
A customer who has ordered from you four times in the last year calls their bank and says the fifth order was not them. The issuer files a Visa dispute under condition 10.4, Other Fraud – Card-Absent Environment, and unless you can show otherwise, the money moves. Since April 2023 Visa has had a specific remedy for exactly this situation: Compelling Evidence 3.0, usually shortened to CE3.0. It lets a merchant prove that the same card and the same person were behind earlier, undisputed orders, and if the proof meets Visa's test the fraud dispute is invalid. The rule has been changing quickly. Visa began qualifying transactions automatically through Visa Secure in October 2025, attached a fee to successful qualifications in April 2026, and from 24 October 2026 will accept purchase history from other merchants. This guide explains what the rulebook actually requires, where the evidence is used, what is changing, and what a card-not-present business should be capturing today.
What CE3.0 is, and what it is not
CE3.0 is not a product or a portal. It is a rule inside the Visa Core Rules and Visa Product and Service Rules, listed in the table of invalid disputes for condition 10.4. When an acquirer supplies evidence that meets the rule, the issuer's dispute is invalid, and financial responsibility stays with the issuer rather than moving to the merchant. Visa's own description is that CE3.0 is an optional program intended to combat first-party fraud misuse, designed to identify when a cardholder participated in card-not-present transactions that are now claimed to be fraudulent.
Two boundaries matter before anything else. First, CE3.0 applies only to dispute condition 10.4. It does nothing for a not-as-described claim under 13.3, a cancelled-recurring claim under 13.2, or a card-present fraud dispute under 10.3. Second, it is about the cardholder's history with the card, so it cannot help with a first-time buyer. A merchant whose disputes come mostly from new customers needs authentication and fraud screening, not CE3.0.
It also sits alongside, not in place of, the older compelling evidence list. Visa's Table 11-6 still allows an acquirer to answer a 10.4 dispute with, for example, evidence that three or more of customer account ID, delivery address, device ID or fingerprint, email address, IP address and telephone number were used in an undisputed transaction. That older item is broader in the data it accepts but does not carry the same invalid-dispute outcome. CE3.0 is narrower and stronger.
The qualifying test, as written in the rulebook
The figures below come from the 18 April 2026 edition of the Visa Core Rules and Visa Product and Service Rules, Table 11-28, and apply to disputes processed through 23 October 2026. A separate section covers what changes after that date. To qualify, all of the following must be true.
Two prior transactions on the same payment credential
The same payment credential, meaning the Visa account number or the token, must have been used in two previous transactions that the issuer did not report to Visa as fraud. Those transactions must have been processed more than 120 calendar days before the dispute, and not more than 365 calendar days before the dispute's processing date. The rulebook measures that window from the dispute's processing date. Several third-party guides, Verifi's own overview page and at least one large processor's documentation describe it as running from the date of the disputed transaction instead, so a prior order that sits near either edge of the window is worth checking both ways before you rely on it. The 120-day minimum does not apply if the earlier transactions were original credit transactions. If the issuer files a fraud report on one of the earlier transactions, it only counts against you if Visa received that report before the dispute processing date, so a late fraud report cannot retroactively disqualify your evidence.
A description of what was bought
You must supply a detailed description of the merchandise or services for both the disputed transaction and the two earlier ones. Visa's published CE3.0 FAQ says the description must go above and beyond the merchant name or merchant category code, and gives subscription IDs, service plans and service dates as examples; a line that only repeats your billing descriptor does not qualify. There is one alternative: for e-commerce transactions processed through Visa Secure with ECI 7 and a CAVV, which includes Visa Data Only transactions, a purchase order number can be used instead of the description.
Two matching data elements, one of which must identify the device or connection
The device ID, the device fingerprint, or the IP address must be the same in the earlier transactions as in the disputed one, and so must at least one additional element from the list. The rulebook is specific about the format of each, and a value that fails the format test does not count:
- IP address: the cardholder's public IP address, in clear text, not hashed, in IPv4 or IPv6 format.
- Device ID: a unique identifier of the cardholder's device that the cardholder could verify, such as a serial number or IMEI, at least 15 characters, in clear text and not hashed.
