
If you bill cards on a schedule, a share of your renewals will decline every cycle, and most billing platforms retry them automatically. That is sensible: a card that was over its limit on Monday may clear on Friday. But Visa and Mastercard both limit how often you may retry, which declines you may retry at all, and what you pay when you get it wrong. The limits are counted per card at each merchant, so a dunning tool, a gateway's automatic retries and an agent re-keying the card by hand all draw on the same allowance.
The numbers have also moved. Many processor help pages still say Visa allows 15 reattempts in 30 days. The April 2026 edition of the Visa Core Rules and Visa Product and Service Rules, the current published edition, allows up to 20. This guide sets out what the rules say as of September 2026, what the two networks charge, and how to build a retry policy that recovers revenue without paying for it in fees.
Why the networks meter retries
Every retry is a new authorization request that the issuing bank has to process. A retry that cannot succeed, on a closed account or a card reported stolen, is pure cost to the issuer and the network. Repeated attempts on the same card also look exactly like card testing, where a bot runs a number again and again to see whether it is live. The networks' answer has been to tell merchants plainly, in the decline response itself, whether a retry has any chance of working, and to charge merchants that ignore the answer.
Visa: four decline categories
Visa's rules group every decline response code into one of four categories, and the category decides whether and how often you may resubmit. The table sits in section 7.3.6.3, Use of Authorization Response Codes, of the April 2026 Visa rules:
- Category 1, issuer will never approve. Codes include 04 (pick up card), 07 (pick up card, special condition), 12 (invalid transaction), 14 (invalid account number), 15 (no such issuer), 41 (lost card), 43 (stolen card), 46 (closed account), 57 (transaction not permitted to cardholder) and the stop-payment and revocation codes R0, R1 and R3. After a Category 1 decline, a merchant must never resubmit an authorization request for the same payment credential.
- Category 2, issuer cannot approve at this time. Codes include 51 (not sufficient funds), 61 (exceeds approval amount limit), 65 (exceeds withdrawal frequency limit), 59 (suspected fraud), 62 (restricted card), 91 (issuer or switch inoperative) and 96 (system malfunction). Reattempts are permitted, up to 20 attempts in 30 days.
- Category 3, data quality: revalidate payment information. Codes include 54 (expired card or expiration date missing), 55 (PIN incorrect or missing), 82 (negative CAM, dCVV, iCVV or CVV results) and N7 (decline for CVV2 failure). Reattempts are permitted, up to 20 attempts in 30 days.
- Category 4, generic response codes: every decline code not listed in the first three. Reattempts are permitted, up to 20 attempts in 30 days.
A few details catch merchants out. Code 05, do not honor, is one of the most common declines merchants see, and it is not in any of the first three lists, so it falls into Category 4 and is retryable within the limit. Code 59, suspected fraud, sits in Category 2, not Category 1. And from 25 July 2026 Visa added code 83, fraud/security, a Visa-only code used when Visa's stand-in processing declines a transaction as high-risk or fraudulent. It is also a Category 2 code.
The 20-attempt limit is recent enough that you will still find 15 in a lot of documentation. Visa set the four-category structure in 2020 and 2021 with a limit of 15 reattempts in 30 days, and many acquirer and gateway help pages still quote that figure. The April 2026 rulebook says 20, and PayPal's merchant guidance, updated in May 2026, uses 20 as well. If your processor's documentation says 15, working to 15 keeps you inside either number.
What Visa charges
Retries outside these limits attract Visa fees that acquirers pass through to merchants, typically itemized on the statement as excessive reattempt or integrity fees. Visa does not publish the amounts in its public rulebook. PayPal's May 2026 guidance lists $0.10 per excessive reattempt on a domestic transaction and a higher amount cross-border, and fee pages from other processors give the same domestic figure but different cross-border figures. The amount on your own statement is the one that counts.
Mastercard: merchant advice codes and Transaction Processing Excellence
Mastercard attaches a merchant advice code, or MAC, to many declines, telling the merchant directly what to do next. The ones that matter most for retries:
- MAC 01: new account information available. The card has been reissued or updated; get the new details, for example through an account updater service, before trying again.
- MAC 02: cannot approve at this time, try again later.
- MAC 03: do not try again.
- MAC 21: payment cancellation. The cardholder has stopped the payment, typically a recurring one, and it should not be resubmitted.
- MACs 24 to 30: retry after a set interval, from one hour (24) and 24 hours (25) through two, four, six, eight and ten days (26 to 30).
Mastercard enforces this through fees in its Transaction Processing Excellence program. Two of them bear directly on retries.
