Contactless payment processing solutions by Host Merchant Services for seamless commerce.

No Penny, No Problem: How Square’s Penny Rounding Feature Helps Merchants Adjust

After more than two centuries in circulation, the U.S. penny has been retired, with the final one-cent coin minted on November 12, 2025. The decision was driven by cost: producing a penny cost roughly 3.7 cents, creating millions in annual losses. While the vast number of pennies already in circulation will remain usable, shortages have already affected small businesses. Many merchants struggled to obtain rolls of pennies, leading to exact-change policies or ad-hoc rounding at the register.

To address this shift, Square introduced a new cash rounding feature for sellers. As penny shortages increased, retailers asked for a practical way to handle cash transactions without one-cent coins. In late 2025, Square released a built-in rounding function that automatically adjusts cash totals, eliminating pennies while keeping transactions straightforward for both merchants and customers.

Square’s Cash Rounding Solution: How It Works

Contactless payment solutions for small businesses and merchants.

Square’s cash rounding feature is straightforward but powerful. For any cash sale, the final total is automatically rounded to the nearest nickel (5¢) so that no pennies are required in change. In practice, prices may be rounded up or down depending on the final digits of the amount due. For example, Square’s system follows a symmetric rounding rule (similar to the one adopted in Canada after it axed its penny in 2013):

  • Totals ending in $X.01 or $X.02 are rounded down to $X.00
  • Totals ending in $X.03 or $X.04 are rounded up to $X.05
  • Totals ending in $X.06 or $X.07 are rounded down to $X.05
  • Totals ending in $X.08 or $X.09 are rounded up to $X.10

This rounding applies only to cash transactions; electronic payments (card, mobile, etc.) are charged to the exact cents, since no physical change is required. By rounding the final amount due (after applying taxes, discounts, etc.) to the nearest 5¢, Square’s approach keeps item prices, tax calculations, and receipts intact to the cent.

The customer pays a nickel-increment total, and the register displays a nickel change. For instance, if a customer’s purchase totals $10.02, the system would ask for $10.00 in cash; if it totals $10.03, it would round up to $10.05. The goal is to remove pennies from the equation without otherwise altering the pricing structure or shortchanging anyone in a meaningful way.

Behind the scenes, Square also ensures accurate record-keeping despite the rounding. The platform’s back-end transaction reporting continues to log the exact sale amounts and taxes as if pennies still existed, so merchants can report taxes on the true totals.

In other words, even if a merchant collects only $10.00 in cash for a $10.02 sale, Square will still record the 2¢ difference internally. This allows businesses to report the total dollar amount of tax collected and manage their accounts correctly, while the customer-facing side is neatly rounded.

It’s a technical fix that maintains financial accuracy and compliance – no pennies required. Square has emphasized that this is something their system “has always done” – handling sales tax reporting precisely – and the new rounding feature doesn’t change any of those fundamentals.

Square began piloting this cash rounding functionality with select U.S. sellers in December 2025. The timing was intentional: the penny’s end came right before the busy holiday shopping season, when stores often face long lines and hurried customers. By rolling out the feature ahead of the holidays, Square aimed to ensure a smooth shopping season for cash transactions despite the coin upheaval.

Notably, Square wasn’t entering completely uncharted territory with this move. The company had already implemented similar cash-rounding in other countries – Australia stopped using 1¢ and 2¢ coins back in 1992, and Canada retired its penny in 2013 – so Square was able to leverage that experience to deploy a U.S. solution quickly. The technology and know-how were already in Square’s toolkit; it was just a matter of tailoring it to U.S. currency and deploying it at the right moment.

Willem Avé, Square’s Global Head of Product, noted that while removing the penny may appear minor, it has a real effect on daily business operations. He pointed out that large retailers have the resources to plan and adapt quickly, while millions of neighborhood businesses still need practical ways to keep transactions running smoothly. He emphasized that Square’s role is to support those businesses so they can continue serving customers without disruption.

The rounding feature is important because it levels the playing field for small merchants navigating the penny phase-out. Big-box retailers and national chains may have the resources to swiftly reprogram systems or adopt new cash-handling policies. For a corner cafe or a family-run shop, however, figuring out how to handle a penny shortage can be a real challenge. Square’s solution basically hands them a ready-made fix – automatically applied through the point-of-sale – so they don’t have to develop a policy from scratch or worry about unfair outcomes.

Why the End of the Penny Was a Problem for Merchants

End of the Penny 1024x493 1

For context, cash remains an important payment method for many businesses, even in an increasingly digital age. According to Square, roughly 19% of all Square transactions in the U.S. are paid in cash, and in certain sectors, such as food and beverage, cash usage is highest. In fact, each week, an estimated 16.7 million pennies were changing hands in Square-facilitated purchases before the penny’s retirement.

That’s a lot of copper coins suddenly in limbo. When the U.S. Mint halted penny production, those coins didn’t instantly vanish – but they did become a finite (and quickly diminishing) resource. Banks began distributing fewer pennies, businesses started running low, and it wasn’t guaranteed that customers would bring in enough pennies to make change. This situation led to real headaches: stores unable to break a dollar properly, cash drawers skewed at day’s end, and frustrated buyers and sellers alike.

Small businesses were feeling the squeeze most acutely. By late 2025, some shops put up pleas or policies to cope. Signs appeared at registers saying “exact change only”, effectively urging customers to either fork over the exact pennies or use a non-cash method.

Major retailers and even government offices got in on this; for example, some McDonald’s locations and the Chicago city finance office notified customers they might not get pennies in change anymore.

Others adopted ad hoc rounding: some stores rounded down in the customer’s favor (essentially absorbing the 1–4 cent difference themselves), while others rounded up and asked the customer to pay a few cents more. The approaches varied: Aldi and Goodwill rounded down, while Whole Foods rounded up in at least one area, which only added to the confusion.

From a merchant’s perspective, neither option was ideal. If you always round down, you risk a small loss on each transaction (which can add up over hundreds of sales). If you round up, you risk irritating customers or appearing to nickel-and-dime them (quite literally).

There were also accounting questions and legal gray areas: How should sales tax be reported when the amount charged differs slightly? Could consistent rounding up be considered price gouging, or might it unfairly affect cash-reliant customers? Even organizations like the National Conference of State Legislatures (NCSL) began urging the adoption of standardized rules to prevent businesses from facing lawsuits or audits for improvised rounding practices.

This is the problem Square’s penny-rounding feature was designed to solve. Baking a uniform rounding policy directly into the point-of-sale system removes ambiguity. Every Square seller using the feature follows the same fair rounding rule (nearest nickel), and it’s applied consistently for every cash payer. Back-end accuracy means the books still balance and taxes are remitted correctly, avoiding the accounting pitfalls that worried some retailers.

Square’s solution essentially standardizes what could have been a chaotic, store-by-store experiment. As a result, a small change – losing the lowest-denomination coin – doesn’t spiral into big operational disruptions.

Smoother Sales and Shorter Lines (Pros of Rounding for Merchants)

Fast and secure payment processing solutions for small businesses.

For many small merchants, eliminating pennies may come as a relief once the transition is complete. One immediate benefit is time saved at the register. Rummaging for pennies or waiting for a customer to check their pockets for an extra cent or two can noticeably slow down checkout. Over countless transactions, those seconds add up. Transactions are a bit smoother when you have less change to count out, and even a tiny time savings per customer can reduce overall wait times when you serve hundreds of people a day.

During busy periods (think holiday shopping rushes or lunch-hour crowds), not accepting pennies can help keep lines moving more efficiently. Small businesses often have limited staff, and anything that speeds up each sale improves customer flow and satisfaction. Square explicitly highlighted this advantage, suggesting that by minimizing the need for pennies, the rounding feature “reduces friction” for cash-paying customers and keeps lines moving. In other words, it eliminates awkward pauses for penny-finding and allows both the customer and the cashier to get on with their day more quickly.

Merchants also see a simplification in cash handling and management. No pennies means one less coin type to stock, count, and roll. Cash drawers can be a little less cluttered (expect to stock more nickels and dimes; at least those are useful in multiple scenarios, unlike pennies, which primarily serve to make change).

Many business owners quietly welcome the penny’s demise because it removes a long-standing source of frustration – pennies often got lost, spilled, or ignored, and employees had to tediously count heaps of nearly worthless coins at closing time. Dropping pennies streamlines end-of-day reconciliation and can reduce the number of bank trips to load coin rolls.

There’s also an argument that ditching pennies could slightly streamline pricing for businesses. While merchants can still set prices at $4.99 or $9.97 if they prefer, they might also choose to simplify to nickel increments (e.g., $4.95 or $10.00) for a cleaner, penny-free pricing structure. Some cash-only businesses have already started doing this – opting for prices that round neatly – which can make cash transactions more straightforward.

Square’s data from Canada and Australia likely gave them confidence that U.S. sellers could adapt without alienating customers. After all, Canada eliminated pennies years ago, and daily commerce carried on with little trouble. In both Canada and Australia, people quickly adapted to nickel-rounding, and economists found no significant negative effects on consumers or businesses. In fact, customers in those countries largely appreciate avoiding nuisance coins, and businesses save time by handling less loose change.

Another pro is that Square’s approach is fair and symmetric – it doesn’t always round in favor of the store or the customer, but rather does whichever is mathematically nearest. This tends to even out over time. Some transactions are rounded up by a few cents; others are rounded down. Statistically, neither side consistently loses. Across many sales, some transactions are rounded up, others are rounded down, so there will be no net burden on consumers or businesses.

In other words, the pennies even out. This should allay shoppers’ fears that they’ll always pay a “rounding tax” and reassure merchants that they won’t lose revenue by rounding down. Square’s system ensures neutrality and transparency – receipts can even show a “rounding adjustment” line, so everyone knows what was done. With trust and consistency established, most folks won’t miss the penny after all.

Potential Drawbacks and Adjustments (Cons and Concerns)

No change (pardon the pun) comes without concerns. Some small businesses and shoppers worry about pricing and fairness once pennies are gone.

One issue is psychological pricing. Retailers love prices ending in .99 because they feel cheaper. If a $4.99 cash purchase often rounds to $5.00, shoppers may start treating $4.99 as “basically $5.” Some call this the “death of .99 pricing.” Over time, more prices may shift to endings like .95 or .00, which can feel less like a bargain.

Another concern is fairness for cash users, especially low-income customers who rely on cash more often. If stores rounded up too often, it would amount to a small fee for the people least able to absorb it. Square avoids this by rounding to the nearest nickel (up or down), not always up. In practice, most customers don’t mind rounding, and many don’t notice, especially when stores explain it clearly.

There’s also a learning curve. Some people still expect pennies in change or get confused by a rounded total. Simple signage and a short script help: “We don’t use pennies anymore, so cash totals round to the nearest nickel.” A few retailers may choose to round in the customer’s favor to protect goodwill, but as people adjust, that usually isn’t needed.

Finally, there are accounting and compliance details. Sales tax is still owed on the exact amount before rounding, so records must reflect that. Programs like SNAP also require equal treatment across payment types, which limits special rounding exceptions. Square’s approach, calculating tax first, then rounding the final cash total, helps ensure consistent, compliant reporting.

Lessons from a Penny-Free World: Canada, Australia, and Beyond

Penny Free World 1024x493 1

The U.S. may be late to drop the penny, but it has plenty of models to copy.

Canada phased out its penny in 2012-2013, and the change was smooth. Businesses used a rounding system much like Square’s: totals ending in .01-.02 round down, .03–.04 round up, and so on. Over the years, Canada has found no meaningful effect on inflation or consumer spending. Any “rounding tax” was tiny, just a few dollars per person per year at most, and retailers saw only modest gains. Canadians continued to use 99-cent shelf prices, while accepting that cash totals might be a nickel higher or lower.

Australia dropped its 1¢ and 2¢ coins in 1992, and rounding to the nearest 5¢ has been routine ever since. New Zealand followed (1c/2c in 1990, and later the 5c coin in 2006). Many European countries have also moved away from small-denomination coins, often using register rounding to the nearest €0.05, even when 1- and 2-cent coins remain in circulation.

The pattern is consistent: economies don’t break, shoppers don’t revolt, and retail adapts. The main changes are practical, lighter coin jars and simpler cash handling.

For U.S. merchants, these examples should be reassuring. The penny survived in the U.S. largely due to habit and symbolism, but rising production costs and everyday hassles finally prompted change. Now, tools like Square’s cash-rounding feature help businesses make the transition without awkward math or inconsistent treatment.

Pennies also remain legal tender, so people can still spend them. But as they stop circulating, lost, saved, or not returned through banks, their use will fade. The debate has shifted from “Should we get rid of the penny?” to “How do we operate without it?” and standardized rounding is the practical answer.

Conclusion

The end of the penny is a small but symbolic shift in how America handles money. For small businesses, it could have been stressful. With Square’s cash rounding, the transition is smoother. “No penny, no problem” is quickly becoming true at the register.

Square’s rounding feature shows how fintech can adapt to real-world currency changes. It bridges old pricing habits with new cash-handling rules. Sellers save time (less coin counting and fewer bank runs) and can reassure customers they aren’t being shorted. The adjustment is automatic, bi-directional, and clearly shown on receipts. Over time, many shoppers and merchants may no longer notice pennies.

Change can be annoying, but it can also be useful. Other countries have shown that removing low-value coins can streamline commerce without hurting consumers. The U.S. is now following that path, and tools like Square’s feature reduce the friction. For small businesses, the ones most likely to feel the impact, this removes a major hassle.

Retiring the penny should save money, simplify transactions, and speed up checkout. Square’s approach helps merchants keep operating normally while the system adjusts. So if you buy a coffee with cash and get a nickel back instead of four pennies, it’s not a mistake, it’s the new normal, working the way it’s meant to.

Frequently Asked Questions

What is Square’s cash rounding feature?

It automatically rounds cash totals to the nearest 5¢, so you don’t need pennies. Card and digital payments still charge to the exact cent

How does the rounding work?

Square uses “nearest nickel” rounding: .01–.02 down, .03–.04 up, .06–.07 down, .08–.09 up. So $10.02 becomes $10.00, and $10.03 becomes $10.05 (cash only)

Will customers pay more overall?

Not consistently. Some transactions round up, others round down, and it tends to balance out over time. Receipts can show the rounding adjustment to ensure clarity and transparency.

Does this change sales tax reporting?

No, tax is still calculated on the exact amount before rounding. Square records the true totals in the backend, so reports stay accurate.

Do merchants have to change sticker prices, such as $9.99?

No. You can keep the $0.99 price on the shelf. Only the final cash total is rounded, so the pricing strategy doesn’t have to change overnight.

Lost payment card being canceled on a mobile device with POS terminal background.

Recurring Billing & Subscription Payments: Best Practices to Reduce Churn in 2026

For subscription-based businesses, one of the most frustrating ways to lose a customer is through involuntary churn – when a subscriber who intended to stay is dropped because their payment didn’t go through. These are customers who want your service but get canceled due to a failed recurring charge. Unfortunately, this scenario is all too common. Studies have found that payment failures account for 20%-40% of customer churn in subscription businesses. In other words, up to nearly half of your lost subscribers may be leaving due to a billing issue, not by choice.

The good news is that this kind of churn is largely preventable. By optimizing your recurring billing processes, you can keep more customers on board and retain the revenue you’ve already earned. In this post, we’ll explore best practices to reduce churn in 2026 by minimizing failed subscription payments.

Why Failed Payments Cause Involuntary Churn

Fast payment processing with Host Merchant Services for secure business transactions.

Before implementing solutions, it’s important to understand the problem. Involuntary churn (also known as accidental churn) refers to losing customers due to payment issues rather than the customer’s intent to cancel. Unlike voluntary churn – when a customer actively decides to leave – involuntary churn happens when a legitimate recurring payment fails for some reason, causing the subscription to end against the customer’s wishes.

These failures can occur for a variety of mundane reasons: an expired credit card, insufficient funds in the account, the card being reported lost/stolen and replaced, a bank’s fraud detection system falsely declining a legitimate charge, or technical processing glitches in the payment network. None of these means the customer wanted to stop their service – it’s often a surprise to them when they find their account canceled or access cut off due to a payment issue.

The impact of these failed payments is significant. Industry research shows subscription companies lose an average of 10% of their annual recurring revenue to involuntary churn. In fact, payment failures are now cited as a top concern for many subscription businesses, even outranking customer acquisition in some surveys. This is not just lost immediate revenue, but lost future revenue as well – when a customer churns prematurely due to a failed payment, you forfeit all the remaining months or years of subscription they would have had. It directly cuts into customer lifetime value and can cost businesses millions.

Additionally, failed payments can hurt customer relationships and brand reputation. A once-loyal customer might feel frustrated or embarrassed when their subscription lapses unexpectedly, and some may not bother to sign up again even if the issue was an accident. Simply put, failed payments are a huge but often hidden driver of churn and lost revenue.

The silver lining is that involuntary churn is largely preventable. Unlike voluntary churn (which might require improving your product or service), reducing involuntary churn is about payment optimization and smart billing practices. By targeting the root causes of failed transactions and having processes in place to recover from payment declines, you can dramatically improve your subscription retention. Below, we outline several best practices to do exactly that.

Keep Cards Updated Automatically (Use Account Updater Tools)

Secure online payment processing with Host Merchant Services, trusted credit card solutions.

One of the most common causes of recurring payment failures is outdated card information: the customer’s credit card has expired or been replaced with a new number. In fact, nearly 30% of payment cards in the U.S. are reissued each year (due to expiration, loss, upgrades, etc.). If you’re billing a card that has changed, the charge will be declined unless the information is updated.

Chasing down each customer for new card details is tedious and often unsuccessful – many customers don’t notice or act on expiration reminders in time. This is where Account Updater services come in; they are a must-have for modern subscription billing.

Account updater services (offered by major card networks like Visa, Mastercard, Discover, and AMEX) automatically provide updated card information to merchants when a customer’s card number or expiration date changes. In simple terms, if a subscriber gets a new card, the updater service can supply the new card number/expiry to your billing system behind the scenes.