- Device fingerprint: a unique identifier derived from at least two software or hardware properties of the device, such as browser version and operating system version, at least 20 characters; this one may be hashed.
- Customer account or login ID: a unique identifier the cardholder uses to authenticate on your site or app at the time of the transaction, in clear text, and a value the cardholder would recognise.
- Full delivery address: the cardholder's complete shipping address, including street, city, state or province, postal code and country, in clear text.
Email address and telephone number are not on the CE3.0 list in the rulebook, even though they appear in the older compelling evidence item. At least one large processor's CE3.0 documentation does list email as an acceptable secondary element, so processors may accept more than the rule requires, but the rulebook is what the issuer is bound by. Treat email as supporting detail, not as one of your two qualifying elements.
Where the evidence is used: before the dispute or in response to it
The same evidence can be presented at two points, and the outcome differs.
Pre-dispute, through Order Insight. Verifi, which Visa owns, operates Order Insight. When an issuer looks up a transaction because a cardholder is querying it, a merchant enrolled in Order Insight returns its captured data automatically, and if that data meets the CE3.0 test the dispute is deflected before it is created and liability sits with the issuer. Nothing posts as a chargeback, so nothing counts toward your dispute ratio. Verifi's own summary is that if the qualified transaction data for the disputed transaction matches the eligible transactions, dispute liability shifts from the seller to the issuer, and the dispute is deflected.
Post-dispute, in your response. If the dispute has already been filed, your acquirer includes the same evidence in its response. For a 10.4 dispute that response is the pre-arbitration attempt, due within 30 calendar days of the dispute processing date. The issuer may only decline it on limited grounds, and where compelling evidence was supplied the issuer must certify either that the contact details you provided do not match its records or that it contacted the cardholder to review the evidence and can explain why the cardholder still disputes the charge. Winning at this stage recovers the funds, but the dispute was still filed, so the chargeback fee and the count against your ratio have already happened. Dispute-management providers consistently describe the post-dispute path as a recovery mechanism and the pre-dispute path as the one that protects your monitoring-program standing.
The VAMP connection is the reason many high-risk merchants care. Visa's Acquirer Monitoring Program counts reported fraud, TC40 records, as well as disputes, and a fraud report that is successfully answered with CE3.0 is excluded from the VAMP calculation. With the merchant threshold now at 1.5% (see our VAMP guide), removing qualifying fraud reports from the numerator can be the difference between a warning and enforcement fees.
What has changed since 2025, and what changes next
Visa has published three dated changes and the industry is reporting a fourth. In order:
- 17 October 2025: Visa began automatically qualifying transactions for CE3.0 through Visa Secure, including Visa Data Only, in the US region. Visa's announcement does not describe the mechanism in detail; industry coverage describes it as using the authentication data already flowing through Visa Secure rather than evidence the merchant assembles afterwards.
- 17 April 2026: Visa introduced a fee for successful CE3.0 qualifications. Visa's merchant business news announcement confirms the fee exists but does not publish the amount, and how or whether it is passed through depends on your acquirer, so ask before you assume CE3.0 is free.
- 18 April 2026: According to dispute-management providers reporting Visa's announcement, CE3.0 was extended to non-disputed fraud, meaning cases where an issuer files a TC40 fraud report but never files a dispute. Order Insight-enabled merchants can challenge the fraud report using the same criteria and have it excluded from VAMP. This change is not in the public rulebook, so treat the mechanics as something to confirm with your processor.
- 24 October 2026: The rule itself is rewritten. For disputes processed on or after this date, the two prior transactions may have been at one or more merchants, not only at the merchant fighting the dispute; the same card or a payment credential associated with it, such as a token, must have been used. The purchase-order-number alternative is extended to transactions carrying a Visa Token Service TAVV or a Visa Intelligent Data Exchange match key. Login IDs for an agentic payment provider count as a customer account ID. And, for the avoidance of doubt, device ID and device fingerprint are treated as the same element, so an acquirer may not submit both and must pick another element instead.
