somebody offers it doesn’t make it right. Some companies are offering “free merchant accounts” by offsetting fees with surcharge of 3.5% or even 4%, both exceeding current rules. The average B2B company has much lower than 3.5% effective rate so that was always a violation of card acceptance rules, subject to penalty. The companies offering these services are making big money on the spread of actual fees vs what customers are paying. Again, these are card brand rules violations.

Non-compliant merchants could face fines ranging from $50,000 to $1 million according to a memo from a. credit card processor to merchants, 12/2023 ahead of expected increase in Visa enforcement in 2024 and beyond.

Surcharge checklist:

  1. Merchants must notify their acquirer 30 days before they begin surcharging; must state whether will surcharge at the brand level or product level.
    1. https://www.visa.com/merchantsurcharging
    https://www.mastercard.us/en-us/business/overview/support/merchant-surcharge-rules.html
    1. Amex- none required
  2. For card not present orders, disclose verbally if telephone; for online orders minimum 10-point Arial font, but in any case no smaller or less prominent than surrounding text.
  3. Receipt must be delivered with the surcharge as a separate line item.
  4. The surcharge amount must be sent with the transaction for authorization.
  5. Retail Point-of-Entry Disclosure example: “We impose a surcharge on credit cards that is not greater than our cost of acceptance. We do not surcharge debit cards. ” Main entrance(s) of the Merchant Outlet, in a minimum 32-point Arial font, but in any case no smaller or less prominent than surrounding text.
  6. Point of transaction sign: Every customer checkout or payment location, in a minimum 16-point Arial font, but in any case no smaller or less prominent than surrounding text.

What’s the penalty for non-compliance with surcharge rules? Fines. Acquirers of any merchant identified as surcharging improperly may be assessed an immediate US $1,000 fine. They pass those down to their clients. Acquirers (the credit card processor or merchant account provider) merchant clients could face fines ranging from $50,000 to $1 million. This is not all inclusive.

  1. Effective January 2025, Kansas allows surcharging.
  2. In 2015, the 11th U.S. Circuit Court of Appeals, a federal court, overturned Florida state law as being unconstitutional, allowing surcharges to legally continue in Florida and nine other states that had enacted bans against them. The case was a highly contentious 2-1 decision in which the court’s chief judge said the state surcharge bans (like Florida’s) were “being struck down by a federal court for no good reason.”
  3. In December 2019, Oklahoma attorney general official opinion declaring the state’s no-surcharging law unconstitutionally restricts free speech. 

Surcharge Laws Stories:

  • NYS new rules in effect on February 11, 2024. https://www.governor.ny.gov/news/governor-hochul-announces-new-law-clarify-disclosure-credit-card-surcharges-goes-effect-sunday
  • Visa Intensifies Enforcement on Merchant Surcharges https://thefinancialtechnologyreport.com/visa-intensifies-enforcement-on-merchant-surcharges/
  • Visa Revises Rules Governing Surcharge Programs https://www.taftlaw.com/news-events/law-bulletins/visa-revises-rules-governing-surcharge-programs-1/
  • 2/2023 NJ Businesses Fined For Credit Card Surcharge Without Proper Notice https://lakewoodalerts.com/cracking-down-businesses-fined-for-credit-card-surcharge-without-proper-notice/
  • California update
    https://oag.ca.gov/consumers/general/credit-card-surcharges
  • 2018 Florida https://www.nbc-2.com/story/40273084/you-can-legally-be-charged-extra-for-using-a-credit-card
  • 2018 case in California http://delfinomadden.com/credit-card-surcharge-ban/
  • http://fortune.com/2017/03/29/credit-card-charges-supreme-court-freedom-speech/

State statutes on surcharge laws

  1. Maine Credit and Debit Card Surcharges https://www.maine.gov/pfr/consumercredit/consumer/surcharge.html
  2. https://oag.ca.gov/hiddenfeeshttps://portal.ct.gov/DCP/Legal/Credit-Card-Surcharge
  3. https://m.flsenate.gov/Statutes/501.0117
  4. https://portal.ct.gov/dcp/legal/credit-card-surcharge?language=en_US
  5. https://sll.texas.gov/faqs/credit-card-surcharge
  6. https://statutes.capitol.texas.gov/Docs/BC/htm/BC.604A.htm#604A.0021
  7. https://malegislature.gov/Laws/GeneralLaws/PartI/TitleXX/Chapter140d/Section28a Massachusetts statutes.
  8. Maine https://legislature.maine.gov/statutes/9-A/title9-Asec8-509.html
  9. Minnesota https://www.revisor.mn.gov/statutes/cite/325G.051

For more information, see Surcharge law resources under Merchant Alerts & Rules Links or contact your acquirer for accurate and current information specific to your situation. Neither Christine Speedy nor this web site provide legal advice. Consult an attorney for all your legal questions.