This ensures the next recurring charge processes seamlessly without requiring the customer to manually update their details. Implementing an account updater means expired or replaced cards no longer slip through the cracks.

The impact on churn can be substantial. Account updater tools significantly reduce payment declines caused by outdated card information, thereby reducing involuntary cancellations. According to industry data, these services automatically capture roughly 60-70% of card changes, significantly reducing failed transactions.

By preempting card-related failures, businesses can recover an estimated 2-10% of monthly revenue that would have been lost. In terms of churn, enabling account updater alone can reduce card-related failure churn by about 25-35%. Considering the minimal cost (usually a few cents per update), the ROI is extremely high – each updated card that prevents a failed payment is potentially saving you an entire customer’s subscription.

For these reasons, using an account updater service through your payment processor (many platforms, such as Stripe, Braintree, and Recurly, support it) is a best practice for recurring billing. It keeps your customers’ payment credentials up to date and takes the burden off you and the customer to resolve declines caused by outdated card information.

Implement Smart Retry Schedules for Failed Payments

Secure payment processing with Host Merchant Services for businesses.

Even with preventive measures, some payments will inevitably fail (e.g., a customer maxed out their card or had insufficient funds on the billing date). What happens next is critical. Many subscription businesses have a dunning process – essentially, an automated retry and notification schedule for failed payments. However, not all retry strategies are equal. To reduce churn, it’s important to use smart retry logic rather than a brute-force or ad-hoc approach.

First, recognize that not all payment declines are the same. Some are soft declines – temporary issues that might succeed if tried again later (for example, network timeouts or insufficient funds that could be resolved next payday). Others are hard declines – permanent failures that won’t succeed without the customer changing something (like a stolen card or closed account). A smart retry strategy accounts for these differences.

You don’t want to keep hammering a card if the error is unrecoverable, but you do want to persistently retry when there’s a good chance the payment will go through on a later attempt.

Timing is everything. If you retry a failed payment too soon (e.g., within minutes), you’ll likely get the same result. On the other hand, if you wait too long to retry, the customer might meanwhile notice the cancellation or even sign up with a competitor. The key is to find a balanced, data-driven retry schedule that maximizes success.

Rather than retrying at arbitrary intervals, use insights about why the payment failed and typical customer behavior. For example, if a transaction fails for “insufficient funds,” trying again in a day or two (or on the customer’s next payday) is often effective, since their balance may recover. An insufficient funds decline might justify 5-7 retry attempts spread over up to 30 days, especially timed around common pay cycles (e.g,. attempting charges on the 1st and 15th of the month).

On the other hand, a hard decline, such as “card reported stolen,” should not be retried repeatedly; instead, you should stop automatic attempts and ask the customer for a new payment method.

A common best practice is to stagger retries over several days or weeks, increasing the interval each time. For instance, you might configure retries roughly 1 day, 3 days, 7 days, and 14 days after the first failure (adjusting the pattern based on your business and the decline reason). Research has shown diminishing returns after about the 4th or 5th retry – beyond that, each additional attempt recovers very little and could even backfire.

Many companies cap their retry attempts to a reasonable number (e.g., 3-5 retries per invoice) to avoid excessive attempts that annoy banks or customers. Immediate retries can sometimes work for soft declines – for example, a momentary network glitch might succeed on a second try just seconds later – and some systems will do an instant retry once before waiting longer.

After that, it’s wise to schedule subsequent attempts at optimal times: for example, early morning (when banks begin daily processing cycles), on weekdays (when banking systems and customer support are fully active), and aligned with the customer’s known patterns (avoiding end-of-month if that’s when budgets are tight, and aligning with when they typically receive income).

Advanced billing systems or payment processors (such as Stripe’s Smart Retries or Recurly’s adaptive retry engine) use machine learning to select the optimal day/time to retry for each case, analyzing factors such as past payment behavior, decline codes, and issuer response patterns. These intelligent systems have been shown to lift recovery rates significantly – in some cases, recovering 2–4× more failed payments than a static schedule.

When implementing your retry (dunning) strategy, keep the customer experience and cost factors in mind. Every failed charge attempt incurs transaction fees and, if repeated, could trigger fraud warnings or chargebacks. The goal is to recover the payment quietly, without customer involvement, if possible, so you don’t disrupt their service. For example, many businesses will retry at least once or twice before notifying the customer to see whether the issue resolves (e.g., a soft decline clearing on a second attempt).

But if multiple attempts fail, it’s time to loop in the customer (as discussed in the next section). In summary, a smart retry schedule improves your chances of collecting revenue without alienating customers. By carefully timing retries and limiting their number, companies can avoid both unnecessary churn and the pitfalls of over-aggressive dunning (like angry customers or issuer flags).

Communicate Proactively and Kindly with Subscribers

Innovative payment solutions for business growth and customer engagement.

Recovering a failed payment isn’t just a technical process; it’s also a human one. In many cases, the customer is unaware that their payment didn’t go through – at least until they suddenly lose access to the service. In fact, most customers don’t realize a billing issue occurred until they’re confronted with a cancellation or an interruption notice. That’s why proactive customer communication is vital. A simple, well-timed message can save the customer relationship before it’s too late.

Preemptive reminders: One best practice is to reach out before a failure happens when you can anticipate an issue. For example, if you know a customer’s credit card is about to expire next month, send them a friendly reminder to update their card details in advance. This can be an automated email saying, “Heads up! The card we have on file for you ends in 07/2026.

Please update your payment info to ensure uninterrupted service.” Customers appreciate the notice, and this simple nudge often prompts them to resolve the issue in advance. Similarly, some companies send a reminder about an upcoming charge a few days before each billing cycle (especially for annual plans or large payments), serving as both a courtesy and an opportunity: if the customer knows a charge is coming, they can ensure funds are available or update the card if needed.

Pre-billing notifications sent ~7-14 days before the charge can preemptively resolve 5–10% of issues that would have led to a failed payment. That’s a significant chunk of churn prevented without any revenue loss, simply by being proactive.

Post-failure outreach: When a payment does fail, timing and tone of your communication are crucial. You should alert the customer immediately – the moment a payment is declined – but do so in a helpful, non-accusatory way. For instance, an email or SMS that says, “We couldn’t process your recent payment. Please update your billing information to keep your subscription active. [Click here to update your card]. We’re here to help if you have any questions,” strikes the right balance.

It informs the customer of the issue and provides a direct, one-click path to resolve it, without using threatening language. Always include a clear call to action, such as a button or link, to update the payment method. The easier you make it for them, the more likely they are to resolve the issue promptly.

It’s also wise to reassure them that their access isn’t immediately cut (if you offer a grace period, mention that, e.g., “We’ll keep your account active for the next 7 days to give you time to update your payment.”). Many subscription businesses offer a short grace period after a failed charge, during which the customer can continue using the service while the payment issue is resolved.

This prevents a negative user experience from sudden cancellations and improves the effectiveness of your dunning emails. During this window, you might send a series of follow-ups – for example, an initial failure notice, a reminder 2-3 days later if still unpaid, and a final notice before the account is suspended. Each message should maintain a polite tone and highlight the simple steps to resolve the issue.

In all communications, keep the tone friendly and supportive. The customer likely didn’t intend for the payment to fail, so frame the situation as something that can happen to anyone and that you’re there to help. Avoid language that sounds blaming or overly urgent (“PAY NOW OR ELSE”). Instead, phrases like “please update your card to avoid interruption” or “we noticed an issue with your payment method; please visit [link] to update it” work well.

Additionally, use multiple channels to increase the likelihood the customer sees the message: send an email, consider SMS if you have consent, and use in-app or push notifications if your product allows. People have different communication preferences, so a multi-channel approach can catch their attention sooner.

Lastly, if you have customer support or account reps, empower them to reach out personally for high-value customers or long-time users who experience payment failures. A quick personal call or tailored email saying “we value you and want to ensure you don’t lose access” can turn what could have been a cancellation into a saved account – and it shows the customer you care.

By communicating swiftly, helpfully, and often, you can resolve many payment issues before they lead to churn. In many cases, a customer’s response to a simple failed-payment email (“Oh, I got a new card and forgot to update it – thanks for letting me know!”) is all it takes to retain them.

Give Customers Flexibility and Control over Billing

Affordable merchant payment solutions for businesses | Host Merchant Services.

Another effective way to reduce payment-related churn is to give your customers greater control over their billing. The more flexibility and self-service options you provide, the fewer failures and frustrations will occur. Here are a few aspects of control and how they help:

  • Easy self-service for billing info:

Make it dead simple for customers to update their payment details at any time. If a subscriber receives a new card or wants to switch their payment method, they should be able to log in to their account (or follow a secure link in an email) and update the card on file in seconds. Remove friction from this process – no one should have to contact customer support or jump through hoops to update an expired card.

Best practices include providing one-click update links in your dunning emails that take users directly to a payment update form without requiring them to log in again. The form should be mobile-friendly, require minimal information (use existing data to pre-fill as much as possible), and be secure. Use zero-friction update links and enable features such as scanning the new card with a phone camera to auto-fill the details, making updates as effortless as possible. By streamlining the payment update workflow, you increase the likelihood that customers will proactively resolve issues.

Remember, if updating a card feels like a hassle, some customers won’t do it and will let the subscription lapse. So invest in a user-friendly billing management UI – it pays off in higher retention.

  • Let customers choose their billing date:

Not everyone’s personal cash flow aligns with your default billing cycle. Some subscribers might prefer their charges on a specific day (such as right after their paycheck clears) or avoid charges at the end of the month when budgets are tight. If possible, offer customers the option to select a convenient billing date (or at least provide a few date options). This flexibility can reduce the chance of declines due to insufficient funds. Research shows that when customers can choose their charge date, they can align payments to their income schedule, resulting in fewer failed transactions.

It’s a recognition that they know their finances better than you do. For instance, a customer paid on the 15th might opt to have their subscription renewed on the 16th, ensuring their account has funds. Many subscription platforms now support anniversary billing (charging every X weeks or months from the signup date) or allow moving a billing date on request. Even if you bill everyone on the same day, consider spreading out cohorts (not all on the 1st) or avoiding universally problematic dates like the 30th/31st. The key is flexibility – a little accommodation here can prevent significant involuntary churn.

  • Offer multiple payment methods (and backup methods):

Don’t put all your eggs in one payment-method basket. If you only accept one type of card, you’re more vulnerable to failures. It’s wise to support multiple payment options – all major credit/debit card brands, possibly direct debit (ACH) for those who prefer bank accounts, and digital wallets or services like PayPal, Apple Pay, etc., depending on what’s popular with your customer base.

This not only attracts more customers but also gives existing subscribers alternatives when one method isn’t working. More importantly, allow (and encourage) customers to add a backup payment method to their accounts. For example, a subscriber could have two cards on file, or a card plus a PayPal account. Set your billing system to automatically attempt the secondary payment method if the primary one fails.

This way, a decline doesn’t have to mean a lost customer – the charge can still go through via the backup method with zero intervention from the user. Each additional payment method on file increases your chances of successfully collecting payment, since if one fails, another might succeed.

This is especially useful for preventing involuntary churn: a customer might not update their primary card in time, but if you seamlessly charge their backup card, their subscription continues uninterrupted (and you can notify them that you did so). It’s a win-win: you get the revenue, and the customer doesn’t experience any service disruption.

In addition to the above, consider other customer-friendly billing policies that can reduce churn. For instance, grace periods (as mentioned earlier) and the option to pause a subscription for a short time can help customers who encounter a temporary snag. If someone’s finances are tight this month, allowing them to pause for a month rather than cancel outright can help prevent churn. While pausing is more of a voluntary churn tactic, it overlaps with billing flexibility – you’re giving the customer control to manage payments on their terms, which ultimately protects your recurring revenue.

Overall, by giving subscribers more control over how and when they pay, you remove many of the common friction points that lead to failed payments. An empowered customer who can easily update their card, select their billing date, or rely on a backup payment method is far less likely to churn involuntarily than one with no flexibility. These measures contribute to a smoother billing experience, leading to more successful charges and higher retention.

Conclusion

Involuntary churn from failed payments is a real challenge for subscription businesses, but it’s also highly preventable. To reduce churn in 2026, make recurring billing more resilient by using account updater services to refresh expired or replaced cards, and set up smart retry logic that recovers soft declines with well-timed, limited attempts. Pair that with proactive, friendly outreach, expiry reminders, and failed-payment notices that make it easy for customers to fix the issue, and give subscribers control through self-serve billing updates, flexible billing dates, and backup payment options.

Companies that adopt these best practices often see higher payment success rates, lower churn, and better customer satisfaction. Since retaining existing subscribers is far cheaper than acquiring new ones, every recovered payment protects both immediate revenue and long-term customer value. In 2026 and beyond, teams that master recurring billing and dunning will gain a clear advantage by building stronger lifetime value, more predictable revenue, and healthier growth, without losing customers who want to stay.

Frequently Asked Questions

What is involuntary churn in subscriptions?

Involuntary (or accidental) churn happens when a customer wants to stay but gets canceled because a recurring payment fails. It’s typically caused by card expiry, insufficient funds, or bank declines.

What are the most common reasons recurring payments fail?

The big ones are expired or replaced cards, insufficient funds, fraud filters triggering false declines, and temporary processing/network issues. Most of these are fixable with better billing workflows.

How does an account updater help reduce failed payments?

Account updater services automatically refresh stored card details when a customer’s card is reissued or expires. This prevents avoidable declines and keeps renewals running without customer action.

What’s a “smart” retry (dunning) strategy?

It means retrying failed payments based on decline type and timing, spacing attempts out and stopping early for hard declines. This improves recovery rates without annoying customers or triggering issuer flags.

How should businesses communicate when a payment fails?

Notify customers quickly, in a friendly tone, with a clear, one-click way to update their payment details. A short grace period, along with reminders via email/SMS/in-app, can prevent cancellations and frustration.

credit card surcharges

Credit Card Surcharges & Cash Discounts: A Merchant’s Guide to Fees in 2026

Tired of credit card fees eating into your margins? You’re not alone – and you have options. This guide breaks down everything merchants should know about surcharging credit card payments or offering cash discounts as of 2026.

We’ll clarify where surcharges are legal and the ground rules set by Visa/Mastercard if you do add a fee. Importantly, we’ll also explain the difference between adding a surcharge and giving a cash discount.

Credit Card Surcharges: Passing on Card Fees

A credit card surcharge is an extra fee a merchant adds to a customer’s bill when they pay by credit card. The purpose is to offset the merchant’s credit card processing fees. For example, if your processing fee on a $100 sale is about 3%, you might add a 3% surcharge so the customer pays $103, covering the $3 fee you’d otherwise absorb. Surcharging shifts the cost of accepting credit cards back to the customer. This practice became allowed in the U.S. after a 2013 court settlement, and by 2026, it is legal in the majority of states – but not everywhere.

In most U.S. states, it is legal for merchants to add a credit card surcharge, but a few states still ban the practice outright. Notably, Connecticut, Massachusetts, Maine, and Puerto Rico prohibit credit card surcharges, meaning you cannot add a surcharge in those states. (Cash discounts, discussed later, remain legal there.) A handful of other jurisdictions have recently tightened surcharge rules as well. For example, California is a high-risk state for add-on checkout fees due to its price transparency rules (SB 478) and prior surcharge restrictions. Many merchants avoid traditional surcharges and instead use dual-pricing or cash-discounting models to remain compliant with card network and state requirements.

Cash Discounts: Incentivizing Cash Payments

Credit Card Network Rules

A cash discount is essentially the mirror image of a surcharge. Here, instead of adding a fee on top of the price for credit card users, you give a discount or reduced price to customers who pay with cash (or check, debit card, or other non-credit methods). The outcome can be very similar – card-payers end up paying more than cash-payers – but legally and perceptually, cash discounting is treated differently. Cash discounts are legal in all 50 states and have been encouraged by laws and card network policies for decades.

Under a cash discount program, a merchant might mark all prices to account for the typical cost of credit card processing, then offer, say, a 3% discount at the register if the customer pays with cash (or an equivalent method that doesn’t incur heavy fees). So, if an item is listed at $100 (the price when paying by card), a customer paying cash might get 3% off and only pay $97.

Either way, the merchant receives roughly $97 net – the difference is whether that extra $3 goes to the processor as a fee (in a card transaction) or is forgiven as a discount to the cash-paying customer.

Why Choose a Cash Discount and How to Implement?

Cash Discounts

The big advantage is that cash discounts are explicitly allowed everywhere – even in states that ban surcharges, you are permitted to offer a discount for cash payments. There are also fewer bureaucratic hoops. You don’t have to register with card networks or worry about strict caps, since you’re simply giving a discount off the regular price. From a customer-relations perspective, a discount can feel like a reward (for using cash) rather than a penalty for using a card.

This positive framing can make cash discount programs more palatable to customers who might otherwise complain about fees.

  • Proper Implementation:

To run a cash discount program correctly (and avoid any perception that you’re just sneaking in a surcharge by another name), you need to advertise and handle your pricing appropriately. The key is transparency in pricing:

  • Post prices correctly:

One compliant approach is to post your prices as the credit card price, and then advertise a discount (e.g., “X% off”) for paying with cash. For instance, your menus, stickers, or price tags list the higher price (which covers card fees), and you subtract the discount at the point of sale for cash transactions.

Alternatively, you can list two prices for each item – a “cash price” and a “credit price”- side by side, so customers can see that paying with a card costs more. Either method is acceptable. What you should not do is advertise one (lower) price, then simply add a fee at checkout for credit cards without prior indication – that starts to look like an undisclosed surcharge and can violate truth-in-pricing regulations. Make sure the customer is aware of the price difference from the start.

  • Clear disclosure:

Just as with surcharges, it’s wise to post signage or notices informing customers that “We offer a X% discount for cash payments” or similar wording. This sets expectations. The receipt for a cash sale can show the discount as a line item (e.g., “Cash Discount -$3.00”) so the customer sees they saved money by paying cash.