The multi-merchant change is the one to watch. Today a subscription business with a customer on their fifth renewal qualifies easily, while a retailer whose customer has bought from it only once cannot, because it has no earlier transactions of its own. After 24 October 2026, that retailer's dispute can, in principle, be invalidated by the cardholder's history elsewhere. How the cross-merchant history is surfaced will depend on the data Visa holds and on what acquirers and gateways implement, and the rulebook says nothing about that mechanism yet, so it is too early to count on it.
What to capture now
Every element of the test is data you either captured at checkout or did not. Nothing can be reconstructed after the dispute arrives, and a hashed or truncated value fails the format rules. For a card-not-present business the checklist is short:
- Store the customer's public IP address for every order, in clear text, and keep it for at least 13 months so it outlives the 365-day window.
- Generate a device fingerprint from at least two device properties and make it at least 20 characters. If your gateway or fraud tool already does this, confirm the value is stored against the order, not only used for a real-time score.
- Require an account or login for repeat purchases, or at least tie orders to one, so there is a recognisable login ID to match. Guest checkout produces orders that cannot qualify on that element.
- Store the full shipping address, every field, exactly as entered.
- Record a per-order description that names the product, plan or service. If your order data only says the merchant name, add line-item detail.
- Keep the link between the order and the payment credential. If you use network tokens, make sure you can identify earlier orders on the same token; the rule already accepts a token as the payment credential and the October 2026 wording makes that explicit.
Then ask your processor three questions. Does it submit CE3.0 evidence through Visa Resolve Online, and is that automatic or does it need you to attach prior-order data to each response? Are you enrolled in Order Insight, so the evidence works pre-dispute? And what does it charge, now that Visa charges for successful qualifications? A processor that cannot answer the first question is not using CE3.0 on your behalf, whatever its marketing says.
Where CE3.0 will not save you
Merchants sometimes treat CE3.0 as a general answer to friendly fraud. It is not. It does not apply to any dispute condition other than 10.4, and a cardholder who says the goods never arrived has filed a 13.1, not a 10.4. It needs two qualifying prior transactions, so a second order from a customer whose first order was 60 days ago does not qualify, and neither does a fifth order if the earlier ones were more than a year before the dispute. It needs the device or IP element; two orders that match only on login ID and shipping address fail. And the 10.4 dispute itself has a 120-day time limit from the transaction processing date, so the cardholder's window to file is as long as the minimum age of your evidence.
For everything CE3.0 does not cover, the tools are the ones covered elsewhere on this site: Rapid Dispute Resolution and prevention alerts for disputes you would rather refund than fight, and the representment and pre-arbitration cycle for disputes you can win on other evidence.
The bottom line
Meet the CE3.0 test and a card-absent fraud dispute is invalid by definition, which makes it the most favourable rule Visa has written for merchants with repeat customers. But the test is precise, the data has to exist before the dispute does, and since April 2026 a successful qualification is no longer free. The merchants who benefit are those whose checkout captures a clear-text IP address or a real device fingerprint, a recognisable login, a full shipping address and a line-item description on every order, and whose processor actually presents that data through Order Insight and Visa Resolve Online. For a subscription, digital goods or continuity business, that is worth building now, before the October 2026 expansion makes purchase history the deciding factor in even more 10.4 disputes.
Categories

Kyle Hall is a fintech entrepreneur, software engineer, and marketing strategist with over a decade of experience in high-risk payment processing and SaaS development. He is the CEO of PayKings, a lea...
More from Kyle Hall
Chargeback Pre-Arbitration and Arbitration: What Happens After Representment
You received a chargeback, sent the order record, delivery confirmation and customer emails back thr...
Cannabis Merchant Processing: How to Get a Cannabis or Dispensary Merchant Account
Yes — licensed cannabis businesses can get merchant accounts. The route runs through cannabis mercha...
Card Testing Attacks: How Bots Use Your Checkout to Validate Stolen Cards, and How to Stop Them
A card testing attack is a bot running hundreds or thousands of stolen or guessed card numbers throu...
Network Tokens for High-Risk Merchants: Approval Rates, Ownership, and Switching Costs
If your customers' cards are stored for recurring or repeat billing, the highest-leverage change ava...