Does your company want to surcharge? Or do you want to reduce fees with payment optimization? Call Christine Speedy right now at 954-942-0483, 9-5 ET for compliant solutions. Please share your surcharge insights for others and ask any questions below. The information herein is based upon public information available at the time written and may change.

3D Merchant Services is rebranding as Greater Good Tech.

Disclaimer: This information is for reference only and is not legal advice. Rules are constantly changing, and you should verify the accuracy of surcharge laws for your business needs and location.

Visa Acquirer Monitoring Program (VAMP) Explained

Why does compliance with Visa’s new VAMP program matter and what do merchants need to do?Visa’s new VAMP program for online payments became effective April 1, 2025, consolidating five existing fraud and dispute programs into a single acquirer program. The payment gateway is a critical tool for merchant compliance. Do not assume your payment gateway will get you compliant.

Fraud problems are not just from real buyers but bots attacking web servers. A big mistake is thinking you won’t have a fraud problem with your B2B business. That’s because criminals are not necessarily looking for your business, but they are automatically seeking technical vulnerabilities. For example, card testers can blast a thousand attempted transactions in seconds. Without controls to prevent, you’ll be stuck with potentially thousands of dollars in authorization fees.

Fraud prevention and risk management are critical to maintaining the integrity of financial transactions. One of the ways Visa addresses these concerns is through the Visa Acquirer Monitoring Program (VAMP). This program aims to ensure that merchants and acquirers meet Visa’s security standards and mitigate fraud risks across the payment ecosystem. This article delves into what VAMP is, how it works, and how payment gateways contribute to compliance.

What is Visa VAMP?

The Visa Acquirer Monitoring Program (VAMP) is an initiative by Visa designed to monitor and enforce the compliance of acquirers and merchants with Visa’s security requirements. The program tracks merchant activities and identifies merchants who present an elevated risk for fraud, allowing Visa to take action before fraud risks escalate.

VAMP operates primarily by analyzing transaction data to detect patterns indicative of fraud. It uses a sophisticated risk algorithm that identifies outliers in a merchant’s transaction activity, such as unusual chargeback rates or instances of card-not-present fraud, both of which are major indicators of potential fraud.

If a merchant is flagged by the VAMP program, the acquirer is notified and required to investigate and take corrective actions. This can include additional monitoring or, in more severe cases, suspension of the merchant’s account. The goal is to protect cardholders and the broader Visa ecosystem from fraudulent activity.

Key Elements of the Visa Acquirer Monitoring Program

The Visa Acquirer Monitoring Program includes several important components that aim to maintain compliance and ensure the integrity of transactions:

  1. Risk Scoring and Monitoring: VAMP assigns risk scores to acquirers and merchants based on a variety of factors. Merchants with high chargeback rates, evidence of data breaches, or other signs of fraudulent behavior are placed under heightened scrutiny. Every month, Visa pulls data from your acquirer about:
    • How many of your online transactions were reported as fraud?
    • How many turned into disputes/chargebacks?
    • How many card-not-present transactions have you successfully processed?
    • Visa then plugs these numbers into one formula — the VAMP ratio — to see whether you (or your acquirer’s overall portfolio) are within acceptable limits.
  2. Risk Thresholds: The Visa VAMP ratio is calculated by Fraud Reports plus Disputes divided by the number of transactions.. For USA merchants, the excessive VAMP threshold ratio is 2.20% and a minimum of 1,500 transactions. Merchants who exceed these thresholds are flagged for further investigation. Fraud that turns into a chargeback gets double-counted. Effective April 1, 2026 the Excessive threshold drops to 1.50%, potentially flagging more merchants unless fraud and disputes are reduced.
  3. Corrective Actions and Penalties: Once a merchant is flagged, the acquirer is responsible for taking corrective actions. If corrective actions are not taken, Visa may impose penalties such as fines or even suspension of the merchant’s ability to accept Visa transactions. Acquirers then pass these costs along to merchants.
  4. Education and Resources: Visa provides acquirers with resources to help them better understand compliance and fraud prevention measures. This includes best practices, training, and guidance on preventing fraud and maintaining a secure payment environment.