For a card sale, since you’ve either listed the higher price or shown both prices upfront, the receipt will just show the full price (no extra fee line needed, because in theory the listed price was the card price). The overarching goal is that the customer doesn’t feel tricked – the pricing difference between cash and card should be transparent and presented as a discount, not as a last-minute fee.

  • No notification needed:

Unlike surcharges, you typically do not need to notify card networks when implementing true cash discounts. All the major card brands allow merchants to offer discounts for cash or other payment methods as long as it’s clearly a discount, not a surcharge.

There’s also no hard percentage cap on cash discounts (you’re free to set any discount amount), though most merchants will keep it in the same ballpark as typical card fees (e.g. 3-4%) to preserve their margins. Keep in mind that extremely large “cash discounts” could raise customer suspicion or regulatory interest if they start to look punitive; a reasonable discount that reflects avoided fees is the safest approach..

Surcharges vs. Cash Discounts: Key Differences

Affordable merchant services comparison for credit card processing and payment solutions.

It’s important to distinguish between surcharges and cash discounts, as the two strategies have different rules and implications. Below is a quick comparison of key differences:

FeatureCredit Card SurchargingCash Discounting
LegalityAllowed in most states; banned in a few (CT, MA, etc.)Legal in all 50 states (no state bans)
Card Network RulesStrict rules: capped by network + your actual cost (Visa 3%), acquirer notification required, and disclosure/receipt rules.Minimal network restrictions (no cap or notice required)
Applies ToCredit card transactions only (no surcharges on debit/prepaid)All payment types can receive a discount (cash, debit, check, etc.)
How It’s AppliedAdded as an extra fee on top of the price at checkoutGiven as a discount or price reduction off the listed price
Receipt DisplayShown as a separate fee line item on the receiptAll payment types are eligible for a discount (cash, debit, check, etc.).
Customer PerceptionOften viewed as a penalty or “extra charge” on the purchaseOften viewed positively as a “savings” for paying by cash
Compliance BurdenHigh – must comply with state laws + card rules (signage, fee caps, notifications)Low/Moderate – generally simpler, just ensure honest advertising of prices

Both approaches can achieve a similar result (offsetting the merchant’s processing fees), but they do so in opposite ways. Surcharging explicitly passes the cost to credit card users as an added fee, which requires navigating additional legal constraints and risks annoying customers who don’t like surprise fees.

Cash discounting adds the cost to prices and then offers a discount to incentivize other payment methods, which is legally permissible everywhere and often more acceptable to customers, though it requires a careful pricing strategy. However, it requires a careful pricing strategy.

Credit Card Network Surcharge Rules and Compliance Requirements (2026)

As of 2026, the major U.S. credit card networks have established specific rules that merchants must follow to apply credit card surcharges. These rules address surcharge limits, advance notification, disclosure standards, and enforcement.

NetworkMaximum Surcharge CapNotification RequirementKey Conditions
VisaUp to 3% (or the merchant’s actual cost, whichever is lower)Notify Visa and your merchant acquirer at least 30 days before startingSurcharge limited to credit cards only; cannot exceed merchant’s cost of acceptance.
MastercardUp to 4% (or the merchant’s actual cost, whichever is lower)Surcharge limited to credit cards only; must not exceed the actual cost of acceptance.Typically, notification to the acquirer is required
American ExpressNo fixed industry cap published; treat similarly to cost recoveryTypically notification to the acquirer is requiredSurcharge only on credit transactions and must comply with parity rules for similar card types.
DiscoverNotify the network and acquirer at least 30 days before startingNo specific published cap separate from the overall rulesSurcharge only on credit transactions and must follow network rules consistent with cost recovery.

General Compliance Requirements for All Networks

Credit Cards Only: Merchants may only add a surcharge to credit card transactions. Debit and prepaid card transactions cannot be surcharged under card network rules, even if a debit card is processed as “credit.”

Advance Notification: Merchants must notify their acquirer (payment processor or bank) at least 30 days before commencing surcharges. Some networks still recommend notifying the network directly, but acquirer notification is the standard method.

Disclosure and Signage: Merchants must post clear notices that a surcharge will be added. Notices must typically be displayed at the point of entry, at the point of sale, and in online checkouts.

Receipt Itemization: The surcharge must appear as a separate line item on all transaction receipts and be labeled appropriately.

Uniform Application: Surcharges must generally be applied uniformly across all credit card transactions under a given card brand; differential pricing by specific card products may be restricted.

State Laws Also Apply: In addition to network rules, merchants must comply with applicable state laws, which vary and can prohibit or limit surcharging.

Complete List: Credit Card Surcharge Legality by State (2026)

This list is for credit card surcharges only. Cash discounts are legal in all 50 states.

StateStatus (2026)Notes
AlabamaAllowedStandard card network rules apply.
AlaskaAllowedStandard card network rules apply.
ArizonaAllowedStandard card network rules apply.
ArkansasAllowedStandard card network rules apply.
CaliforniaRestricted/High-riskSB 478 requires upfront all-in pricing; add-on checkout surcharges are risky. Many merchants use dual pricing/cash discounting.
ColoradoAllowed with limitsAllowed but capped at 2% or merchant cost of acceptance.
ConnecticutProhibitedCredit card surcharges are illegal.
DelawareAllowedStandard card network rules apply.
FloridaAllowedState prohibition found unconstitutional; follow network rules.
GeorgiaAllowedStandard card network rules apply.
HawaiiAllowedStandard card network rules apply.
IdahoAllowedStandard card network rules apply.
IllinoisAllowedStandard card network rules apply.
IndianaAllowedStandard card network rules apply.
IowaAllowedStandard card network rules apply.
KansasAllowedStandard card network rules apply.
KentuckyAllowedStandard card network rules apply.
LouisianaAllowedStandard card network rules apply.
MaineProhibitedCredit card surcharges are illegal.
MarylandAllowedStandard card network rules apply.
MassachusettsProhibitedCredit card surcharges are illegal.
MichiganAllowedStandard card network rules apply.
MinnesotaAllowed with limitsAllowed but capped at 2% or the merchant cost of acceptance.
MississippiAllowedStandard card network rules apply.
MissouriAllowedStandard card network rules apply.
MontanaAllowedStandard card network rules apply.
NebraskaAllowedStandard card network rules apply.
NevadaAllowed with limitsAllowed but surcharge may not exceed processing cost; disclosures required.
New HampshireAllowedStandard card network rules apply.
New JerseyAllowed with limitsAllowed; surcharge must not exceed merchant processing cost.
New MexicoAllowedStandard card network rules apply.
New YorkAllowed with limitsMust display the highest total price (credit price) or dual pricing before checkout; surcharge cannot exceed actual processing cost.
North CarolinaAllowedStandard card network rules apply.
North DakotaAllowedStandard card network rules apply.
OhioAllowedStandard card network rules apply.
OklahomaAllowed with limitsBan repealed Nov. 1 2025; capped at 2% or merchant cost.
OregonAllowedStandard card network rules apply.
PennsylvaniaAllowedStandard card network rules apply.
Puerto RicoProhibitedCredit card surcharges are illegal.
Rhode IslandAllowedStandard card network rules apply.
South CarolinaAllowedStandard card network rules apply.
South DakotaAllowed with limitsAllowed; surcharge may not exceed processing cost.
TennesseeAllowedStandard card network rules apply.
TexasUnclear/disputedAllowed but often requires that the surcharge not exceed the processing cost.
UtahAllowedStandard card network rules apply.
VermontAllowedStandard card network rules apply.
VirginiaAllowedStandard card network rules apply.
WashingtonAllowedStandard card network rules apply.
West VirginiaAllowedStandard card network rules apply.
WisconsinAllowedStandard card network rules apply.
WyomingAllowedStandard card network rules apply.

Best Practices to Implement Fees Without Losing Customers

Whether you choose to implement a surcharge or a cash discount program, how you execute it makes all the difference. Here are some best practices to ensure you recover costs fairly and transparently:

1.    Check the Rules First

Always verify the current laws in your state (or any state where you operate) before starting. Surcharge regulations can change, and you don’t want to inadvertently break the law.

Likewise, review the card network requirements for surcharging (which are updated from time to time) to make sure you’re in compliance. If in doubt, consult with your payment processor or a legal advisor about surcharging in your jurisdiction.

2.    Keep Fees Reasonable

Do not charge more than your actual card processing cost. The aim is to offset fees, not turn a surcharge into a profit center. Charging a higher-than-necessary fee will not only violate card network rules (and possibly state law), but also will certainly irritate customers. Determine your average effective credit card processing rate and set your surcharge or cash discount percentage at or below that level (capped by your actual processing cost and the card network limits, 3% for Visa, and up to 4% for Mastercard).

If your fees average 2.5%, you might set a 2.5% surcharge – customers will find that easier to swallow than a full 3% in that case, and it stays within the rules.

3.    Be Transparent and Upfront

Surprises are the enemy of customer goodwill. Post signs prominently about your surcharge or cash discount policy so customers know before they reach the checkout. For brick-and-mortar stores, put a notice at the entrance and at the register. For e-commerce, display the notice on the payment page (before the final purchase confirmation).

The signage or notice should clearly explain the fee or discount and which payment methods it applies to. When customers understand why you’re implementing a fee (e.g., “credit card fees have increased, so we add a small charge for credit transactions”), they may be more accepting of it than if it seems hidden.

4.    Train Your Staff

Make sure employees know how to explain the surcharge or discount to customers and handle common questions or pushback. If a customer asks “Why am I being charged extra for using a card?”, staff should be ready to politely explain it’s to cover processing costs and that no fee is charged for cash or debit payments.

Well-informed staff can turn a potentially negative encounter into a positive one by highlighting the customer’s options (e.g. “You can save a few dollars by using debit or cash for this purchase, totally up to you!”). Consistency in how the policy is presented will avoid confusion.

5.    Monitor Customer Feedback

Pay attention to how your customers respond. Some businesses find that a small surcharge has little to no impact on sales, while others might get complaints. If you notice many customers walking away or commenting negatively about the fee, consider adjusting your approach.

You could try a lower surcharge percentage, offer a cash discount instead, or ensure your prices remain competitive even with the fee. It’s a balance – recovering some fees vs. possibly losing sales. Gauge what your market will tolerate.

6.    Reevaluate Periodically

Laws and card network rules can evolve (for instance, the surge in “junk fee” regulations aimed at greater price transparency). Stay updated on any changes in surcharge legality or requirements.

Also, re-check your processing rates annually – if you negotiate a lower rate with your processor, you might reduce your surcharge accordingly (since you only need to cover the actual cost). The goal is to keep your fee programs compliant and fair over time, not “set and forget.”

Conclusion

As of 2026, U.S. merchants can offset credit card processing costs either by adding a credit card surcharge or by offering a cash discount, but the two approaches are regulated very differently. Credit card surcharges are allowed in most states but are banned in a few, including Connecticut, Massachusetts, Maine, and Puerto Rico, and they must comply with strict card network rules such as advance notice, fee caps tied to actual processing costs, clear signage, and receipt disclosure.

Cash discounting, by contrast, is legal in all 50 states and does not require network registration, provided pricing is transparent, and the discount is clearly presented as a reduction from the posted price. Because of the lower compliance burden and more favorable customer perception, many merchants choose cash discounts or dual pricing instead of traditional surcharges, especially in high-risk states with strict price transparency requirements.

Frequently Asked Questions

  1. Can I charge customers extra for using a credit card?

    In most states, yes. Credit card surcharges are allowed if clearly disclosed and capped at your processing cost, typically around 3%. Debit card surcharges are not allowed.

  2. What rules do card networks require for surcharging?

    You must notify card networks in advance, cap the fee at 3% or less, post clear signage, and show the surcharge as a separate line item on receipts. Non-compliance can violate your merchant agreement.

  3. What’s the difference between a cash discount and a surcharge?

    A surcharge adds a fee to card payments, while a cash discount lowers the price for paying with cash. Cash discounts are legal everywhere and often preferred because they feel like a reward, not a penalty.

  4. How do customers usually react to credit card surcharges?

    Some accept small fees, while others dislike unexpected charges. Clear signs like “Save 3% by paying cash” and reasonable rates help reduce complaints.

  5. Should I add a surcharge or raise prices?

    Surcharges shift card fees to card users, while price increases spread the cost across all customers. The right choice depends on your market, customer expectations, and the level of competition in your pricing.u003cbru003e

Seamless merchant services integration for efficient financial management and payment processing.

Open Banking on Hold: CFPB Plans “Interim” Data-Sharing Rule Amid Funding Woes

The Consumer Financial Protection Bureau (CFPB) is poised to use an emergency interim final rule to carry out its new open banking framework, rather than completing the normal multi-step rulemaking process. It’s because the CFPB is under significant financial pressure and is caught in political disputes over how much funding it should receive. And for this reason, the agency has not been able to proceed with implementing Section 1033 of the Dodd-Frank Act, which addresses consumer access to financial data.

In this article, we explain why the CFPB is resorting to an “interim final” rule, how funding fights and dismantling attempts are stalling it, and what it means for banks, fintechs, and the timeline for open banking.

Background: Section 1033 and the Open Banking Rule

Flexible payment processing solutions for small businesses.

Section 1033 of the Dodd-Frank Act (2010) obligates financial institutions to make consumer financial data available to customers and their authorized third parties. In October 2024, under the prior CFPB leadership, the agency finalized a Personal Financial Data Rights rule to implement this data-rights mandate. That rule required banks with more than $850 million in assets to provide API access to account information (balances, transactions, payment schedules, etc.) on standardized, secure terms.

Under the published schedule, the largest banks would have to comply by April 2026, with smaller banks phased in through April 2030. The goal was to create an open banking ecosystem similar to Europe’s PSD2: consumers could authorize third-party apps to access data from their banks, fostering fintech innovation and competition.

However, the 2024 rule quickly became embroiled in controversy. Major banks and industry groups sued, arguing that the CFPB exceeded its authority and that the mandate was unduly burdensome. A federal judge in Kentucky delayed the rule’s effective dates and issued an injunction preventing enforcement until the litigation is resolved. In 2025, a new administration took over the CFPB, with different priorities. The bureau signaled it would reopen the rulemaking, seeking comments on narrowing who may access data, whether banks can recover costs through fees, and what security or privacy changes to require.

Why an Interim Final Rule?

Secure Merchant Payment Solutions from Host Merchant Services.

An interim final rule is an unusual “shortcut.” The agency issues a rule that takes effect immediately while still accepting comments, instead of waiting for the usual notice-and-comment period. The CFPB says it needs this emergency measure because its funding is exhausted. In legal filings, the bureau told a federal court it expects to “run out of money” by the end of 2025 and will not have funds to finish a regular rulemaking.

The bureau noted it currently has cash to operate through December 31, 2025, but beyond that, the White House has refused to replenish its budget. Under federal law, the CFPB draws funding from Federal Reserve earnings. But an October 2025 Department of Justice opinion found that no Fed balances are available to transfer to the bureau. After this yea,r the CFPB will effectively have no funds until Congress acts.

The agency’s acting director, Russell Vought, who also heads the Office of Management and Budget, has publicly signaled he intends to “close down” much of the CFPB and downsize it dramatically. Faced with this cash crunch, the CFPB has told courts it will skip some steps and swiftly finalize an open banking rule.

Funding Battles and the Fight to Dismantle the CFPB

The need for an interim rule is rooted in a bitter funding and political fight over the CFPB itself. Since early 2023, Republican lawmakers and the new administration have sought to curtail the bureau’s budget and authority. In Congress, House Republicans have voted to slash CFPB funding, proposing to cut the agency’s cap on Fed earnings from 12% to just 5%. This would remove roughly $250 million in resources (about 70% of its budget) and return it to a pre-2011 level.

Republicans even introduced a “Defund the CFPB Act” to cap its funding at zero. The stated goal is fiscal restraint, but critics say it amounts to a legislative effort to starve the bureau of funds altogether.

These moves follow a federal court’s ruling blocking the Trump administration’s attempt to eliminate CFPB staff through layoffs. Since that order, the administration’s strategy has shifted to using budget legislation to disable the agency. At the same time, President Trump and other conservative officials have said outright that the CFPB should be dismantled as an unelected regulator.

Acting CFPB Director Vought, a former aide to Trump, has repeatedly assailed the agency’s mission and slashed its operations. He reportedly told bureau employees that almost no one will be working there, aside from Republican appointees, as it winds down.

Because the CFPB was created by Congress, dismantling it fully would require legislative action. In the interim, Congress’s decision not to appropriate new funds has effectively paused the bureau’s work. Nonprofit groups and unionized CFPB staff have sued to force Congress to restore funding, but so far those efforts have not succeeded. The result is that the CFPB is operating on a shoestring.

Congress’s recent proposals would leave the bureau with only 30% of its previous budget to fulfill all statutorily required tasks. This funding squeeze directly underlies the CFPB’s claim that it must issue an interim final rule under Section 1033.

What Would an Interim Open Banking Rule Require?

Flexible payment solutions for businesses at Host Merchant Services.

Because the CFPB is still collecting input for a new full rule, the interim rule is likely to focus on near-term mechanics rather than substantive changes. It could temporarily extend compliance deadlines and preserve existing data-sharing obligations, while the agency works out details through a revised rulemaking process. It could also be used to delay the original April 2026 start date for big banks.

In fact, the courts have already pushed the compliance dates out by 90 days, and the CFPB is considering further extensions. If an interim rule delays those deadlines (e.g., by one year), covered banks would have more time to build or adapt their data APIs, and fintech firms could adjust their rollout plans accordingly.

Banks should continue their preparations for eventual compliance. Even if the first enforcement date is pushed back, large banks still need to develop secure data-portability interfaces and adopt any required standards. Many large banks (such as Bank of America, Citibank, and U.S. Bank) already have open API systems in place, but smaller institutions will need additional lead time. Fintech companies, for their part, should maintain readiness to receive data through these new channels and keep their user-consent systems up to date.

