SCA Exemptions for Subscription Rebills Without Breaking PSD2

Subscription rebills sit mostly outside strong customer authentication (SCA), yet banks still soft-decline them when merchant-initiated flags break in transit. This guide maps each exemption to its fields, its decline codes and a check you can run per merchant ID.

Subscription rebills sit mostly outside strong customer authentication (SCA), yet banks still turn some of them down with an "authenticate first" code. The cause is usually the data, not the rule. The flag that marks a rebill as merchant-initiated often never reaches the bank intact. This guide maps each exemption to the fields that carry it. It also shows the decline you see when it breaks and how to check your own gateways.

SCA exemptions are requests to skip strong customer authentication on a payment that the second Payment Services Directive (PSD2) would otherwise cover. Your acquirer (the bank that processes your card payments) or your gateway sends the request. The cardholder's bank decides. Ordinary subscription rebills need no exemption. A properly flagged merchant-initiated transaction (MIT) sits outside SCA. Exemptions matter on customer-initiated payments such as add-ons.

What is an SCA exemption, and who actually decides: merchant, gateway or issuer?

An SCA exemption is a claim, not a permission, and the issuer (the cardholder's bank) makes the final call. In its 2018 opinion, the European Banking Authority (EBA) says merchants never decide whether an exemption applies. Only the acquirer (your bank) and the issuer can apply one. Even when the acquirer claims it, the issuer can still accept, ask for authentication, or decline.

Think of it as asking for a waiver at a door the bank guards. Your gateway can knock and give a reason. The bank still decides whether to open. When the bank wants proof, it asks for a 3-D Secure (3DS) check. That check is the one-time code or app approval your customer sees. Visa's current guide says issuers always make the final decision on an exemption. Issuers may apply SCA or decline instead.

  • You, the merchant, choose which payments go out with a claim and hold the customer's mandate. You cannot apply any exemption yourself.
  • Your acquirer or gateway can apply transaction risk analysis (TRA) and low value, and it passes your flags to the card network. Its own fraud rate decides whether it may use TRA.
  • The cardholder's bank applies trusted beneficiaries and secure corporate payments, keeps the low-value counters, and accepts or refuses each claim.

PSD2 SCA exemptions cover remote card payments where both banks sit in the European Economic Area (EEA) or the UK. The UK keeps its own copy of the rules in the Financial Conduct Authority (FCA) Handbook, with thresholds in pounds. Payment providers such as Stripe apply matching UK limits to Swiss merchants.

The rulebook is changing, but the change has not landed yet. Known: the EU reached provisional agreement on PSD3 (the third Payment Services Directive) and the Payment Services Regulation (PSR) on 27 November 2025. PSD2 and its regulatory technical standards (RTS 2018/389) still govern SCA today. Unknown: the exact date the PSR applies. Sopra Steria's estimate is the first half of 2028 (H1 2028). Assumed: the MIT model survives. The agreed text requires SCA when the mandate is set up, not on each later charge.

Are subscription rebills in scope for SCA at all, or out of scope as merchant-initiated transactions?

Subscription rebills are out of scope, not exempt, when they pass the MIT test. The EBA says payee-initiated payments made under a mandate are not subject to SCA. That holds only if the payer takes no action to trigger them. Setting up that mandate through a remote channel is subject to SCA. The signup carries the authentication, and the rebills ride on it.

With an exemption, the payment falls under SCA and someone asks the bank to skip the check. With an out-of-scope payment, SCA does not apply and nobody needs to ask. Strictly, the rules contain no merchant-initiated transaction exemption. The EBA draws the same line in fraud reporting. From 1 July 2020, providers report MITs executed without SCA in their own category, not as exemptions.

A rebill qualifies as an MIT only when all four of these conditions hold. Each condition maps to a failure you can see later in your decline data.

  1. The customer gave you a mandate to start later payments, fixed or variable in amount. Billing without a mandate does not count as payee-initiated.
  2. The payment that set up the mandate was authenticated with SCA. A zero-value card check counts, but a signup that used an exemption leaves no authenticated anchor.
  3. The customer takes no action on each charge. If they click to buy with a saved card, it is a customer-initiated transaction (CIT) and back in scope.
  4. Each rebill carries the scheme's MIT flags and the ID of that first authenticated payment. Without them, the bank cannot see conditions one to three and may ask for SCA.

Stripe describes the practical result plainly. Flagging a payment as an MIT works much like requesting an exemption. The bank sends no challenge, and fraud liability does not shift to the bank. As a result, fraud chargebacks on rebills stay with you. So treat each flag as evidence you can audit.

Which exemptions can a subscription merchant realistically claim, and what are the actual thresholds?

Four exemptions matter to subscription merchants, and each fits a different payment. TRA and low value fit customer-initiated payments that do not set up a mandate, such as an in-app add-on. The recurring exemption fits fixed-amount plans on Mastercard. Trusted beneficiary works only if the cardholder added you to a trusted list at their bank. None of them replaces the MIT flag on an ordinary rebill.

