A declined card-not-present payment is rarely the end of the transaction. Subscription platforms retry overnight, gateways retry on a schedule, and some merchants simply send the same request again until something comes back approved. Both card networks limit how that may be done, and both charge for getting it wrong. The charges land on the acquirer's invoice first and on the merchant's statement after, usually as a line nobody on the merchant's side recognises.
This piece sets out what the rules say as of September 2026. The Visa side is taken from the Visa Core Rules and Visa Product and Service Rules dated 18 April 2026, which Visa publishes, and from earlier public editions where they date a change. Mastercard's retry program and both networks' fee schedules are not public, so where a figure comes from processor or third-party guidance rather than the network, we say so.
Visa: Four Categories, One Hard Stop
Visa sorts decline response codes into four categories in Table 7-2 of its rules, Decline Response Code Use. The issuer must send the code that most accurately reflects the reason for the decline, and the category decides what the merchant may do next. The rule covers account verification requests as well as authorization requests.
- Category 1, issuer will never approve: codes 04, 07, 12, 14, 15, 41, 43, 46, 57, R0, R1 and R3, covering pick-up cards, invalid account numbers, lost, stolen and closed accounts, transactions not permitted to the cardholder, and stop-payment and revocation orders. After a Category 1 decline, a merchant must never resubmit an authorization or account verification request for the same payment credential.
- Category 2, issuer cannot approve at this time: codes including 51 (not sufficient funds), 59 (suspected fraud), 61 (exceeds approval amount limit), 91 (issuer or switch inoperative), 96 (system malfunction), 03, 62, 93, 5C and 9G.
- Category 3, data quality: codes including 54 (expired card or expiration date missing), 82, 6P and N7 (decline for CVV2 failure). These call for revalidating the payment details before trying again.
- Category 4, generic: every other decline code. Issuers are told to use these only where no other value applies.
For Categories 2, 3 and 4 the table permits reattempts up to 20 attempts in 30 days. A footnote binds issuers too: once an issuer has sent a Category 1 code, it must keep sending the same code. A merchant that retries a closed account is not going to catch the issuer in a better mood.
The stop-payment and revocation codes, R0, R1 and R3, are the ones subscription merchants hit. A cardholder who has told their bank to stop paying a merchant produces a Category 1 decline, and the retry logic that recovers a genuine insufficient-funds decline must not touch it.
The Limit Is 20, Not 15
Visa introduced the four categories in April 2020. A Visa rules update published in September 2020 moved codes 03, 62, 78 and 93 out of Category 1 from 17 April 2021, so that merchants could, in that document's words, reattempt up to 15 times in 30 days.
That figure has since changed. The April 2025 edition of the Visa Rules lists a change titled Authorization Retries and System Integrity Fee Program Updates, and its Table 7-2 reads: effective through 24 May 2025, up to 15 attempts in 30 days; effective 25 May 2025, up to 20. The October 2025 edition still printed both figures with their dates; the April 2026 edition carries only the 20.
Plenty of processor help pages and merchant guides still quote 15. A retry schedule built to stop at 15 is more conservative than the rule and costs nothing but recovered revenue. Anything that quotes 15 as the limit, whether it is merchant-facing documentation or a support script, is out of date.
What Changed in 2026
The April 2026 edition adds one code. From 25 July 2026, Visa uses response code 83, Fraud/Security (Visa use only), to signal that it declined a transaction in stand-in processing because of high-risk or fraudulent conditions. It sits in Category 2, so it counts toward the 20-attempt limit like any other temporary decline. It is not a code an issuer sends, so a spike in 83s says something about what Visa's own systems saw rather than about the cardholder's bank.
Visa's rules also govern what a retry may look like. Section 1.7.2.1 says an acquirer, merchant, payment facilitator or VisaNet processor that reattempts an authorization after a decline must not intentionally manipulate data elements from the original request. The rule names the acquiring identifier, the acquirer and merchant country, the MCC, the POS condition code, the POS environment field, the POS entry mode and the electronic commerce indicator. Resending a declined card-not-present transaction under a different MCC, or with the e-commerce indicator changed to look more trusted, is a rules violation whether or not it works.