One crucial question is whether the interim rule will change the substance of data sharing in the short term. The Biden-era rule banned banks from charging customers for sharing their data. Under the interim rule, the CFPB might allow at least a temporary continuation of fee-free access.

The agency is separately considering, in its advance notice, whether banks should be allowed to recoup costs through “reasonable” fees, a debate sparked by recent bank announcements that they plan to charge fintechs for data access. For now, absent a new final rule, the existing prohibition on fees may effectively remain in place.

Similarly, the 2024 rule broadly defined who counts as an authorized “representative” for a consumer (including non-fiduciary fintechs). The new CFPB leadership is reconsidering whether to narrow it to fiduciaries only. An interim rule likely won’t resolve that question immediately; that will come in a later final rule.

But fintechs should be aware that who can request data on a user’s behalf may change. Banks and other data holders will continue to process any legitimate requests they currently receive under 1033, but an interim rule may hold the line rather than expand the regime.

What Can We Expect in the Near Term

  • Deadlines may shift: The interim rule could extend the compliance deadlines for banks. In that case, the compliance schedule (originally set for April 2026 for the largest banks) will be pushed out, perhaps to 2027. Both banks and fintechs should plan for a later start to full-scale data sharing.
  • Continue readiness: Institutions subject to Section 1033 should continue to build out APIs, security, and consent tools. Even if enforcement is delayed, the technical and operational work of open banking goes on. Developing standardized data formats (e.g,. FDX or similar) and rigorous security controls now will ease the eventual rollout. Fintech developers should stay engaged with the rulemaking process and ensure their systems can handle data from all major banks.
  • Monitor fee and privacy rules: The CFPB is soliciting input on whether to allow cost-based fees and how to tighten privacy controls. If the final rule permits banks to recover costs via fees, fintech apps may face new charges for data access. Industry groups are sharply divided: banks argue fees are needed to cover expenses, while consumer advocates warn they would become a “toll on consumers.” Whatever happens, banks should be ready to comply with any fee regimen, and fintechs may need to adjust their pricing models if data access is no longer free.
  • Data security remains critical: The CFPB’s advance notice also questioned existing security standards. Banks and fintechs must continue to adhere to robust security standards (e.g., by discouraging screen scraping and complying with GLBA safeguards). In the interim, both sides should use this extra time to strengthen protections and mitigate privacy risks.
  • Legal limbo persists: Until the CFPB issues a final rule after comment, the precise obligations remain unsettled. Both banks and fintechs should monitor litigation and agency updates, as the court could impose additional stays or the bureau could further extend deadlines through the interim rule.

Shifting the Timeline for Open Banking

Flexible payment processing solutions for businesses - Host Merchant Services.

With the interim rule delaying the process, the overall timeline for Section 1033 implementation will slip. The initially published schedule (large banks by April 2026, smaller banks by 2030) was based on the 2024 rule. In mid-2025, the CFPB had already paused those dates by 90 days while it reopened the rulemaking. Now, the bureau is openly asking whether that timeframe remains feasible if it revises the rule.

It seems likely that the first compliance deadlines will be pushed out by at least a year. If reopening the rule took nine months previously, a new full rule after ANPR (August 2025) could realistically emerge in early 2026 or later. Large banks might then be given until sometime in 2027 to enable open banking APIs.

In any event, the staggered schedule (with full implementation by around 2030) will probably be preserved, but shifted later. Even if delayed, the “open banking” framework will still be phased in by the early 2030s.

Not everyone views the delay as purely negative. Fintech advocates argue that pushing out deadlines avoids rushed rollouts and gives stakeholders more time to prepare robust systems. The Financial Technology Association, which intervened to defend the 2024 rule in court, told the judge that “delays in full implementation of Section 1033 harm the public interest” and urged the CFPB to let the rulemaking proceed on its own timeline.

In other words, if open banking is ultimately good for competition and consumers, then ensuring the rule is well-crafted and implementable may justify the extra wait.

The first meaningful compliance dates (for the largest banks) will no longer arrive in 2026 as initially planned. CFPB officials have acknowledged they will likely not issue the final rule until 2026 at the earliest, pushing significant data-sharing obligations into 2027 or later.

Looking Ahead

In its filings, the CFPB has affirmed that it ultimately intends to finalize the open banking rule. A spokesperson told reporters that the Section 1033 framework “will absolutely be finalized,” even if the process is being accelerated and truncated in parts. This means that once the funding impasse is resolved (or workarounds are implemented), the bureau still expects to implement a permanent rule to ensure consumer financial data rights.

For now, however, open banking progress depends on the outcome of political and legal battles. If the funding freeze persists, the interim rule may serve as a stopgap for months to come. Banks should focus on system readiness and compliance planning. At the same time, fintech companies should engage with regulators and be prepared for both favorable and adverse policy changes (e.g., changes to allowable fees or access restrictions). Consumers hoping to use future apps for budgeting or account aggregation will have to remain patient until this regulatory saga concludes.

Conclusion

The CFPB’s move to an interim final rule is a direct consequence of its funding crisis and the broader campaign to curtail the bureau. It pauses the aggressive timeline for data-sharing but does not cancel Congress’s directive on open banking.

Ultimately, Section 1033 remains viable, but its implementation will depend on both the shifting political winds and the following chapters of CFPB rulemaking.

Frequently Asked Questions

  1. What is an “interim final” rule in open banking?

    An interim final rule takes effect quickly without the whole public comment process. The CFPB plans to use this approach to expedite the adoption of open banking rules, with the option to revise them later.

  2. Why is the CFPB low on funding, and how does that affect open banking rules?

    Funding disputes and legal challenges have limited the CFPB’s resources. As a result, the agency cannot complete the normal rulemaking process and is using an interim rule to avoid missing key deadlines.

  3. What was the original open banking rule meant to do?

    The original rule aimed to give consumers control over their financial data. It would require banks to securely share account data with approved third parties upon customer consent.

  4. How might an interim rule differ from the original open banking rule?

    The interim rule is likely narrower and more temporary. It may set basic data-sharing requirements first, while delaying more complex provisions until funding and legal issues are resolved.

  5. What does this mean for consumers and fintech companies?

    Consumers may start gaining easier access to their financial data once the interim rule takes effect, likely in 2026. Fintechs and banks will get more explicit guidance, but should expect changes as the rules evolve.u003cbru003e

Stripe payment processing robot representing Host Merchant Services.

Stripe’s “Agentic Commerce” Suite Ushers in the AI Shopping Revolution

Stripe has just launched a new Agentic Commerce Suite to help merchants sell directly to AI-driven shopping agents. In the era of agentic commerce, autonomous AI assistants can handle product discovery and purchases on users’ behalf. To make it easy for businesses to sell to AI agents, Stripe agentic commerce suite is a one-stop solution that makes your products discoverable, simplifies checkout, and enables agentic payments through a single integration.

Major brands and platforms are already on board: Stripe names retailers such as Kate Spade, Coach, URBN, and Ashley Furniture, and e-commerce platforms such as Squarespace, Wix, Etsy, WooCommerce, commercetools, and BigCommerce among the first adopters.

What Is Agentic Commerce?

AI customer support chatbot for Host Merchant Services simplifies payment solutions.

At its core, agentic commerce means letting AI agents act autonomously on shoppers’ behalf. Instead of passive recommendations, AI assistants proactively find, compare, and even buy products for the user. Agentic commerce is AI that acts on behalf of users or businesses to manage tasks such as personalized recommendations and order placement. This involves granting AI assistants access to your product catalog and checkout to complete purchases.

Stripe and OpenAI have taken a leading role here: they co-developed an open standard, the Agentic Commerce Protocol (ACP), to enable this direct interaction. ACP provides a standard set of APIs for product feeds, checkouts, and delegated payments, enabling any AI platform (such as a chatbot or voice assistant) to interface with any merchant’s systems.

It is open-source (Apache 2.0) and “easy to adopt,” integrating with existing payment processors and back-end systems while ensuring merchants retain all their usual controls. Merchants remain the “merchant of record”: the seller still owns the customer relationship, handles fulfillment, and has access to all order details. All told, the ACP enables ChatGPT and other AI tools to serve as virtual shopping assistants: Stripe powers ChatGPT’s new “Instant Checkout” feature on Etsy and Shopify via ACP, enabling in-chat purchases.

Stripe Agentic Commerce Suite Features

AI chatbot assisting with Host Merchant Services payment solutions.

Stripe’s Agentic Commerce Suite bundles several components to connect a merchant with AI shopping channels through a single integration. Key features include:

  • AI-Ready Product Feeds:

Merchants receive a hosted ACP product endpoint to upload or link their catalog. Stripe then syndicates product data (title, price, availability, etc.) to multiple AI agents simultaneously. In other words, your inventory becomes AI-discoverable across all participating platforms without building a custom feed for each one.

Stripe handles the connectors – with one click, you can automatically start taking payments across any supported agent. Behind the scenes, this uses the Agentic Commerce Protocol’s Product Feed spec to ensure everything stays in near-real-time sync.

  • Streamlined Checkout Integration:

The Suite uses Stripe’s Checkout Sessions API to handle agentic checkouts. Once a customer (or an AI agent) selects items, Stripe automatically calculates taxes and shipping and validates the order. Merchants can choose to let Stripe calculate these (via Stripe Tax and other built‑in products) or integrate their own tax/shipping logic with minimal coding.

After checkout, the order is handed back to the merchant’s existing system for fulfillment. Crucially, the merchant remains in control: they retain merchant-of-record status, handle payments, and manage post-order steps such as refunds and disputes using their usual processes.

  • Shared Payment Tokens (SPTs) & Fraud Protection:

A novel part of the suite is the Shared Payment Token, a secure proxy for the buyer’s payment method. When a customer authorizes an AI agent to purchase on their behalf, the agent does not receive the customer’s raw card or account information. Instead, Stripe generates a token scoped to that one purchase, merchant, time window, and amount.

The AI agent uses this SPT to initiate the charge, without exposing the buyer’s credentials. This limits abuse: tokens are single-purpose and observable, reducing the risk of unauthorized charges or disputes. Plus, Stripe’s Radar fraud system analyzes these payments for AI-specific risk signals. In effect, Stripe relays the underlying risk signals – including stolen card or bot patterns – to help differentiate between high-intent agents and malicious bots.

  • Modularity & Existing Systems:

Every component of the suite is optional and pluggable. A merchant can adopt just the product feed or the complete checkout and payment stack, depending on their needs. Importantly, the integration sits on top of the merchant’s current e-commerce platform and order system, so there’s no need to rebuild everything from scratch.

You connect your product catalog to Stripe, then select which AI agents to sell through. All the agent interactions (catalog queries, carts, charges) funnel through Stripe’s APIs, which then hand off orders to the merchant’s back-end. This lets businesses expand into AI-driven channels while keeping their existing shopping cart, inventory, and fulfillment logic intact.

Early Adopters and Partners

Leading retailers and platforms are already testing the waters. Stripe explicitly lists Coach, Kate Spade, URBN (Anthropologie/Free People/Urban Outfitters), Ashley Furniture, Revolve, Abt Electronics, Halara, Nectar, and others as early users of the Suite. Several e-commerce platforms have built integrations on day one: for example, Etsy, Wix Payments, and Squarespace all confirm they can now surface merchants’ items to AI agents via Stripe.

Commerce parent (BigCommerce) and enterprise platforms like commercetools have similar announcements. Merchants (brands like Perry Ellis and Cole Haan) will gain seamless access to AI-driven discovery, checkout, and payments through a single Stripe integration. What once took months of bespoke engineering is now possible with a single, configurable integration – enabling merchants to unlock AI-driven discovery and checkout flows without reworking their systems.

Opportunities for E-Commerce

Proponents say agentic commerce could open up powerful new revenue streams. Many consumers already use AI tools to research what to buy, and surveys suggest a meaningful share of U.S. adults used AI for shopping in 2025. The idea is that autonomous “shopping agents” are beginning to handle parts of the journey, such as comparing options, selecting items, and completing transactions.

The upside could be huge at a global scale. Some projections suggest AI agents could lift e-commerce conversion rates by roughly 1.5-2.5 percentage points, translating into hundreds of billions of dollars in additional sales worldwide. Other forecasts estimate U.S. “agentic” spending alone could reach hundreds of billions by 2030.

In practical terms, this would give merchants of all sizes a new sales channel: AI shopping assistants. Solutions in this space are being built to scale to millions of users across AI products. Early feedback has been encouraging, with some reporting that a large share of small and mid-size businesses have already seen AI agents complete purchases on behalf of customers.

Consumers are warming up to the idea as well. Research indicates that nearly half of shoppers would consider using an AI agent for routine purchases, with willingness notably higher among people aged 25-44. That points to real demand for low-effort, automated shopping experiences. Industry experts argue AI could make shopping feel more personalized and intuitive, improving efficiency and reducing the need for endless searching.

Early adopters are betting this translates into higher conversion and larger basket sizes. By making product catalogs accessible to assistants such as ChatGPT, Alexa, and others, merchants can capture purchases that would otherwise be lost. Shared product feeds and streamlined checkout could enable customers to buy directly within a chat or voice conversation, instead of navigating to a website and completing a manual checkout. Overall, many observers believe that agentic commerce is moving beyond hype toward a tangible sales channel that could meaningfully reshape online shopping.

Security and Trust Challenges

However, there are real perils and concerns to address. Many businesses and consumers remain wary of letting an AI “click buy” without supervision. The core tension is evident: companies want AI-driven growth, but with safeguards in place. Some enterprise leaders have been blunt: they want to participate early without rebuilding core systems, which makes it essential that security and control measures are built in from the start. Others emphasize that this innovation must be simplified, secure, and scalable, or merchants won’t adopt it with confidence.

Concrete worries are easy to understand. A significant share of businesses say they would be concerned if AI agents started buying on behalf of consumers. The central reservations tend to cluster around security (protecting payment credentials and sensitive data), fraud prevention, and dispute resolution.

Without the right tools, the idea of “robot” shopping can feel risky. Malicious bots could exploit loopholes, automate card testing, or generate high-volume, hard-to-resolve transactions. Consumers share that hesitation: only a small minority report having allowed an AI assistant to complete a purchase, and an even smaller fraction says they’re interested in doing so. Many people still prefer the control and visibility of completing checkout themselves.

To reduce these risks, payment platforms are building guardrails designed specifically for agent-driven purchases. One approach is tokenization, which prevents agents from ever seeing raw card details and tightly constrains a payment to a specific, intended transaction. Another is enhanced fraud screening that looks for patterns common to automated or agentic behavior. Systems can also be designed to keep merchants in the loop – such as requiring order approval steps or adding verification points – so purchases don’t become fully automated “blind buys.”

Even with these protections, trust will likely take time to build. Familiarity tends to reduce anxiety: people and businesses get more comfortable once safeguards prove themselves in real-world use. For now, the most realistic stance is cautious optimism – embrace AI as a promising new channel, but pair it with strong transactional security, fraud defenses, and transparent processes for disputes and accountability.

Conclusion

Stripe’s Agentic Commerce Suite is a clear sign that AI shopping agents are moving from concept to reality. By co-developing an open standard with an AI partner and offering a turnkey integration, Stripe is lowering the barrier for merchants to reach customers through AI assistants. Early trials across well-known retailers and major commerce platforms suggest that both large brands and smaller sellers are eager to experiment.

If AI agents can deliver truly frictionless shopping – discovering products, answering questions, and completing checkout inside a conversation – merchants that adapt early could gain a meaningful edge. But adoption will hinge on trust. Strong security controls, transparent user consent, and apparent dispute and returns processes will be essential to making merchants and consumers comfortable with AI-assisted purchasing.

For now, Stripe is positioning the Suite as a measured step forward: enabling AI-driven transactions while emphasizing safety and reliability. The near term will test whether agentic commerce can meet expectations quickly, or whether both shoppers and businesses will need more time – and more proven safeguards – before they embrace it at scale.

Frequently Asked Questions

  1. What does “agentic commerce” mean?

    Agentic commerce is shopping conducted by AI assistants rather than people. An AI agent can search for products, decide what to buy, and complete the purchase on a customer’s behalf.

  2. What is included in Stripe’s Agentic Commerce Suite?

    Stripe’s suite helps businesses sell to AI agents by making product data easy to find and checkout simple. It also uses secure payment tokens, enabling AI to complete purchases safely.

  3. Which companies are using Stripe’s agentic commerce tools?

    Early adopters include brands such as Coach and Ashley Furniture, as well as platforms including Etsy, Wix, WooCommerce, and BigCommerce. These companies are preparing their stores for AI-driven purchases.

  4. Why is agentic commerce important for the future of shopping?

    It shifts shopping tasks from humans to AI, saving time and opening new sales channels for merchants. This model grows quickly, though it changes how orders and payments are handled.

  5. What risks and challenges come with agentic commerce?

    Security, fraud, and trust are significant concerns. Businesses must plan for mistakes, disputes, and system readiness, while balancing innovation with strong safeguards.

Contactless payment terminal for Host Merchant Services.

Restaurants Embrace Cash Discounts as Card Fees Squeeze Margins

As restaurants struggle with inflation and thin margins, payment processing costs have become a significant concern. In the U.S., credit card processing is now the third-largest operating expense for a typical restaurant, behind only food and labor costs. These “card swipe fees,” which are roughly 2-4% of each credit card sale, have risen sharply in recent years. Industry data show U.S. merchants paid about $187.2 billion in interchange and processing fees in 2024, roughly 70% higher than before the pandemic.

For a small restaurant, this can amount to tens of thousands of dollars a year, eroding already razor-thin margins. With menu-price inflation already squeezing customers, many operators are wary of simply raising prices again. Instead, a growing number are quietly passing some card costs back to customers through dual pricing, offering a small discount for cash or applying a modest surcharge on credit cards, to shore up profits without a blanket price hike.