- Excessive authorization attempts. For merchants in the United States, a fee applies once a card has been declined 10 times at the same merchant within 24 hours, or 35 times within 30 days, and you keep trying. PayPal's May 2026 guidance lists the US fee as $0.50 per attempt over the threshold.
- Merchant advice code fee. This applies to card-not-present authorizations declined with MAC 03 or 21 where, in the previous 30 days, a transaction on the same card, at the same merchant and for the same amount was also declined with MAC 03 or 21. In other words, retrying a do-not-retry decline is billed.
When Mastercard introduced the excessive attempts fee, its own illustrative example was a fraudster using a bot to test whether a card number is valid, which is why the same fee can show up on a merchant's statement after a card testing attack. Our guide to card testing attacks covers that side of it.
Changing the transaction is not a new transaction
One tempting workaround is to resubmit a declined transaction with something changed, in the hope that it is treated as a fresh request. Visa's rules close that off. Section 1.7.2.1 says a merchant, acquirer, payment facilitator or processor that reattempts an authorization after a decline must not intentionally manipulate any data elements from the original request. The list includes the acquiring identifier, the acquirer and merchant country, the MCC, the POS condition code, the POS environment field, the POS entry mode and the electronic commerce indicator.
Read that list with multiple merchant accounts in mind. The acquiring identifier is on it, so resubmitting a declined transaction through a different merchant account is the kind of change the rule is written against. A decline has to be retried on its merits, or not at all.
A retry policy that stays inside the rules
Most of this can be handled in your billing platform's settings, but only if someone has checked what those settings actually do. The essentials:
- Read the decline code and the MAC on every failure, not just the approved or declined flag. Map each Visa code to its category and each Mastercard MAC to an action, and make the retry decision from that map.
- Never retry a Visa Category 1 decline or a Mastercard MAC 03 or 21 decline on the same card. Stop the billing attempt, notify the customer and ask for a new payment method.
- Honor Mastercard's timed MACs. If the issuer says retry after four days, the retry belongs on day four, not tomorrow.
- Count attempts per card across every system that can charge it. If your subscription platform retries on its own schedule and your gateway also retries automatically, the two are drawing on one allowance. Turn one of them off.
- Space soft-decline retries out rather than clustering them. A handful of attempts timed around when the customer is likely to have funds, such as a few days apart or near the start of a month, uses far less of the allowance than daily attempts.
- Fix Category 3 and MAC 01 declines with data, not repetition. An expired card or a reissued number needs new details, which account updater services and network tokens can supply automatically for stored cards.
- Check your statement for Visa integrity or excessive reattempt fees and Mastercard Transaction Processing Excellence fees. If they appear, they point to the exact part of your retry logic that is breaking the rules.
Why this matters more on a high-risk account
The businesses mainstream processors decline tend to be the ones that bill stored cards repeatedly: subscriptions and continuity products, memberships, payment plans, and services paid in instalments. That means more declines to manage each month and more places for a badly configured retry loop to run. Per-attempt fees are small on their own, but a loop that retries a few thousand closed accounts every day adds up quickly, and the pattern of repeated declines on the same cards is visible to your acquirer.
It also works the other way. Recovering soft declines within the rules is one of the cheapest sources of revenue a recurring-billing merchant has, and a clean retry policy protects it. Our guides to network tokens and to free trial and subscription billing rules cover the other two pieces of the same problem: keeping stored card details current, and keeping the recurring charges themselves compliant.
How PayKings approaches it
PayKings places high-risk and recurring-billing merchants with acquiring banks that understand these models, with gateways that return the full decline code and merchant advice code and that support account updating for stored cards. If you are seeing retry or integrity fees on your statement, or you are setting up recurring billing and want the retry logic right from the start, talk to our team about a merchant account built for how you actually bill.
Categories

Kyle Hall is a fintech entrepreneur, software engineer, and marketing strategist with over a decade of experience in high-risk payment processing and SaaS development. He is the CEO of PayKings, a lea...
More from Kyle Hall
Chargeback Time Limits: How Long Customers Have to Dispute a Charge, and How Long You Have to Respond
Ask how long a customer has to file a chargeback and most people will say 120 days. That is the righ...
PCI Compliance for Online Merchants: Which SAQ You File and What the SAQ A Script Rule Requires
Every merchant that accepts cards is required to comply with PCI DSS, and every year your acquirer c...
MCC 5723: Where the Firearms Merchant Code Is Required, Where It Is Banned, and What the House Bill Changes
For most of the history of card acceptance, a gun store was coded like any other sporting goods or g...
The Visa–Mastercard Settlement: What Changes for Merchants, When, and What It Leaves Alone
On November 10, 2025, Visa and Mastercard signed a settlement with the class of every merchant that ...