Why VAMP Matters for Acquirers and Merchants

For acquirers, VAMP is a tool that ensures they are working with merchants who adhere to Visa’s standards for security and risk management. Acquirers are responsible for monitoring their merchants’ activities and reporting any fraudulent or non-compliant behavior to Visa. Failure to comply with VAMP can lead to increased fines, penalties, and even the termination of the ability to process Visa transactions.

For merchants, compliance with VAMP is essential for protecting the business from fraud-related losses. Non-compliance can result in financial penalties and loss of access to the Visa payment network, which can significantly impact the business’s ability to process payments.

How Payment Gateways Play a Role in VAMP Compliance

Payment gateways are a critical component of the payments infrastructure. Payment gateways play a key role in ensuring that merchants comply with proper authorization and Visa’s security protocols, including those outlined in VAMP. If you recall when EMV chips were launched, a lot of players in the payment ecosystem were not compliant, some of them took years to catch up and some never did.

  1. Fraud Detection and Prevention: Payment gateways incorporate various tools and technologies to detect and prevent fraudulent transactions. These tools include features such as Address Verification Service (AVS), CVV checks, velocity checks, 3-D Secure, other filters. By detecting and preventing fraud before it occurs, payment gateways help merchants stay within Visa’s risk thresholds. 3-D Secure can reduce merchant fees. Some gateways have more robust merchant manageable solutions than others.
  2. Security Features: Visa’s security standards require merchants to implement strong encryption and secure payment processes. Payment gateways are responsible for ensuring that all cardholder data is encrypted and stored securely. They also support features like tokenization, which replaces sensitive card data with unique identifiers, further reducing the risk of data breaches and fraud. All of the major payment gateways have robust security.
  3. Chargeback Management: A high chargeback ratio is a major red flag for the VAMP program. Payment gateways provide tools for merchants to manage and reduce chargebacks, such as implementing fraud prevention measures. The most effective solutions automate transaction management to mitigate risk of fraudulent attempts in the first place.
  4. PCI DSS Compliance: Payment gateways are required to comply with the Payment Card Industry Data Security Standard (PCI DSS), which mandates a set of security measures designed to protect cardholder data. PCI DSS compliance is directly linked to Visa’s security expectations and plays a critical role in VAMP compliance. All of the major payment gateways offer PCI compliant solutions.
  5. Reporting and Analytics: Payment gateways also provide merchants and acquirers with detailed transaction reports and analytics that can help identify trends, spot potential fraud, and ensure ongoing compliance with Visa’s monitoring criteria.
  6. Proper Authorization: This is one of the least talked about but critical component to mitigate chargebacks. Examples of challenging rules that many payment gateways don’t comply with are mismatched authorization and settlement, one dollar pre-authorizations, and expired authorizations.

Visa VAMP is a critical initiative for maintaining the security and integrity of the Visa payment ecosystem. It is a program that holds acquirers and merchants accountable for managing fraud risks and ensures that high-risk merchants are identified and monitored effectively. Payment gateways play a central role in compliance by offering essential fraud prevention tools, securing transactions, and supporting proper authorization compliance.

By staying proactive about security, monitoring transaction data, and implementing Visa’s recommended best practices, merchants and acquirers can ensure they remain compliant with Visa’s VAMP program, help protect themselves and their customers from fraud, and reduce fees.

For more detailed guidance on how to comply with Visa VAMP, visit Visa’s official Acquirer Monitoring Program page.

For a free consultation on compliant B2B payment gateways, contact 3D Merchant Services.

2025 Credit Card Surcharge Laws Update

What are 2025 surcharge regulations?

Our primary customer base is business to business (B2B) so this credit card surcharge article includes specifics for companies, not government or education, and in particular for

B2B and automotive, truck, and related dealers. Merchants must consider Federal and state laws as well as merchant account, Visa, MasterCard and other card networks compliance rules.