Rising Card Swipe Fees and Pressure on Margins

Cash discount store illustration with POS terminal, storefront, and shopping concept.

Over the past decade, the U.S. payments landscape has tilted further toward cards. Nearly 70% of restaurant transactions are now non-cash, and networks like Visa and Mastercard capture a slice of each credit sale. While consumers enjoy rewards and convenience, restaurants literally pay for the privilege. For every $100 on a bill, a typical U.S. restaurant might keep only about $97.50 after interchange and gateway fees are paid to banks and processors.

Those deductions add up fast. In 2024 alone, U.S. credit and debit card swipe fees totaled a record $187.2 billion. This was about $1,200 for the average family, and the cost has jumped roughly 70% since 2019.

This spike has turned card fees into a crisis for restaurants. Until recently, small restaurants could absorb credit card charges without drawing attention. But rising food and labor costs mean margins are thinner than ever. Credit card processing has become the third-highest expense for a typical restaurant, behind only food and payroll. For a local bistro, paying even 2-3% on $1 million in annual sales can eat up $20,000-$30,000 from the bottom line – more than the profit on many months of business. Faced with this pressure, operators report they can no longer ignore the cost.

At the same time, restaurants have few tools to push back. Unlike large chains, most independents can’t negotiate drastically lower rates with Visa/Mastercard. They can’t refuse cards (it’s against card brand rules), and lowering menu prices to offset fees only digs a hole for survival, not sustainability. With public and regulatory attention on the cost of living, any significant menu price increase risks customer backlash.

Dual Pricing, Cash Discounts, and Surcharges

Cash Discounts

Dual pricing means posting two prices for the same item: a slightly lower price for cash payments and a higher price for credit/debit card payments. Under this model, paying with cash effectively earns a slight “discount” (e.g., 2-3%) off the menu price. The same effect can be achieved by adding a surcharge when a card is used, though terminology and legal nuances differ. These programs are identical; card users pay a bit more, cash users pay a bit less. The economics are straightforward: the extra cents on card payments cover the processing fee, while cash patrons receive a discount.

This strategy is common in some industries (e.g., fuel stations have long listed separate cash and credit fuel prices). Now, more restaurants are experimenting.

Customers rarely notice and don’t care; nearly everyone pays by card anyway. Even after adding the surcharge, the tab for a dinner order remained competitive with nearby restaurants. A higher price for a card payment is a ‘normal’ trend, and many other local eateries do it. By openly displaying both prices, customers see precisely what they save by paying cash.

Other tech-forward examples have emerged. In 2024, the popular restaurant POS provider Toast quietly began offering a surcharge feature to its 120,000 clients. Toast has just raised its processing rates for some merchants (for the first time in 12 years) and now allows restaurateurs to add a compliant surcharge at checkout if they choose. If a diner on a $50 bill sees a 3% fee, the restaurant nets an extra $1.50 (about the same as the processing cut).

Toast believes this helps protect restaurants’ bottom lines without carving an obvious fee into the price list. Other POS systems, such as Square, Shift4, and Clover, also offer “cash discount” or “dual pricing” options.

The idea is gaining traction. Surcharging and cash-discount programs are still emerging, not yet ubiquitous. A 2024 NRA survey found that only about 16% of operators had any surcharge or cash discount in place. (This low figure includes extra fees for large parties or delivery; true payment surcharges were even rarer then.) However, real-time data suggest rapid growth: a December 2025 merchant study reported roughly one-third of businesses (across sectors) were now adding card surcharges, up from under 5% in 2021.

In restaurants, anecdotal evidence from Texas to New York shows local eateries quietly adopting cash specials or “service charges” labeled as a fee to cover card processing costs. All told, the trend reflects a shift toward greater price transparency: instead of mixing fees into menu prices, restaurants are signaling the actual cost of credit in real time.

Implementing Cash Discounts – Practical and Legal Considerations

Implementing cash discounts

Implementing cash discounts or surcharges isn’t just a business decision – it involves careful compliance. Payment networks and state laws set strict rules. At the federal level, merchants may apply a surcharge on credit card transactions (subject to network rules), but most states ban such fees outright or cap them at around 4%. As of late 2025, only a handful of U.S. states (Connecticut, Maine, Massachusetts, and Puerto Rico) prohibit surcharges on card payments. Other states (like New York and California) allow surcharges only if they are clearly disclosed and do not exceed the actual fee charged.

For example, New York law forbids separately listing a surcharge line on a check, effectively requiring merchants to call it a “discount for cash.” Importantly, network rules insist that debit card payments cannot be surcharged – only credit cards are fair game.

For these reasons, most restaurants frame the adjustment as a cash discount rather than an add-on fee. They post one price (the higher “card price”) on menus and signage, then deduct a few percent at checkout when cash is used. This “two-tier pricing” approach skirts legal issues in restrictive jurisdictions and is fully sanctioned by Visa and Mastercard, provided the discount is clearly advertised.

Regardless of method, successful rollout hinges on transparency. Restaurants should prominently disclose dual pricing on menus, websites, signs at the register, and printed receipts. Some owners report telling new customers in a one-sentence script (“we can do 2% off for cash”) to avoid confusion. Customers are generally placated if they understand the reason and see their savings; surprise or misleading fees, by contrast, can spark negative reviews or even regulatory scrutiny.

Operationally, the shift usually requires minimal effort. Modern POS systems typically include built-in features to apply cash discounts or surcharges and handle bookkeeping to split sales figures. Restaurants planning this change are advised to consult their payment processor and local attorney: ensure the chosen method (cash discount vs. surcharge) is permitted in their state, set the correct percentage to avoid exceeding actual costs, and train staff to explain it to guests. When done right, many merchants find the process smooth – staff say customers usually appreciate the discount option, and don’t often remark on it after the first visit.

Impact on Diners and Market Dynamics

How are customers responding? Early evidence is mixed. Some diners grumble that new “fees” feel like junk charges, while others are indifferent. In some cases, guests still paid by card and barely noticed the change. In fact, many customers expect merchants to quote a cash price: gas stations have trained Americans to think of the card price as the “regular” price, with a built-in card fee. A rising share of merchants (34%) now impose surcharges on card purchases. This means card-carrying diners will increasingly encounter small upcharges on their bills.

For a frequent restaurant-goer, the effects can be tangible. A typical 2.5% surcharge can easily wipe out a 2% credit card rewards rate, effectively turning a modest purchase into a net loss for the cardholder.

On the other hand, savvy consumers can adapt. A few patrons may opt to pay in cash upon seeing the discount. Local credit unions and associations have even mounted “cash is king” campaigns, highlighting that a $0.50 coffee surcharge, for instance, could add up over time – and suggesting cash as a way to support local businesses.

In most cases, however, the convenience of plastic reigns. The NRA reported that Americans have grown accustomed to “cashless” dining (even though some data show credit cards used slightly less than debit at restaurants, over 60% of spending is non-cash). If anything, the new pricing may encourage a few more diners to keep a $20 bill handy, but it is unlikely to reverse the overall trend toward electronic payments.

From a market standpoint, the rise of cash discounts is already influencing competition. Restaurants that impose surcharges may be at a disadvantage if nearby competitors do not (or if those competitors quietly absorb the cost through slightly higher menu prices). However, the amounts are relatively small, like a 3% surcharge on a $100 tab is $3, which many diners accept as the “cost of doing business” for card convenience.

Some franchise chains have held back on surcharges to avoid customer backlash, while independents and locals (who cannot easily raise prices further) seem more willing to experiment. Notably, some diners and watchdogs classify surcharges as “junk fees,” a term now under regulatory scrutiny. Federal agencies (and some states) are cracking down on undisclosed add-on fees across industries. As a result, any restaurant that adopts dual pricing must ensure the charge is advertised transparently and labeled appropriately, or risk violating consumer protection rules.

Looking Ahead: Policy and Industry Trends

The scramble over swipe fees isn’t happening in a vacuum. Restaurant groups and merchant coalitions are lobbying for broader fixes. The National Restaurant Association, for example, actively supports the Credit Card Competition Act (CCCA), proposed legislation to introduce more networks and transparency into the card system.

NRA research suggests that enforcing competition could save merchants and consumers more than $16 billion per year. Likewise, the Independent Restaurant Coalition and food industry associations regularly urge Congress to cap or reduce interchange fees, arguing that smaller independents suffer disproportionately under the current Visa/Mastercard duopoly. Efforts like these have had mixed progress: the CCCA has stalled repeatedly, and even regulatory tweaks (like cap on debit fees under the Durbin Amendment) offer only limited relief.

In the meantime, many restaurants are taking matters into their own hands. Dual pricing is one tactic among several in a broader cost-saving toolbox. Alongside surcharges and cash discounts, operators are trimming operating hours, re-engineering menus (dropping unprofitable dishes), and using loyalty programs and off-peak promotions to boost revenue.

Some chains are even encouraging customers to use cheaper payment methods. For instance, a few upscale chains remind diners that cash and debit cards cost less (though they cannot legally refuse plastic). Ultimately, the billing strategy a restaurant chooses will depend on its clientele and local regulations.

What does this mean for consumers? Diners should be aware that two prices may appear. If a menu notes a “cash price” or if the receipt shows separate totals, that is the restaurant’s way of passing along processing costs. Paying cash will save the stated percentage, while using a credit card will trigger the higher price.

Financially savvy customers can adapt by calculating their net rewards: if your credit card bonus is 1-2%, a 3% surcharge might negate any gain. In the long term, if legislation forces lower interchange fees, these surcharges could disappear. For now, however, restaurants see them as a necessary counterbalance to protect staff, service, and food quality amid overwhelming costs.

Conclusion

Mounting card fees have pushed U.S. restaurants to explore pricing models long used elsewhere: offering discounts for cash or surcharging card users. The trend is driven by economics: as credit card networks capture an ever-larger share of each dining dollar, independent restaurants have little margin left to absorb those costs.

If current patterns persist, customers may start to view cash not as archaic, but as financially savvy – at least at the local cafe. Meanwhile, the industry and lawmakers will continue to debate whether to rebalance the system through regulation. For restaurants and diners alike, the message is clear: be alert for new price signals at the table.

Frequently Asked Questions

  1. What are credit card surcharges and cash discounts in restaurants?

    A surcharge adds a small fee when customers pay by credit card to cover processing costs. A cash discount lowers the price for customers who pay with cash. Both help restaurants reduce card fees.

  2. Why are more restaurants adding these fees now?

    Rising costs from inflation and higher card processing fees have squeezed profit margins. Adding surcharges or cash discounts helps restaurants recover these costs without raising menu prices.

  3. Is it legal for restaurants to charge extra for credit card payments?

    It depends on state law. Many states allow surcharges or cash discounts when clearly disclosed, but some ban them. Debit card surcharges are not allowed.

  4. How do customers usually react to dual pricing?

    Most customers accept minor differences, especially when framed as a cash discount. Problems usually arise when fees are not clearly explained before checkout.

  5. What other ways can small restaurants manage card fees?

    They can encourage cash or debit payments, review processors for better pricing, or use lower-cost payment methods. Some also support efforts to limit future fee increases.

With cash discounts and card fees on your list, the restaurant resources hub has the related guides.

Flexible payment processing solutions for host merchants.

Real-Time Payments for Small Businesses — 2026 Trends to Watch: FedNow, RTP, and Instant Transfers

In a technologically advanced environment, people are tired of waiting for invoice payments and advocate for instant money movement. Today’s small businesses are discovering that instead of sending an ACH payment on Friday and waiting until Tuesday for funds to clear, they can push or request payment and have the money arrive in seconds (even on weekends or holidays). New real-time rails are making this possible. The Federal Reserve’s FedNow service (launched in July 2023) enables banks to send instant transfers 24/7, every day of the year.

Over the last year, FedNow has quickly added participants and volume. Meanwhile, The Clearing House’s established RTP® (Real-Time Payments) network (introduced in 2017) covers most of the U.S. banking system and processes hundreds of billions of dollars per month. Together, these networks mark a sea change in how businesses pay vendors, payroll, and suppliers. Here are the top instant payments trends for small businesses to watch out for in 2026.

Understanding Real-Time Payments

Fast and reliable payment processing for your business with Host Merchant Services.

At its core, a real-time payment is simply an account-to-account transfer that settles within seconds, with funds available to the payee immediately. Unlike ACH transfers (which typically take 1 to 3 business days to process) or legacy Fedwire wires (which only run during banking hours), modern instant rails operate 24/7/365.

The Clearing House RTP and FedNow both use the ISO 20022 messaging standard, enabling rich payment data and immediate settlement. Once initiated, the money moves, and the transfer is final. For small businesses, this means they can send a payment at midnight on Sunday, and the supplier’s account receives it instantly rather than waiting for Monday’s banking window.

Both real-time systems offer very similar core benefits: immediate settlement (often under 5 seconds), irrevocable transfer, and 24/7 availability. They also support payment messaging (e.g., invoice details) and are designed to be accessible to banks and credit unions of any size. The key difference is who runs them.

The Clearing House (owned by major banks such as Chase, BofA, and Wells Fargo) built the RTP network first, while FedNow is operated by the Federal Reserve. Many financial institutions use both rails to reach more counterparties. But currently they operate as two separate, non-interoperable systems. Industry data show that about 58% of banks offering instant payments are connected to both networks.

FedNow: The Fed’s Instant Payment Network

fednow

Image source

FedNow is the Federal Reserve’s instant payments rail, launched in July 2023 to give banks and credit unions of all sizes access to real-time transfers nationwide. Early adoption came from smaller institutions seeking parity with large banks already on RTP, but by late 2025, usage had broadened significantly. FedNow now connects roughly 1,500 financial institutions, covering about 40% of U.S. demand deposit accounts, with participation growing faster than RTP did in its early years. Large banks have also joined, including PNC and Capital One, signaling mainstream acceptance.

Network usage has accelerated sharply. In Q1 2025, FedNow processed about 1.3 million transactions; by Q2, that rose to roughly 2.1 million transactions and nearly $246 billion in volume, a 405% quarter-over-quarter increase. Regulators attribute the surge to increased business awareness and new use cases, including payroll, marketplace disbursements, and government payments.

The Federal Reserve has also reduced friction by raising the transaction limit from $25,000 at launch to $10 million by November 2025, enabling larger B2B and real estate payments. Core features, 24/7 availability, immediate and final settlement, push-only payments, ISO 20022 messaging, and built-in fraud controls make FedNow especially attractive for time-sensitive business payments.

Business demand is strong. Surveys show roughly two-thirds of companies would use instant payments for supplier invoices and just-in-time purchases if available, and many SMBs already rely on instant methods to manage tight cash flows. FedNow removes “float,” allowing payments sent outside bank hours to settle immediately.

Adoption has been reinforced by public-sector use, including U.S. Treasury disbursements through the Bureau of the Fiscal Service for programs like FEMA disaster relief. At roughly $0.045 per transfer, far cheaper than wires and close to ACH pricing, FedNow’s cost structure further supports adoption, particularly among smaller banks and their commercial customers.

The Clearing House RTP Network

Secure payment processing with Host Merchant Services for seamless transactions.

Image source

FedNow isn’t the only instant rail in the U.S. The incumbent is the RTP® network, launched in 2017 by The Clearing House. RTP already reaches about 71% of U.S. demand deposit accounts, with technical reach exceeding 90% through intermediaries, meaning most major banks and credit unions are enabled. Like FedNow, RTP operates 24/7 with seconds-level delivery and final, irrevocable settlement, but it benefits from a multi-year head start and deep penetration among large banks and corporates.

That head start is clearly evident on the scale. By late 2024, the RTP Network was processing roughly 1 million payments per day and about $500 billion per month, far exceeding FedNow’s volumes through 2025. Around 285,000 businesses send RTP payments each month, with everyday use cases including loan payments, payroll, and supply-chain disbursements. In February 2025, RTP raised its per-transaction limit from $1 million to $10 million, aligning with FedNow and enabling large corporate and real estate payments to move instantly.

As a result, most banks now pursue a multi-rail strategy. Roughly two-thirds of U.S. banks have enabled at least one instant rail, and more than half of those support both RTP and FedNow to maximize reach. While the two systems are not directly interoperable, third-party providers often bridge them, allowing businesses to pay counterparties on either network. Looking ahead, both rails support Request for Payment (RFP), enabling merchants to send a digital invoice directly to a payer’s bank app for one-click approval. Industry consensus is that RFP could meaningfully reshape B2B invoicing and consumer billing starting in 2026.

Why Instant Payments Matter for Small Businesses

Easy merchant payment solutions for small businesses with Host Merchant Services.

For small and medium enterprises, faster payments can be transformative. The single most significant benefit is improved cash flow and liquidity. Instead of having money sit “in transit” for days, real-time transfers put funds to work immediately. This means a retailer can get paid and use those funds to restock inventory or pay the next invoice that same afternoon. It means a service provider doesn’t have to wait an extra business day to pay wages or suppliers.

Instant settlement eliminates pre-funding: businesses no longer need to hold large cash balances or worry about timing payroll in advance, because the funds arrive exactly when needed.

Another plus is transparency and record accuracy. When payments settle immediately, a business’s books are always up to date. There’s no lag between a customer paying and the accounting system reflecting the new balance. This can simplify reconciliation and planning: at any moment, you have a clear view of cash on hand and outstanding liabilities. Errors and disputes may also drop, since instant rails provide robust status messages (you know right away if a payment went through or failed).

Operationally, real-time payments cut admin work. Instead of printing checks or initiating ACH batches, a company can click to send a FedNow payment or activate a pull via RFP and be done. Funding payroll via FedNow can ensure employees get paid on time, even if last-minute adjustments are needed. Businesses can automate payables and receivables more tightly: some inventory management systems can even trigger instant payments upon shipment arrival (a “just-in-time” model). In fact, Fed surveys indicate that many companies want these options. Nearly two-thirds of firms would use instant payments for recurring bills if their bank offered them.