What Visa Charges, According to Processors
The public rules do not contain Visa's fee schedule, and the amounts below come from processors and third parties, not from Visa. Processor and industry guidance agrees on a domestic fee of $0.10 for each reattempt beyond the limit, and that any reattempt after a Category 1 decline is chargeable from the first. The cross-border figure is reported inconsistently. One processor's fee page describes a $0.05 surcharge on top of the domestic fee. Two industry sources report that the cross-border fee rose from $0.15 to $0.25 per attempt on 25 April 2026. Visa has not published the figure, so ask the acquirer for its current pass-through rate before building a forecast on either.
Processors show the charge under their own statement descriptors, so the line a merchant sees varies by processor. When a merchant asks what the line is, the useful answer is the decline code behind each counted attempt, which the gateway has and the statement does not.
Mastercard: Read the Merchant Advice Code
Mastercard gives the merchant a second signal alongside the decline response code: the Merchant Advice Code, or MAC. The developer documentation for Mastercard Gateway, Mastercard's own gateway product, lists the values and the scheme's recommendation for each:
- 01, new account information available, and 04, token requirements not fulfilled for this token type.
- 02, cannot approve at this time, try again later.
- 03, do not try again.
- 21, payment cancellation.
- 24 to 30, retry after a stated interval: 1 hour, 24 hours, two days, four days, six days, eight days and 10 days respectively.
- R0, stop payment order; R1, revocation of authorization order; R3, revocation of all authorizations order. Mastercard's guidance is to stop processing payments under the current payer agreement after R1, and under any payer agreement after R3.
The MAC is more specific than Visa's categories. A merchant that retries a MAC 25 decline after an hour has ignored advice that told it to wait a day, where a MAC 02 decline sets no interval at all.
Mastercard charges for retries under its Transaction Processing Excellence program, but its thresholds and fees are not in any Mastercard document we could access, and third-party accounts of them do not agree. One gateway's knowledge base describes a fee on card-not-present retries of the same card and amount within 30 days of a MAC 03 or MAC 21 decline. A chargeback-services firm reports a limit of 10 attempts in 24 hours or 35 in 30 days on most decline codes, with $0.50 charged for each attempt beyond it. Reported per-attempt amounts range from a few cents to $0.50, depending on the source and the year. Treat the Mastercard numbers as unverified until the acquirer confirms the current schedule in writing.
What a Merchant-Services Team Should Check
- Where retry decisions are made. For most merchants they are made in a gateway or billing platform, not by the merchant. Find out which, for every card-not-present merchant in the portfolio, and whether it reads the Visa category and the Mastercard MAC or only an approved or declined flag.
- That Category 1 declines and MAC 03 and 21 stop retries for that card, including the stop-payment and revocation codes R0, R1 and R3. For a subscription merchant, one of those codes means the customer has cancelled through their bank, so the record in the billing system should change too.
- That retries are counted over a rolling 30 days against the 20-attempt Visa limit, per card at the least. The rule table does not say what unit Visa counts by, so confirm it with the acquirer. Check too that MAC 24 to 30 intervals are honoured rather than overridden by a fixed schedule.
- That a retry resends the original data unchanged. MCC, POS entry mode and e-commerce indicator changes on a retry breach Visa's rules.
- Whether merchant-facing documentation, onboarding packs and support macros still say 15.
- Statement lines. Excessive-reattempt fees are small per attempt and add up fast on a subscription book. Find out what each processor calls them, and have support log the decline codes behind the count when a merchant disputes the charge.
None of this needs a new system. It needs the decline code captured on the transaction, carried into the ticket when a merchant calls about declines or fees, and checked against the table above. A merchant that knows which of its declines were Category 1 can fix its retry logic in an afternoon. One that only sees a growing fee line is left asking its ISO why.
Tags
About the author

Kyle Hall
Founder
Kyle Hall is a fintech entrepreneur, software engineer, and marketing strategist with over a decade of experience in high-risk payment processing and SaaS development. He is the CEO of PayKings, a leader in high-risk merchant services, and the founder of PulseCRM, a purpose-built CRM platform for the payments industry. Kyle specializes in building custom payment processing systems and growth strategies that empower merchant services providers to scale and succeed in the digital marketplace.