Since our August 2024 update there have been multiple changes. Most notably, on July 1, 2024, when a new California law called Senate Bill 478 went into effect.

Which states prohibit merchants surcharging?

States with other surcharge regulations

  • Colorado allows credit card surcharging up to 2%. 
  • New York, New Jersey, Nevada, and South Dakota prohibit surcharges from exceeding the cost that the merchant pays to accept the card. (See also Visa merchant surcharge rules.)
  • The legislative intent in many states was to protect consumers, and not to restrict B2B surcharging, therefore, B2B companies may have exceptions. 

Can a B2B company use surcharge to offset fees?

The rules vary across multiple card brands and terms of acceptance. Here’s a 2025 updated review of who can surcharge, what card types, and checklist of how to roll out credit card surcharge at your company. The answers are targeted for business to business merchants, our area of expertise. Historically if a merchant complies with Visa surcharge rules, they’d be compliant with other brands, so we often cite that as the standard. A B2B company that wishes to surcharge in every state should contact an attorney.

What is a credit card surcharge?

Surcharge is any fee charged by a merchant for the use of a card.These disclosure requirements include advance notice to both Mastercard and the merchant’s acquirer of the merchant’s intention to impose a surcharge no less than thirty days before the merchant implements a surcharge.

These disclosure requirements include advance notice to both Mastercard and the merchant’s acquirer of the merchant’s intention to impose a surcharge no less than thirty days before the merchant implements a surcharge.

What’s the difference between a surcharge and convenience fee? Convenience fees can only be charged for a bona fide convenience in the form of an alternative payment channel outside the Merchant’s customary payment channels and not charged solely for the acceptance of a Card. If a merchant only accepts credit cards, it’s prohibited. If a merchant is 100% card absent, merchant cannot charge a convenience fee.

Card brands agree on this for surcharging:

  1. Merchant Discount Rate is the fee, expressed as a percentage of the total transaction amount that a Merchant pays to its Acquirer or Service Provider for transacting on a Credit Card brand. In short, it’s typically all the fees on your merchant statement EXCEPT PCI compliance, terminal rental fees or any other special fee that is not paid via the mechanism of the per-transaction merchant discount fee. Per Visa, merchants must “Limit the amount to your merchant discount rate (MDR) for the applicable credit card or 3% whichever is lowest.” This is the reason merchants can get in trouble if their surcharge solution provider charges a flat amount for every card type.
  2. The Surcharge amount must be submitted separately (in the defined surcharge field) from the Transaction amount in the authorization and clearing message.
  3. The receipt must list the surcharge amount separately.
  4. If the original transaction has a partial or full refund, the surcharge amount must all be refunded proportionally.
  5. Surcharge on debit or prepaid cards is prohibited for all merchants.To ensure compliance use a payment gateway that can identify the card brand and type of card to allow surcharges only on eligible cards.
  6. The fee must be relative to their average cost of card acceptance.
  7. Any surcharge amount, if allowed, must be included in the Transaction amount and not collected separately.

How much can a merchant surcharge?

In short, surcharging is allowed to cover costs, not to make a profit. Let’s face it, based on the rules above, to simplify implementation, merchants will surcharge at the brand level because they lack the technology to discern between product types on a per transaction basis. Taking all that into account what can you surcharge?

  • Cannot exceed Maximum Surcharge Cap, which for Visa is currently 3%, effective April 15, 2023, and MasterCard remains at 4% in 2025.

Just because somebody offers it doesn’t make it right. Some companies are offering “free merchant accounts” by offsetting fees with surcharge of 3.5% or even 4%, both exceeding current rules. The average B2B company has much lower than 3.5% effective rate so that was always a violation of card acceptance rules, subject to penalty. The companies offering these services are making big money on the spread of actual fees vs what customers are paying. Again, these are card brand rules violations.

Non-compliant merchants could face fines ranging from $50,000 to $1 million according to a memo from a. credit card processor to merchants, 12/2023 ahead of expected increase in Visa enforcement in 2024 and beyond.