Several industries are already gravitating toward real-time pay. Online marketplaces are using instant disbursements to pay sellers faster after a sale. Gig-economy platforms pay workers on demand via instant rails. And service firms (contractors, healthcare providers, etc.) can request and receive immediate payment for invoices. In sectors with tight margins and cash constraints (such as hospitality and transportation), businesses increasingly require faster settlement to remain agile. Consumer-facing apps like Venmo and Zelle have shown that people expect instant transfers, and business customers are increasingly demanding the same convenience in B2B contexts.

Finally, timing can be a competitive differentiator. Offering your customers faster refunds or billing them via instant invoice requests can build goodwill. Paying a vendor in seconds can secure an early-payment discount. During emergencies (such as natural disasters), the ability to send or receive funds immediately can be critical. The recent use of FedNow for FEMA relief payments highlighted how much faster funds can reach where they’re needed.

Instant Payments Trends: What To Watch In 2026

Looking to 2026, several key trends are likely to shape how small businesses interact with real-time payments:

1. Continued Growth in Participation

The number of banks and credit unions participating in FedNow and RTP will continue to grow. By early 2026, well over half of all U.S. institutions are expected to be live on at least one instant network. In particular, the remaining mid-size banks – and some of the last big holdouts like Citigroup and Bank of America – have been moving toward connectivity.

PNC and Capital One joined FedNow in late 2025, and more are expected to follow. The result will be an even broader reach for small businesses: eventually, you can assume almost any bank account can send or receive instantly.

2. Higher Transaction Limits and Big-Business Use

With FedNow and RTP both supporting $10 million transfers, large corporate payments are becoming viable on these rails. In 2026, we expect to see more treasury departments sending big vendor bills, cross-border suppliers (via U.S. banks), and real estate or M&A transactions move in real time.

This opens up instant rails for mid-market and enterprise clients, too – meaning fintech tools that serve small businesses (like payment gateways or accounting platforms) may start supporting larger instant transfers.

3. “Request for Payment” (RFP) Goes Mainstream

Both FedNow and RTP support RFP messages (also known as “request-to-pay” or “RTPay”). Starting in 2026, this is likely to become a widely used feature: think of it as electronic invoicing on steroids. A small business can issue an RFP invoice through their bank or invoicing app; the customer receives it (often via their mobile banking app) and taps to pay immediately.

TCH executives believe RFPs will dramatically change receivables, turning old-fashioned bill collections into a seamless digital workflow. We’ll likely see RFP-enabled invoicing portals, QR-code receipts that auto-initiate payments, and more automated bill pay options for consumers and businesses.

4. Multi-Rail as the Norm

By 2026, it will be standard practice for any business-facing bank or fintech to support both FedNow and RTP (and even alternative instant rails like push-to-debit). As noted, over half of banks with instant-pay services already do this. This reduces fragmentation: if your vendor is on one network, your bank can still reach them via the other rail or a combined payments platform.

For small businesses, this means you can request an instant transfer by name, and the underlying system will select the appropriate network or service provider to execute it. In other words, instant payment “interoperability” will come through software and partnerships, if not through a single unified network.

5. Integration with Digital Wallets and Gateways

Expect more third-party payment platforms (e.g., Stripe, PayPal, Square/Block) to integrate with FedNow and RTP. Some already have pilot programs or partnerships in place. In practice, this means a small merchant on such a platform could withdraw or transfer funds on demand via instant rail.

Instead of waiting days to get a payout from an online sales platform, the business could initiate a FedNow transfer. The advantage here is flexibility: you can move funds between your bank and treasury accounts instantly, 24/7.

6. Enhanced Fraud Controls and Data

As instant payments scale, fraud and compliance capabilities will evolve. In 2025–26, the Fed introduced tools such as “account activity thresholds” and is piloting a network intelligence check (which allows senders to query recipient bank information in advance). We expect more such controls to arrive, enabling banks and businesses to vet transactions in real time.

Meanwhile, the rich ISO 20022 data fields available on FedNow/RTP will allow merchants to include detailed invoice information with each payment, aiding reconciliation and reducing errors. Better data enables small businesses to link transactions directly to invoices or purchase orders, improving accounting efficiency.

7. Government and Payroll Use

Beyond the FEMA example, governments at all levels may start using instant rails for certain disbursements (e.g., tax refunds, grants, vendor payments). In 2026, more agencies will likely give small businesses the option to receive funds instantly.

On the payroll side, instant payroll services (sometimes called earned wage access) will grow: employees can access a portion of their salary early, with funds debited from the employer’s FedNow account immediately. Many wage-payment platforms are already exploring this, and the trend will catch on with small employers who want to offer flexible pay.

8. Cross-Border and New Markets

While FedNow and RTP are domestic systems, their adoption could enable cross-border instant transfers in the future (e.g., by partnering with Canada’s new real-time system, which is slated to launch 24/7/365, as FedNow does).

For now, 2026 trends will primarily focus on U.S. domestic flows, but keep an eye on any bridging initiatives between U.S. and foreign RTP schemes – these could simplify international payments in the future.

Getting Started: Using Real-Time Payments in Your Business

If you’re a small business owner or finance professional, here’s how to take advantage of these developments:

  • Check Your Bank’s Capabilities: First, see if your bank offers FedNow or RTP payment services. Many banks advertise “real-time payments” as a product. Note that early on, some banks only allowed receiving instant payments (so customers could send them money, but they couldn’t send it out). Make sure your account can send on the real-time rail as well. If you’re not sure, ask your banker or check your online bill-pay or payment services; they may offer an “instant transfer” option.
  • Use Instant Payments for Invoicing and Payables: If you issue invoices, ask your customer to pay via real-time transfer. You could provide your routing and account details along with the invoice and instruct them to use FedNow/RTP. Some billing systems will soon integrate “Pay Now” buttons that generate an RFP on the fly. On the vendor side, you can pay suppliers instantly. If you need to pay a vendor outside regular ACH cycles, log into your bank’s portal and choose the “Instant” or “Real-time” payment option. Your bank will deduct the funds from your account and route them via FedNow/RTP; the vendor will receive the cleared funds seconds later (even if it’s 10 pm).
  • Automate Recurring Payments: Payroll is a great use case. Instead of accumulating funds days in advance of payday, you can schedule or trigger the payroll file to send via FedNow at pay time. Employees at participating banks will receive their salaries instantly (after tax withholding), with no pushback because the funds haven’t “hit” yet. Similarly, you could automate routine vendor payments (rent, utilities, loan payments) to go out in real time, ensuring no missed deadlines.
  • Mind the Transaction Limit: FedNow and RTP each have per-transaction maximums ($10 million in 2025). For most small-business needs, this is well above the typical invoice amount. If you have a substantial payment (e.g., from a large construction project), you may need to split it into multiple payments or use wire transfers. But remember that ACH often has per-batch or daily limits, whereas FedNow allows a single push of up to $10M.
  • Factor in Fees: A FedNow payment costs about $0.045 (4.5 cents) per credit transfer; RTP fees are similar. Compare this to your current costs: if you’re used to wire fees or overnight ACH fees, instant rails can be cheaper. For high-volume businesses, consider how these per-payment fees affect your costs. Some banks bundle real-time payments into package fees, especially as usage grows. It’s a good time to negotiate with your banker, given the competitive landscape of real-time services.
  • Stay Updated on Standards: Because real-time payments are data-rich, work with your accounting or ERP system to capture remittance info. In 2026, you’ll want to ensure your invoicing software can include invoice numbers or line items in the payment request. This way, when funds arrive, your accounts receivable automatically matches them to open invoices. Also, follow developments like the FedNow ‘Explorer’ portal (fednow.explore.gov) and industry forums for best practices.
  • Educate Your Customers and Vendors: Not all of your customers or suppliers may yet be familiar with real-time payments. Consider including a note on invoices: “Want to pay instantly? Use bank quick-pay with our routing/account details or look for a ‘Request for Payment’ link.” If a client’s bank supports RTP or FedNow, they might already see an instant-pay option in their online bill pay. On the flip side, if you rely on just a few key vendors, encourage them to enable instant payment receipt (this may require no action on their part if their bank already supports it, but it’s worth confirming).

Conclusion

Real-time payments are poised to become the new normal for small businesses. Both FedNow and RTP have achieved critical mass in participation and now boast billions in quarterly volume. For U.S. SMBs, this means better cash flow, reduced financial friction, and new service models (instant invoicing, on-demand payroll, etc.).

As 2026 unfolds, watch for broader adoption by larger banks, innovative “request to pay” workflows, and the cementing of a multi-rail payments infrastructure. By exploring these tools now, businesses can get ahead of the curve – enhancing liquidity and convenience for themselves and their customers.

Frequently Asked Questions

  1. What are real-time payments, and how fast are they?

    Real-time payments are account-to-account transfers that settle in seconds, with funds available immediately, 24/7/365, including weekends and holidays.

  2. What’s the difference between FedNow and RTP?

    FedNow is operated by the Federal Reserve, while The Clearing House runs RTP®. Both offer instant, final payments, but they are separate, non-interoperable networks.

  3. Do small businesses need special software to use instant payments?

    No. Most businesses access real-time payments through their bank’s online portal or existing treasury, payroll, or invoicing systems, provided their bank supports FedNow or RTP.

  4. Are real-time payments safe and reversible?

    They are highly secure but not reversible. Once a payment is sent, it is final; therefore, banks apply fraud controls and transaction monitoring before processing it.

  5. How will instant payments change small businesses in 2026?

    In 2026, expect wider adoption of bank accounts, greater use of Request for Payment (RFP) invoicing, faster payroll processing, and tighter cash-flow management to become standard for small businesses.

Fraud alert on online payment security and merchant services risk.

E-Commerce Fraud & Chargebacks in 2026: Fighting Back Against Online Payment Scams

Online sellers are seeing a sharp rise in e-commerce fraud & chargebacks as we head into 2026. This “chargeback tsunami” is coming from both organized fraudsters and regular customers who abuse the system. Most disputes now involve “friendly fraud,” where legitimate customers dispute valid purchases. In many e-commerce sectors, analysts estimate that about 60-75% of chargebacks fall into this category rather than being caused by stolen cards or hacking.

Chargeback volumes continue to climb, with global disputes expected to reach approximately 261 million by 2025 and 324 million by 2028. That adds up to significant losses: online merchants are set to lose more than $30 billion to chargebacks in 2025 alone (roughly $33–34 billion by some estimates). And the actual cost is even higher, since merchants usually pay $3-$4 in total costs for every $1 of fraud once you add fees, lost goods, and staff time.

The upside is that savvy merchants can counter by spotting emerging fraud patterns (especially friendly fraud) and implementing layered defenses, including stronger fraud filters, more transparent communication, tracking, new network rules, and strong customer service.

Friendly Fraud on the Rise

Unauthorized transaction warning digital icon, cyber security issue, online payment alert, fraud alert, Host Merchant Services.

First-party, or “friendly,” fraud occurs with a valid card and a mostly honest transaction. It occurs when a real customer makes a purchase, receives (or retains) the goods or services, and later disputes the charge, claiming it was unauthorized or not delivered. Common motives include simple buyer’s remorse, confusion (especially with subscriptions or trial offers), or even families sharing a card without permission.

Because the transaction appears legitimate, friendly fraud can be hard to spot until weeks later, when the chargeback is issued. By then, the merchant has already shipped the item or provided the service and has collected payment. The cardholder typically initiates the chargeback process, resulting in the merchant losing both the item and the sale and incurring any dispute fees.

Today, this problem is everywhere. Industry research shows that friendly fraud now drives most online disputes. In one survey, 72% of merchants reported a surge in friendly fraud incidents. Analysts estimate that friendly fraud makes up roughly 60-75% of chargebacks in high-risk online sectors (in some reports, even higher), far above actual stolen-card fraud. Put differently, the vast majority of chargebacks today are actually real customers disputing legitimate transactions.

This shift has several causes:

  • The post-pandemic normalization of shopping patterns,
  • Exploding subscription services, and
  • Consumer behavior

Many shoppers now subscribe to multiple services and may forget to renew, then dispute the charge when it appears on their statement. Others regret an impulsive purchase or find an easier way to get a “free return.”

Specific industries feel the friendly-fraud pinch even more. Digital goods, gaming, and subscription services all report especially high rates of “first-party” fraud. Travel is another flashpoint: consumers who miss a flight or decide not to travel often dispute airline or hotel charges rather than work it out with the provider. Post-pandemic habits play a role here.

Studies of travel merchants show higher “no show” disputes due to weather or personal reasons, and retailers note that Gen Z shoppers, in particular, sometimes dispute purchases out of impulse or confusion. Even everyday purchases, such as healthcare or auto service, can lead to disputes if the customer misunderstands the plan. In all these cases, from the merchant’s point of view, the sale seemed normal and above-board until the dispute arrived out of the blue.

Why friendly fraud is so tricky: It appears to be a regular sale. The transaction is approved, the product ships, and customer communications may all go smoothly. There is nothing to suspect at the point of purchase. Then weeks later, often after the product was delivered, the merchant is blindsided by a chargeback notice.

By that time, the merchant’s evidence may be thin (for example, “proof of delivery” is harder when everything was digital or intangible). Card-issuing banks tend to side with their customers in borderline cases unless the merchant can provide convincing proof. That means merchants must be disciplined in their record-keeping and post-sale communication to combat friendly fraud.

Chargeback Tsunami – Costs and Trends

Chargeback

The scale of the chargeback problem is enormous and continues to grow. Last year, roughly 238 million chargebacks were filed worldwide, and industry forecasts indicate that number will rise dramatically. By 2025, it’s projected to reach around 261 million global disputes, and by 2028, over 320 million. (Some analysts even see 337 million by 2026 under certain assumptions.)

This increase, on the order of 24% or more in a few years, reflects not just more e-commerce, but also how easy dispute filing has become. It also mirrors rising online fraud, with digital fraud losses up about 15% in 2024, indicating more charges are being flagged as suspicious by banks and customers.

For merchants, the financial impact is staggering. In 2025 alone, e-commerce businesses are expected to lose more than $30 billion due to chargebacks. One estimate pegs the global value of disputed transactions at roughly £33.8 billion (about $40 billion) in 2025, resulting in significant refunds and lost inventory. And that’s just the refunds; the actual cost is much higher.

Every dispute incurs fees and overhead: card networks typically charge a fixed chargeback fee (often $15-$25) per case, and merchants incur additional logistics costs, administrative time, and higher processing costs as chargebacks rise. Industry research shows that, once you tally staff hours, fees, lost sales, and penalties, merchants pay roughly $3.75- $4.60 for every $1 in fraud or chargeback losses. In other words, a single $100 fraudulent chargeback can cost a merchant nearly $400 in total costs.

Beyond direct dollar losses, excessive chargebacks can threaten a business’s ability to operate. Credit card brands like Visa and Mastercard monitor each merchant’s chargeback rate (the percentage of transactions that turn into disputes). If a merchant’s chargeback ratio creeps over about 0.5–1% for any month, it often triggers a “chargeback monitoring” program. Merchants in those programs face fines, higher fees, and the need to implement mitigation plans.

If problems persist, a processor may even shut off the merchant’s ability to accept cards. In practice, that means a few chargebacks don’t just steal revenue – they erode trust in the merchant. Regulators and bank underwriters worry that a merchant losing money to chargebacks may be more likely to raise prices or squeeze legitimate operations. Keeping chargebacks under control is critical to avoid losing merchant accounts or being placed on high-risk status.

Tools and Tactics to Combat E-Commerce Fraud & Chargebacks

Cyber security alert for scam detection on merchant processing systems.

Merchants that fight back combine two strategies: first, prevent outright fraud and high-risk transactions up front; second, prepare to handle chargebacks vigorously when they occur. No single tool solves everything; today’s best defense is a layered approach that weeds out bad orders while keeping honest customers happy. Here are the key tactics:

1. Robust Fraud Screening

Use every available fraud filter. Modern fraud prevention platforms use machine learning to analyze each transaction in real time, flagging suspicious patterns, like repeated high-value orders from new accounts, mismatched shipping and billing addresses, or out-of-country cards. Always check the CVV (card security code) and AVS (Address Verification System) on every order – these simple checks can automatically stop a surprising share of fraud attempts. Merchants using AVS see roughly a 15-20% reduction in fraud-related chargebacks by verifying billing addresses. Even when they do block a payment, it’s better than shipping a product you won’t get paid for.

Crucially, implement 3-D Secure 2.0 (the updated version of “Verified by Visa”/”Mastercard SecureCode”). 3DS2 adds an extra identity verification step (such as a one-time SMS code or biometric check) for high-risk transactions. When done right, 3DS 2.0 shifts liability away from the merchant for fraudulent card-not-present charges, reducing fraud chargebacks significantly while keeping the checkout experience smooth. Studies show 3DS and tokenization together can cut CNP fraud by 15-20% or more.

2. Clear Billing Descriptors & Policies

Many chargebacks happen simply because the customer doesn’t recognize the merchant or the charge. Make sure your billing descriptors, the name that shows on the credit card statement, are clear and recognizable – ideally matching your store or brand name. In shopping carts and confirmation emails, use consistent company names and include a contact number or email so that confused buyers can verify before disputing.

Also, simplify refund and cancellation terms. Hard-to-find or confusing return policies prompt impatient customers to dispute with their bank rather than contact you. Spell out product details plainly on the website and in confirmations. For subscription services, send clear reminders when a trial is about to end or a recurring charge will hit. Taking just a few steps like these can dramatically cut misunderstandings.

One recommendation: some savvy merchants send a pre-charge email or SMS that says, “Your [Service] subscription renews tomorrow for $X. Click here to cancel or update your subscription.” This slight nudge often stops customers from filing an “unauthorized” dispute next week.)

3. Proof of Delivery and Order Tracking

When a product is shipped, enable tracking and delivery confirmation. If a customer says, “I never got the item,” a tracked delivery slip or GPS delivery record can be decisive evidence. For digital goods or services, maintain usage or download logs. Whenever possible, collect a signature (including an e-signature) to confirm receipt of high-value items.

Going the extra mile by having a courier-delivered package signed or geo-verified provides proof that should win disputes. One study found that giving clear tracking information and delivery alerts reduced “item not received” disputes by about 25%. At the very least, a photo of the package at the doorstep, stamped with the date/time, can deter a buyer from claiming it was never delivered.

4. Fast Response and Representment Tools:

Chargebacks must be challenged promptly and supported by substantial evidence. Sign up for chargeback management software or services that alert you immediately when a dispute is filed. (For instance, card schemes now offer dispute alerts through partners like Ethoca or Verifi.) An alert lets you contact the customer right away, often resolving misunderstandings before a formal chargeback.

If a formal dispute arises, use chargeback reprieve platforms to automatically assemble the required documents and meet tight deadlines. These systems typically include representation software that packages the transaction history, proof of shipping, customer communications, and more, then submits it to the bank under the right reason code. Since only about 8-25% of chargeback disputes succeed for merchants without strong tools, having an organized representment process is vital.

5. Leverage Card Network Rules (Compelling Evidence, PSD2, etc.)

Card networks have updated their rules in recent years to help merchants fight friendly fraud. Visa’s Compelling Evidence 3.0 now lets merchants submit enhanced proof during disputes – even evidence of prior legitimate transactions or prior authorization flows, to show that the customer did indeed use the card. In practice, this means you can link a friendly fraud claim (“I never bought this”) to the fact that the same customer has used the card for smaller purchases or to auto-pay subscriptions.

When used correctly, these expanded evidence rules can sway issuers. Similarly, Europe’s PSD2 (Strong Customer Authentication) mandates two-factor authentication on online payments – this extra validation (like a fingerprint or code) makes it much harder for a consumer to claim fraud later. Merchants should stay up to date on all applicable rules and submit all available evidence, including proof of customer identity confirmation, correspondence logs, and accepted service terms. Even something as simple as showing an order confirmation email or online chat log can tip a dispute in your favor.

6. Excellent Customer Service as Prevention

Sometimes the best chargeback to win is the one that never happens. Encourage customers to reach out by providing easy support channels. For confused or unhappy buyers, a quick refund or exchange through your support team can salvage the sale and avoid a bank dispute. Especially for subscription or trial-related misunderstandings, a well-timed outreach (“I noticed your plan renewal – do you have any questions?”) can help prevent chargebacks. Train your service reps to recognize when a customer is upset enough to file a dispute and to offer solutions immediately.

In other words, treat refunds as a cost of excellent service that pays for itself. Data show that many disputes are “resolvable” if the merchant communicates clearly and sympathetically. Good communication also means sending receipts and reminding customers about upcoming payments. Even a brief note (“You’ll see the charge on your bill from MyStore.com on May 10th”) can reduce those “unknown charge” disputes.

7. Monitor Chargeback Metrics

Finally, monitor your chargeback rates and reasons closely. Set internal alerts if the ratio begins to rise. Track the most common dispute codes and drill into root causes. If, for example, you see a jump in “product not as described” claims, it’s a cue to improve product images or descriptions. If disputes cluster in a specific geography or customer segment, consider tightening fraud rules for that area or segment.

Many merchants use analytics from their payment gateway or a specialized dashboard to visualize trends. By identifying problems early, you can adjust your policies or technology to mitigate them before they significantly impact you.

Conclusion

Fighting chargebacks in 2026 means a two-pronged approach. On one side, use advanced fraud tools (AI filters, CVV/AVS checks, 3DS authentication) to prevent fraudulent orders from being approved. On the other side, when disputes do occur (especially friendly-fraud disputes), use clear evidence, new network rules, and innovative customer outreach to win them back. When layered correctly, these tactics can dramatically reduce losses.

Frequently Asked Questions

  1. What is friendly fraud, and why is it growing?

    Friendly fraud happens when a real customer disputes a valid charge, often claiming an item wasn’t received or a purchase wasn’t authorized. It’s rising because online shopping is easier and chargebacks are easy to file, resulting in significant losses for merchants.

  2. How much do chargebacks really cost a business?

    Chargebacks cost far more than the original sale due to fees, lost inventory, and operational work. For every $1 lost, businesses often lose $3–$4, and high chargeback rates can even lead to account closures.

  3. How can I prevent fraud on my online store?

    Use fraud tools like CVV and address checks, risk scoring, and 3D Secure for card payments. Monitor unusual orders and consider AI-based fraud services to prevent fraudulent transactions before they result in chargebacks.

  4. How can I fight chargebacks I believe are invalid?

    Dispute them through representment, using strong evidence such as delivery confirmation, IP data, device matching, and past purchase history. Acting quickly and submitting clear proof improves your chances of winning.

  5. What new tools or trends are helping merchants with fraud and chargebacks in 2025?

    AI-driven fraud detection, chargeback alerts, and bank-merchant communication tools are reducing disputes. Better analytics and customer verification methods are also helping merchants spot risks earlier and respond faster.

Contactless payment technology for merchants and customers.

Tap-to-Phone Payments: Turning Smartphones into POS Terminals

Smartphones have become full-fledged point-of-sale devices thanks to Tap-to-Phone (a type of SoftPOS) technology. With a simple NFC-enabled phone and payment app, even the smallest businesses can accept contactless cards and mobile wallets. In fact, industry data show Tap-to-Phone is exploding – Visa reported a roughly 200% year-over-year growth in Tap-to-Phone adoption globally.

That growth means millions of merchants of all sizes can now “easily accept digital payments” using their existing smartphones. We’ll explain how the system works, outline the easy setup steps, and highlight why it’s a game-changer for contractors, food trucks, boutiques, and other small businesses. We’ll also cover security, costs, and real-world success stories that show Tap-to-Phone levels the playing field – letting a tiny stand look as polished at checkout as a big-box retailer.

How Tap-to-Phone Works

Secure mobile payment verification with Host Merchant Services.

Tap-to-Phone (also called Tap on Phone or SoftPOS) uses the merchant’s phone as the NFC reader for contactless payments. A Tap-to-Phone app (provided by a payment processor or bank) handles all the card-reading and encryption. In practice, the payment flow is almost identical to using a traditional contactless terminal:

  • Enter the amount: The merchant opens the Tap-to-Phone app on their NFC-capable device and types in the sale total.
  • Customer taps to pay: The customer taps their contactless card, phone, or wearable (Apple Pay, Google Pay, Samsung Pay, etc.) to the merchant’s phone. The phone’s NFC antenna reads the payment token just like a card reader.
  • Process and receipt: The Tap-to-Phone app securely transmits the payment data to the acquirer and issuer over the same networks used by regular terminals. Once approved, the merchant can instantly email or SMS the customer a digital receipt.

Merchants can now accept payments by simply installing an app. Tap-to-Phone lets merchants securely accept contactless payments on the NFC-enabled Android and Apple smartphones they already own.

Crucially, a Tap-to-Phone transaction is still a card-present EMV transaction under the hood. Every Tap-to-Phone charge uses the same encryption and security as a normal contactless chip card payment.

The card data is read as a one-time cryptogram (token) and sent to the issuer for validation. From the user’s perspective, the experience is just as fast and secure as waving an NFC terminal. Tap to Pay on iPhone is protected by the same technology that makes Apple Pay private and secure, and Apple cannot see transaction details.

Simple Setup: Phone and App

Getting started with Tap-to-Phone is extremely easy. The only requirements are:

  • NFC-capable smartphone or tablet: Most modern Android phones have NFC built in. For Apple, any iPhone XS or later (running iOS 15.5+ or later) can serve as a Tap-to-Phone terminal. (Older iPhones and iPads typically cannot.)
  • A certified Tap-to-Phone app: The merchant downloads a payment app from a trusted processor (e.g., Square, Stripe/Shopify POS, Worldpay Zelle, Bookipi, Verifone SoftPOS, etc.). Often, this app is free or low-cost, and it connects to the merchant’s payment account.
  • Payment account or processor: As with any card acceptance, the merchant needs to set up their account or merchant ID with the provider. After that, no new hardware is required.

Once the app is installed, the merchant logs in and is ready to accept payments anywhere with a network connection. Even small vendors can accept payments by downloading a mobile app. Many apps even work offline briefly (caching transactions until next connectivity).

Importantly, all Tap-to-Phone solutions comply with PCI’s mobile standards. Providers typically go through PCI Mobile-POC (Payment on Consumer devices) certification. This means the app’s code and the device’s secure element have been tested to handle card data securely. Although it’s running on a consumer phone, it still meets strict payment security standards. A Tap-to-Phone app must encrypt all transaction data and may use tokenization (so raw card numbers are never exposed). Some apps further require the merchant to unlock the phone or app (with a passcode or fingerprint) before each sale, adding another layer of security.

Why Small Businesses Tap-to-Phone Payments

Secure payment processing for small business merchants | Host Merchant Services.

Tap-to-Phone is especially valuable for small and mobile businesses. Here are the key reasons:

  • Zero hardware cost: Traditional contactless terminals can cost $300–$1,000 each. Tap-to-Phone replaces the merchant’s phone with their own. Tap-to-Phone requires no additional hardware beyond the app. This eliminates the capital outlay for small businesses, freelancers, home-based businesses, and side hustlers.
  • Full contactless acceptance: Merchants can accept any NFC payment – credit/debit cards or mobile wallets. Tap-to-Phone makes accepting payments from your customer’s card, phone, or watch simple. This means Apple Pay, Google Pay, Samsung Wallet, and similar services are supported, so customers can pay however they prefer.
  • Mobility: Your phone goes anywhere – food truck, farmer’s market, customer’s driveway, or even a delivery route. A Tap-to-Phone solution effectively turns smartphones into mobile checkout terminals. This is ideal for itinerant businesses. For instance, a plumber or mobile mechanic can accept card payments on-site using only a phone. A food truck operator can collect card tips in line as easily as receiving cash.
  • Speed: NFC is swift (often 1–2 seconds). Customers don’t fumble with pins or swipe cards. Faster checkouts can boost satisfaction and sales, especially in queues or on-the-spot purchases.
  • Digital receipts & integration: Unlike some legacy terminals that print paper receipts, most smartphone POS apps instantly send receipts via email or text, reducing paper use and time spent. Many apps can also integrate sales data with inventory or accounting software. A small shop can track inventory and issue invoices through the same system.
  • Professional image: Displaying contactless logos and tapping a phone looks modern. Tap-to-Phone makes the checkout experience feel more sophisticated. Even without a big register, the act of tapping to pay gives customers confidence.

These advantages are especially transformational for enterprises that were previously cash-only. A taxi driver, street vendor, or home baker can now easily take card or wallet payments.

Security and Compliance

Security and Compliance

Security for Tap-to-Phone mirrors that of chip card terminals. Every tap uses encryption: the raw card data is exchanged as a single-use token (cryptogram) through the payment network. PCI Security Standards require that Tap-to-Phone apps meet strict rules (the PCI MPoC standard) to protect data. Typically, the sensitive EMV logic runs in a secure hardware element on the phone, or in a trusted cloud service tied to the certified app. Apps also commonly use tokenization so that merchants never see a full card number.

Payment networks also limit transactions. For instance, Square’s Tap-to-Pay on iPhone has limits (e.g. $50,000 per tap, $10,000 per physical card) to prevent misuse. Most Tap-to-Phone systems require the merchant to authenticate with the phone or app (via PIN or biometrics) before processing a payment, which helps protect against loss or theft.

Costs and Fees

The financial upside is enormous: no more terminal costs. Tap-to-Phone eliminates the hardware expense. Merchants use the devices they already own. This means zero upfront equipment cost for the POS. (Merchants do still need a valid payment account or gateway, but those costs are unchanged.)

Regarding processing fees, Tap-to-Phone generally applies the same rates as other in-person transactions. Providers typically charge a flat per-transaction fee (e.g., around 2-3% plus a few cents) in the U.S. These rates are comparable to, or even lower than, traditional card-present rates for small merchants. There are no surprise add-on charges specific to Tap-to-Phone; the merchant pays their usual payment-processing rate.

Ultimately, Tap-to-Phone can reduce the overall cost of accepting payments. A merchant no longer needs to lease or replace an aging terminal or printer. The only cost is the marginal processing fee on each sale. For many small businesses, the ability to accept card payments (and capture more sales) far outweighs the small percentage fee.

Leveling the Playing Field

Perhaps the most significant impact is how Tap-to-Phone democratizes commerce. No longer do only big stores or chains look polished at checkout. Now the smallest merchant can accept a customer’s tap just as smoothly. A backyard craftsman or an independent plumber can look just as modern as a department store cashier. This helps small sellers compete: they can offer the same quick in-aisle checkout as big retailers.

That means a contractor at a home improvement store or a florist at a farmers’ market can tap to pay without any bulky equipment. A boutique retailer can take both credit card and wallet payments in a single tap. Customers, in turn, are more willing to pay by phone or card rather than only in cash. The net result is more sales and growth for businesses that might otherwise have been cash-only.

Conclusion

Turning smartphones into payment terminals is no longer science fiction – it’s happening now, at lightning speed. Tap-to-Phone lets any NFC-enabled Android or iPhone accept contactless payments with just a downloaded app. The setup is straightforward, security is top-notch (on par with chip cards), and costs are minimal compared to buying a card reader. For small and mobile businesses, from food trucks and flower shops to consultants and salons, the benefits are enormous: instant card acceptance anywhere, a professional-looking checkout, and the ability to tap into more sales.

With Visa and Mastercard championing the trend, and hundreds of thousands of merchants already equipped, Tap-to-Phone is reshaping commerce at the grassroots. It truly is a tap into the future, where even the tiniest vendor has the same checkout power as any big-box store. As more consumers adopt digital wallets and prefer contactless payments, a Tap-to-Phone solution ensures a business never misses a sale. In short, the smartphone has officially become the ultimate portable cash register.

Frequently Asked Questions

  1. What is Tap-to-Phone (SoftPOS), and how is it different from a traditional card terminal?

    Tap-to-Phone turns an NFC-enabled smartphone into a contactless payment terminal using a certified app. It works like a traditional POS, but without extra hardware—everything runs securely on the phone you already own.

  2. What devices do I need to start accepting Tap-to-Phone payments?

    You need an NFC-capable Android phone or a supported iPhone (typically iPhone XS or later), plus a certified Tap-to-Phone app. A standard merchant or payment account is also required to process transactions.

  3. What types of payments can customers use with Tap-to-Phone?

    Customers can pay with contactless credit and debit cards and mobile wallets such as Apple Pay, Google Pay, and Samsung Pay. NFC-enabled wearables, such as smartwatches, are also supported.

  4. Is Tap-to-Phone secure for merchants and customers?

    Yes, Tap-to-Phone uses the same EMV encryption and tokenization as traditional contactless terminals. Card details are never exposed, and transactions follow strict PCI security standards.

  5. How much does Tap-to-Phone cost to use?

    There is typically no hardware cost since you use your existing phone. Merchants usually pay standard in-person processing fees per transaction, similar to traditional card-present payments.

Secure payment processing credentials for Host Merchant Services PCI DSS compliance.

Preparing for PCI DSS 4.0 Compliance

Meeting the new PCI DSS 4.0 compliance standards remains a significant challenge for merchants in 2026. Preparing for PCI DSS 4.0 is crucial for anyone handling credit card data, including local mom-and-pop shops, as it helps prevent data breaches and avoid costly fines.

In this blog, we break down the most critical changes in PCI DSS 4.0 (from multi-factor logins to continuous security monitoring), and provide a practical compliance checklist tailored for small businesses. We’ll also explain how to implement new requirements (such as stronger passwords and anti-fraud measures) at low cost and highlight the real benefits of compliance (such as preventing breaches and maintaining customer trust). By the end, you’ll know exactly what steps to take to stay PCI compliant and protect customer data under the latest rules.

Why PCI DSS 4.0 Compliance Matters for Small Merchants (and Their Payment Partners)

Secure merchant payment processing with Host Merchant Services.

If your business accepts credit or debit cards, PCI DSS compliance isn’t optional – it’s a contractual obligation and a smart business move. The Payment Card Industry Data Security Standard (PCI DSS) 4.0 is the latest version of the rules that all merchants and payment service providers must follow to protect cardholder data. This new version fully replaces the 3.2.1 standard (retired in 2024) and introduces stronger security requirements to address today’s threats. By 2026, PCI DSS 4.0 will be fully effective, meaning every merchant – from single-location retailers to online startups – must meet the updated requirements.

Small businesses might think they’re too small to be targets, but the reality is that cybercriminals often go after easier prey. In recent years, nearly half of data breaches have impacted small or medium-sized businesses. A breach at a small merchant can be devastating – leading to financial loss, legal liability, loss of customer trust, and even the inability to continue accepting cards. PCI DSS 4.0 is designed to help prevent these disasters by raising the security baseline for everyone handling card data.

Payment partners (such as payment processors, gateways, and other service providers) are also a critical part of this ecosystem. PCI DSS 4.0 places greater accountability on these partners to consistently uphold security standards and help merchants remain compliant. In other words, security is a shared responsibility. If you’re a merchant, you should work closely with your payment providers to ensure both sides meet the new standards. If you’re a payment service provider, you’ll need to support your merchants by providing secure solutions and guidance, since your compliance affects theirs.

What’s New in PCI DSS 4.0?

PCI DSS 4.0 compliance for secure payment processing at Host Merchant Services.

PCI DSS has always been built around 12 core requirements (from maintaining secure networks and managing vulnerabilities to protecting data and controlling access). Version 4.0 builds on this foundation but updates many specific rules to enhance security. Here are the most critical changes in PCI DSS 4.0 that every merchant should understand:

  1. Multi-Factor Authentication (MFA) for All Access:

The new standard significantly expands the use of multi-factor logins. Previously, you only needed MFA for remote administrative access. Now, every user who accesses the cardholder data environment (systems that store or process cardholder data) must use MFA, whether on-site or remote.