Surcharge checklist:

  1. Merchants must notify their acquirer 30 days before they begin surcharging; must state whether will surcharge at the brand level or product level.
    1. https://www.visa.com/merchantsurcharging
    https://www.mastercard.us/en-us/business/overview/support/merchant-surcharge-rules.html
    1. Amex- none required
  2. For card not present orders, disclose verbally if telephone; for online orders minimum 10-point Arial font, but in any case no smaller or less prominent than surrounding text.
  3. Receipt must be delivered with the surcharge as a separate line item.
  4. The surcharge amount must be sent with the transaction for authorization.
  5. Retail Point-of-Entry Disclosure example: “We impose a surcharge on credit cards that is not greater than our cost of acceptance. We do not surcharge debit cards. ” Main entrance(s) of the Merchant Outlet, in a minimum 32-point Arial font, but in any case no smaller or less prominent than surrounding text.
  6. Point of transaction sign: Every customer checkout or payment location, in a minimum 16-point Arial font, but in any case no smaller or less prominent than surrounding text.

What’s the penalty for non-compliance with surcharge rules? Fines. Acquirers of any merchant identified as surcharging improperly may be assessed an immediate US $1,000 fine. They pass those down to their clients. Acquirers (the credit card processor or merchant account provider) merchant clients could face fines ranging from $50,000 to $1 million. This is not all inclusive.

  1. Effective January 2025, Kansas allows surcharging.
  2. In 2015, the 11th U.S. Circuit Court of Appeals, a federal court, overturned Florida state law as being unconstitutional, allowing surcharges to legally continue in Florida and nine other states that had enacted bans against them. The case was a highly contentious 2-1 decision in which the court’s chief judge said the state surcharge bans (like Florida’s) were “being struck down by a federal court for no good reason.”
  3. In December 2019, Oklahoma attorney general official opinion declaring the state’s no-surcharging law unconstitutionally restricts free speech. 

Surcharge Laws Stories:

  • NYS new rules in effect on February 11, 2024. https://www.governor.ny.gov/news/governor-hochul-announces-new-law-clarify-disclosure-credit-card-surcharges-goes-effect-sunday
  • Visa Intensifies Enforcement on Merchant Surcharges https://thefinancialtechnologyreport.com/visa-intensifies-enforcement-on-merchant-surcharges/
  • Visa Revises Rules Governing Surcharge Programs https://www.taftlaw.com/news-events/law-bulletins/visa-revises-rules-governing-surcharge-programs-1/
  • 2/2023 NJ Businesses Fined For Credit Card Surcharge Without Proper Notice https://lakewoodalerts.com/cracking-down-businesses-fined-for-credit-card-surcharge-without-proper-notice/
  • California update
    https://oag.ca.gov/consumers/general/credit-card-surcharges
  • 2018 Florida https://www.nbc-2.com/story/40273084/you-can-legally-be-charged-extra-for-using-a-credit-card
  • 2018 case in California http://delfinomadden.com/credit-card-surcharge-ban/
  • http://fortune.com/2017/03/29/credit-card-charges-supreme-court-freedom-speech/

State statutes on surcharge laws

  • https://oag.ca.gov/hiddenfeeshttps://portal.ct.gov/DCP/Legal/Credit-Card-Surcharge
  • https://m.flsenate.gov/Statutes/501.0117
  • https://portal.ct.gov/dcp/legal/credit-card-surcharge?language=en_US
  • https://sll.texas.gov/faqs/credit-card-surcharge
  • https://statutes.capitol.texas.gov/Docs/BC/htm/BC.604A.htm#604A.0021
  • https://malegislature.gov/Laws/GeneralLaws/PartI/TitleXX/Chapter140d/Section28a Massachusetts statutes.
  • Maine https://legislature.maine.gov/statutes/9-A/title9-Asec8-509.html
  • Minnesota https://www.revisor.mn.gov/statutes/cite/325G.051

For more information, see Surcharge law resources under Merchant Alerts & Rules Links or contact your acquirer for accurate and current information specific to your situation. Neither Christine Speedy nor this web site provide legal advice. Consult an attorney for all your legal questions.

Does your company want to surcharge? Or do you want to reduce fees with payment optimization? Call Christine Speedy right now at 954-942-0483, 9-5 ET for compliant solutions. Please share your surcharge insights for others and ask any questions below. The information herein is based upon public information available at the time written and may change.

3D Merchant Services is rebranding as Greater Good Tech.

Disclaimer: This information is for reference only and is not legal advice. Rules are constantly changing, and you should verify the accuracy of surcharge laws for your business needs and location.