This means employees and admins alike will need to provide at least two forms of authentication (e.g., a password and a one-time code or biometric) to log in to sensitive systems. This change is designed to prevent unauthorized access even if passwords are stolen, significantly reducing the risk of a breach.

  1. Stronger Password Requirements:

Say goodbye to short, old passwords. PCI DSS 4.0 raises the bar for password security. Passwords must be longer (a minimum of 12 characters) and should be more complex or phrase-based to improve their strength. The new standards also encourage alignment with modern best practices (such as not requiring arbitrary, frequent changes unless there’s suspicion of compromise, and instead focusing on password length/complexity and checking against known breached password lists).

For a small business, this means updating your password policies so that all staff with access to payment systems use strong, unique passphrases. Weak passwords are a common vulnerability, so this update helps ensure that a stolen or guessed password won’t be an easy entry point for attackers.

  1. Continuous Security Monitoring:

Under PCI DSS 3.x, many security activities were performed periodically (e.g., quarterly scans or annual reviews). Version 4.0 emphasizes continuous compliance and monitoring. This means businesses should not treat PCI as a once-a-year checklist, but rather maintain security vigilance every day. The standard encourages real-time log monitoring, intrusion detection systems, and more frequent checks of your controls.

In practice, a small merchant might set up alerts for suspicious activity on their payment systems, regularly review security logs (or use a service to do so), and frequently test their defenses. The goal is to catch and fix issues before they lead to a breach, rather than just discovering them at the yearly audit.

  1. Enhanced Anti-Fraud and Threat Detection Measures:

The updated standard acknowledges the evolving threat landscape, including web skimming (Magecart attacks on e-commerce sites), phishing, and other fraud schemes. New requirements in 4.0 focus on mitigating these threats. If you run an e-commerce website, PCI DSS 4.0 now requires you to ensure that any scripts or third-party content that run on your payment pages are authorized and monitored for changes (to prevent malicious code injections that steal card data).

There’s also a broader emphasis on maintaining up-to-date anti-malware software and having processes to detect and respond to suspicious activities.

  1. Flexible, Customized Implementation (Outcome-Based Focus):

One of the philosophical changes in PCI DSS 4.0 is an allowance for a “customized approach” to meet specific security objectives. Large organizations with advanced security teams might design alternative controls that achieve the goal of a PCI requirement in a different way (with approval from a PCI assessor). While most small businesses will follow the defined requirements, it’s helpful to know that the standard is becoming more flexible and risk-based.

Essentially, PCI 4.0 focuses on security outcomes (the actual effectiveness of protecting data) rather than a checkbox process. This means you have some leeway to implement security in a way that fits your environment – as long as you meet the intent of the rules. If a new technology or process can better secure card data, PCI allows it, provided you document it and a QSA (Qualified Security Assessor) validates that it meets the objective.

  1. Greater Accountability for Third-Party Service Providers:

Many small merchants rely on third parties – such as payment processors, cloud hosting providers, or IT contractors – that can affect cardholder data security. Under PCI DSS 4.0, there is a stronger emphasis on ensuring service providers are held to high standards and that merchants maintain oversight of those partnerships. This includes having clear agreements that the vendor will adhere to relevant PCI requirements, and obtaining proof of their compliance (e.g., requesting their PCI Attestation of Compliance certificate annually).

For the merchant, this means actively engaging with your partners: ask whether they are PCI DSS 4.0 compliant, inquire about how they protect your customers’ data, and ensure that security roles and responsibilities are well-defined. Payment partners will be conducting more frequent security assessments and are expected to be transparent about their controls. This change is ultimately good for merchants because a secure supply chain means fewer weak links in protecting card data.

  1. Updated Encryption and Security Technologies:

PCI DSS 4.0 updates various technical requirements to keep pace with evolving security standards. For instance, encryption standards for data in transit and at rest have been strengthened. You must use strong encryption (e.g., TLS 1.2+ for data transmission and robust algorithms for any stored card data) to prevent hackers from eavesdropping or stealing readable data. If you’ve been using old protocols or weaker cryptography, now is the time to upgrade.

Additionally, there are updates to requirements around firewalls, change management, and testing. The standard even addresses emerging technologies (such as cloud and API security) as the payments landscape evolves. For a small business, ensuring your payment devices, POS systems, and websites use up-to-date software and encryption is key. Often, this is as simple as keeping your systems patched and using payment solutions from reputable, PCI-compliant providers that automatically include these security features.

PCI DSS 4.0 Compliance Checklist for Small Businesses

Efficient payment processing solutions for your business at Host Merchant Services.

Becoming PCI DSS 4.0 compliant can feel overwhelming, especially with limited IT resources. To help, we’ve compiled a practical checklist of steps and best practices tailored for small merchants. Use this as a roadmap to prepare for a PCI 4.0 assessment (or self-assessment) in 2026:

  • Understand Your Cardholder Data Environment (CDE):

Start by identifying where cardholder data is captured, transmitted, or stored in your business. This could be your point-of-sale terminal, your e-commerce website, a customer database, or even paper records. Map out all the systems and processes involved in processing payments.

The goal is to know what parts of your business must be secured under PCI rules. If possible, reduce your scope by eliminating the storage of card data you don’t need, or by using tokenization/encryption services so you don’t store raw card numbers. A smaller CDE means fewer things to secure and monitor.

  • Update Authentication Measures (Passwords & MFA):

Implement the new authentication requirements across your systems. Ensure that every user account that can access the CDE has multi-factor authentication enabled. Most cloud services or payment portals offer MFA options (like an authenticator app or SMS code – though app or hardware token is preferred for better security).

Also, update your password policy: require at least 12-character passwords or passphrases, and encourage a mix of uppercase, lowercase, numbers, and symbols (or use passphrases that are hard to guess but easy for employees to remember). Don’t allow default passwords or shared accounts. Consider using a password manager to help employees manage complex passwords. This step will address some of the most significant changes in PCI 4.0 related to access control.

  • Review and Enhance Your Network Security:

Make sure you have a firewall installed and properly configured to protect your network (e.g., the network your card payment systems are on). Verify that you’re not using vendor-supplied defaults for system passwords or security settings on your routers, wireless access points, and other devices – change them to secure values.

Segment your network so that systems handling card data are isolated from public internet-facing segments or other parts of your business network if possible. For example, your store’s Wi-Fi for customers should be completely separate from your payment-system network. PCI DSS requires these basics, and PCI DSS 4.0 continues to emphasize strong perimeter and internal defenses.

  • Protect Cardholder Data with Encryption:

Ensure that stored card data (if any) is encrypted using strong cryptography, or, better yet, avoid storing card numbers at all if you can. If you store any card data (including for recurring billing or customer profiles), use approved encryption methods and restrict access to only those who need it. For data in transit, confirm that you use secure protocols – for instance, your payment terminal or website shopping cart should be sending card data over HTTPS/TLS (not HTTP).

Under PCI 4.0, older encryption protocols are not permitted; verify that all your systems use up-to-date, secure versions. If you use a payment service provider, much of this is handled by them, but it’s your job to ensure it’s in place. Don’t forget to protect any paper records (e.g., receipts or forms with card numbers) by securing them or, ideally, not writing full card numbers.

  • Maintain Vulnerability Management and Software Security:

Set up a process to regularly scan and update your systems for vulnerabilities. PCI DSS has long required quarterly external vulnerability scans (usually done by an Approved Scanning Vendor). Make sure you are performing these scans or working with a provider who does. Additionally, apply security patches to your point-of-sale software, e-commerce platform, and any other relevant systems promptly – especially patches for critical security issues.

In PCI DSS 4.0, there’s an emphasis on continuous vulnerability management, so consider scheduling automated scans or at least monthly check-ins to stay current. If you have a website, use a web vulnerability scanner or enable your hosting provider’s security scan service. Also, ensure anti-malware software is running on all computers and servers in scope. Secure coding practices should be followed for any custom applications (or verify your software vendors follow them). Essentially, don’t let known security holes linger in your environment.

  • Implement Continuous Monitoring and Logging:

Enable logging for all systems that handle card data, and ensure the logs (records of activities such as logins, card data access, firewall events, etc.) are monitored regularly. For a small business, “continuous monitoring” can sound daunting, but it could be as simple as using built-in tools or affordable services that alert you to unusual events.  Ensure your point-of-sale system logs administrative actions and that you review those logs or receive email alerts for suspicious login attempts.

If you have an IT service provider, ask if they can set up intrusion detection or file integrity monitoring on your systems. These tools will notify you if anyone attempts to tamper with critical files or settings. Regularly review user accounts and access rights (PCI 4.0 suggests making this a more frequent habit, not just an annual task).

Tip: Many payment platforms and merchant gateways now offer dashboards that show you security health or even include fraud monitoring – take advantage of those features to keep an eye on things in real time.

  • Train Your Staff and Establish Security Policies:

Even the best technology can fail if people aren’t trained. Ensure that you have basic security policies and procedures in place, and that all employees who handle payments or work on systems in scope are aware of them. For example, have a clear policy on how to handle card data (e.g., don’t write down CVV codes or email card numbers) and on what to do if they suspect a security incident.

Train employees on the new PCI DSS 4.0 requirements, including proper MFA use and how to identify phishing emails that could steal their credentials. Training doesn’t have to be overly formal – even a short briefing or an online training module once or twice a year can significantly improve awareness. Make security part of your business culture so everyone works together to protect customer data.

  • Work With Your Payment Partners:

Reach out to your payment processor, bank, or any other service providers to discuss PCI DSS 4.0. They might already have tools or guidance available to help small merchants comply (for example, some providers offer a portal to help generate your Self-Assessment Questionnaire and may include services like scanning or training at low or no cost). Verify that your partners are compliant with 4.0; you can request their latest Attestation of Compliance (AOC). If you use a web hosting or IT support company, ensure they understand the new requirements for your services.

Clarify who is responsible for each aspect of security. If you rely on a third-party online shopping cart, does it handle encryption and secure storage? If so, get documentation of how they meet PCI requirements. Cooperation with partners will make your compliance journey much easier, and it’s a requirement that you only work with compliant service providers.

  • Document Everything and Complete Your PCI Validation:

Finally, maintain good documentation of your compliance efforts. PCI DSS requires evidence for each control – such as policies, system configurations, or scan reports. Keep a file (digital or physical) with all relevant documents: network diagrams of your CDE, copies of security policies, employee training logs, screenshots or settings proving you’ve enforced 12-character passwords and MFA, encryption keys management procedures, etc.

When it’s time to validate compliance (usually once a year), most small merchants can do a Self-Assessment Questionnaire (SAQ) rather than a full on-site audit. There are different SAQ types depending on how you process cards (your bank or PCI SSC’s website can guide you to the right one). Complete the SAQ honestly, address any gaps you identify, and submit it, along with any required scan results, to your acquiring bank or merchant processor.

Completing this annual attestation is not only required to demonstrate compliance, but it also compels you to review your security posture regularly. In 2026, ensure you’re using the updated SAQ forms for PCI 4.0, as they have changed from the 3.2.1 version to include new questions (like those about MFA and updated password rules).

Implementing PCI 4.0 Requirements on a Small-Business Budget

Secure payment processing checklist for Host Merchant Services.

One of the biggest concerns for small merchants regarding PCI DSS 4.0 is cost, but compliance does not have to be expensive when approached strategically. Many businesses can start by leveraging the technology they already use, as modern point-of-sale systems and e-commerce platforms often include built-in security features such as encryption, firewalls, and multi-factor authentication that need to be enabled.

In addition, a wide range of free or low-cost security tools, such as authenticator apps for MFA, affordable password managers, open-source antivirus and intrusion detection tools, and basic firewall capabilities on existing routers, can significantly improve security without major investment. Costs can also be reduced by outsourcing sensitive payment functions to PCI-compliant providers via tokenization or hosted payment pages, which limit the amount of card data a business handles and reduce compliance scope.

When budgets are tight, merchants should prioritize spending based on risk, focusing first on the controls that address their most significant threats, whether that is web security for e-commerce sites or secure card readers and network protection for brick-and-mortar stores. Small businesses can further benefit from free guidance and assistance programs offered by merchant banks, industry groups, and the PCI Security Standards Council, which help reduce consulting and implementation expenses.

Rather than attempting a costly overhaul, incremental upgrades spread over time can make compliance more manageable, especially when combined with retiring unnecessary systems. Ultimately, investing in PCI compliance is far less costly than dealing with the financial and reputational damage of a data breach, and many small businesses find that improved security leads to greater efficiency, reduced fraud, and increased customer trust.

The Benefits of Embracing PCI DSS 4.0 Compliance

Complying with a security standard might feel like doing homework because you “have to,” but there are genuine business benefits to embracing PCI DSS 4.0 compliance, especially for small merchants:

  • Preventing Breaches and Avoiding Disaster:

The most obvious benefit is a significantly reduced risk of a data breach. By following PCI 4.0’s guidelines, you are implementing strong security practices – like using MFA, encryption, and continuous monitoring – that make it much harder for attackers to succeed. This can save you from the nightmare scenario of compromised customer card data. Consider what a breach could mean: you might have to pay for forensic investigations, incur heavy fines from card brands, face potential lawsuits, and cover the cost of providing credit monitoring for affected customers.

Many small businesses never recover from a significant cyber incident. Compliance is like an insurance policy: it’s better to have controls in place than to pick up the pieces after a security disaster. In short, prevention is far cheaper and easier than dealing with a breach.

  • Avoiding Fines and Penalties:

While the primary goal of PCI DSS is security, there’s also a compliance enforcement aspect. If you are found grossly non-compliant, especially in the event of a breach, you could face fines from your acquiring bank or payment brands. Additionally, you might lose the ability to process credit cards if you’re deemed too high-risk. By staying compliant with 4.0, you keep your business in good standing with banks and avoid those penalties.

Also note that some of the new 4.0 requirements (the “future-dated” ones) have a grace period until 2025; failing to implement them by their deadline could result in non-compliance. Avoiding these situations by being proactive ensures you won’t be surprised by fees or higher transaction costs.

  • Protecting Your Reputation and Customer Trust:

Customers today are pretty aware of data breaches and identity theft. When they hand over their card or enter their payment details on your website, they’re putting trust in your business. A publicized breach can severely damage that trust – customers may take their business elsewhere, and it can be hard to win them back.

On the flip side, being able to confidently tell your customers (or display on your website/store) that you take security seriously and are PCI DSS compliant can be a selling point. It shows that even as a small business, you hold yourself to high security standards. Over time, this builds a strong reputation as a safe place to shop. It can set you apart from competitors who may not be as diligent. Trust is invaluable to customer loyalty, and security is a key factor in maintaining it.

  • Operational Improvements:

Following PCI DSS 4.0 can also inadvertently improve your overall operations. For example, the push for continuous monitoring means you’ll likely catch IT issues early (not just security issues, but possibly other system errors), which can improve uptime. The requirement for up-to-date systems may prompt you to upgrade legacy hardware or software that was slowing your business processes.

Training staff on security can also make them more aware of other aspects of their work and help prevent mistakes (for example, phishing awareness can help employees avoid clicking malicious links that could disrupt your business with malware). Many merchants find that after implementing PCI controls, they experience fewer incidents, less downtime, and more streamlined processes, which can save time and money over the long term.

  • Competitive Advantage and Partner Confidence:

As larger companies and even consumers become more security-conscious, they prefer to do business with compliant vendors. For example, a corporate client might ask if you are PCI compliant before signing a contract with you. If you can confidently say yes and even outline the strong measures you have in place thanks to PCI 4.0, it could win you business. Likewise, payment partners (such as banks and vendors) prefer working with merchants that maintain compliance, as it reduces everyone’s risk.

In some cases, being compliant might also help with other regulations or standards (PCI DSS’s best practices overlap with general cybersecurity good practices), so you’re better positioned if new laws or requirements come up. In short, security can be a selling point and a requirement in B2B relationships – by being ahead on PCI DSS 4.0, you’re positioning your business as a trustworthy and professional operation.

Conclusion

Preparing for PCI DSS 4.0 compliance in 2026 is achievable for small merchants with a straightforward, proactive approach. The updated standard strengthens security against modern threats, and steps such as multi-factor authentication, stronger passwords, regular system monitoring, and close coordination with payment partners can significantly reduce risk.

Using a practical checklist and trusted resources from the PCI Council and your payment provider helps turn compliance into manageable actions. PCI compliance is an ongoing responsibility, and treating it as part of daily operations helps build customer trust, protect sensitive data, and support long-term business stability.

Frequently Asked Questions

  1. Do all small merchants need to meet every PCI DSS 4.0 requirement?

    Not necessarily. The exact requirements depend on how you accept, process, and store card data. Many small merchants qualify for a reduced compliance scope if they use PCI-compliant payment terminals, hosted checkout pages, or tokenization that keeps card data out of their systems.

  2. What happens if a merchant is not PCI DSS 4.0 compliant in 2026?

    Merchants that fail to meet PCI DSS 4.0 requirements may face higher processing fees, monthly non-compliance penalties, increased scrutiny from banks, or account termination after a data breach. Non-compliance also increases liability if cardholder data is compromised.

  3. Can PCI DSS 4.0 compliance be handled without in-house IT staff?

    Yes. Many small businesses achieve compliance by working with PCI-compliant payment providers, managed security services, and third-party scanning vendors. Using hosted payment solutions and cloud-based tools significantly reduces technical complexity.

  4. How long does it typically take a small business to prepare for PCI DSS 4.0?

    Preparation timelines vary, but most small merchants can complete initial PCI DSS 4.0 readiness within a few weeks if systems are already modern and payment partners are compliant. Businesses with outdated hardware or unclear data flows may need additional time.

  5. Is PCI DSS 4.0 a one-time upgrade or an ongoing requirement?

    PCI DSS 4.0 is an ongoing compliance requirement. Merchants must continuously maintain controls, monitor systems, train staff, and validate compliance annually to remain in good standing and reduce security risk.