Exemption or categoryWho applies itThresholdFits which paymentNote
MIT (out of scope)No one: it sits outside SCANo amount capRebills after an authenticated signupNeeds the MIT flag plus the original transaction ID on each charge.
Recurring (RTS Art 14)Acquirer claims, issuer decidesSame amount, same payeeFixed-amount plans on MastercardVisa does not support it, and a price change needs a new authenticated payment.
Transaction risk analysisAcquirer or issuer, on its own fraud rateEUR 100 / 250 / 500 at 0.13% / 0.06% / 0.01% fraudCustomer-initiated add-ons and one-off buysStripe currently offers up to EUR 250 (GBP 220 for UK and Swiss merchants).
Low valueAcquirer claims, issuer countsUp to EUR 30 (GBP 25); five payments or EUR 100 (GBP 85) since last SCASmall customer-initiated purchasesYou cannot see the counter, which spans all the card's payments.
Trusted beneficiaryIssuer onlyNo amount capCustomers who listed you at their bankRequested through EMV 3DS 2.2 or later; Stripe says banks have been slow to adopt it.
Secure corporate paymentsIssuer onlyNo amount capDedicated corporate payment processesNot a route for consumer card subscriptions.
MOTO, one-leg-out, anonymousOut of scopeNot applicablePhone orders, a bank outside the EEA or UK, anonymous prepaid cardsStill needs the right indicator; Visa warns unflagged key-entered payments may not be recognized.

Thresholds are the PSD2 RTS values in force in the EEA today. UK figures come from the FCA's version of the rules.

The low value exemption is the one most likely to surprise you, because the bank holds the counter. Say you run Lingofox, a language app selling EUR 25 lesson packs. Customers buy them in-app on a saved card. Assume the bank applies the EUR 100 cumulative limit. Assume also that the card had no other low-value payments since its last SCA. Packs one to four take the total to EUR 25, EUR 50, EUR 75 and EUR 100. The fifth takes it to EUR 125, and the bank refuses it.

The bank's running total of low-value payments since the customer last authenticated

EUR 100 limit
EUR 25
EUR 50
EUR 75
EUR 100
EUR 125
Pack 1Exempt
Pack 2Exempt
Pack 3Exempt
Pack 4Exempt
Pack 5Refused

Each pack costs EUR 25, under the EUR 30 per-payment cap. You cannot see this total.

A low-value claim on EUR 25 lesson packs holds for four payments and is refused on the fifth, because the bank's hidden running total passes EUR 100.

On Mastercard, that refusal arrives as response code 65, and the customer has to authenticate. The counter also includes the card's payments at other merchants. So the refusal can come earlier than your own count suggests. Visa's guide advises preferring TRA over low value when both qualify, for exactly this reason.

How does the transaction risk analysis exemption work, and who qualifies for it?

Transaction risk analysis (TRA) lets a regulated payment provider skip SCA on a customer-initiated payment that its real-time monitoring rates as low-risk. The provider qualifies on its own fraud rate, measured by value over a rolling 90 days. Merchants cannot apply TRA themselves. Your acquirer's portfolio-wide fraud rate decides which amount band you can use.

  • Fraud rate: under the RTS annex, the provider's rate for remote card payments must sit at or below 0.13% for payments up to EUR 100, 0.06% up to EUR 250 and 0.01% up to EUR 500.
  • Amount: the payment must fall within the band's threshold. The UK equivalents are GBP 85, GBP 220 and GBP 440.
  • Real-time analysis: the check must find no abnormal spending, unusual device, malware, known fraud scenario or abnormal location. One red flag sends the payment back to SCA.

The band you can claim depends on your provider, not on you. Stripe currently offers TRA up to EUR 250 for EEA merchants and GBP 220 for UK and Swiss merchants. Both limits sit below the EUR 500 ceiling. Checkout.com lists EUR 250 for its EU domestic transactions. UK Finance adds that an acquirer can limit TRA to low-fraud merchants. Eligibility still rests on the acquirer's total volume.

Eligibility can be withdrawn. If a provider's fraud rate exceeds the reference rate for two consecutive quarters in a band, it must stop using TRA there immediately. It may resume only after one compliant quarter and a notice to its regulator. First-party ("friendly") fraud, where the cardholder disputes their own purchase, does not count toward the rate. Fraud from manipulating the payer does count. In 2020, the EBA ruled that both banks count all fraud. Since then, Visa notes that issuers may be less willing to accept acquirer TRA. Keep your own fraud-to-sales rate per merchant ID (MID). Then you can show your acquirer your share when a band is reviewed.

What data must the gateway send for an exemption or MIT flag to be honored?

Two things must reach the bank for an MIT to be honored. The first is a flag saying what kind of stored-card payment this is. The second is the ID of the authenticated payment that set up the mandate. An exemption needs one exemption indicator in the authorization message. If any piece goes missing, the bank treats the payment as unauthenticated.

Both fields arrive

Your billingROriginal ID
sends R + ID
OrchestratorROriginal ID
passes R + ID
AcquirerROriginal ID
passes R + ID
VisaAdds MIT flag
MIT flag set
Customer's bankOut of scope

One field dropped

Your billingROriginal ID
sends R + ID
OrchestratorROriginal ID
passes R only
AcquirerRNo ID
passes R only
VisaNo MIT flag
no MIT flag
Customer's bank1A: authenticate
A Visa rebill stays out of scope only if the recurring flag and the original transaction ID both survive each hop, and one field dropped at an orchestrator turns it into a 1A decline, Visa's request to authenticate first.

On Visa, the rebill carries "R" for recurring in Field 126.13. It also carries the first payment's Transaction ID in Field 125. Think of that ID as a receipt number tying each rebill back to the signup. Visa's implementation guide says the recurring value alone does not make a payment an MIT. Only the linked original ID does. When both are present, Visa itself sets the out-of-scope flag, Tag 80, for the bank. Your acquirer cannot set Tag 80 directly. So a missing field means the bank never sees it.

Mastercard numbers its message fields as data elements (DE), subelements (SE) and subfields (SF). On Mastercard, the authorization states why SCA was skipped in DE 48 SE 22 SF 1. The codes are 01 for MIT, 02 for acquirer TRA, 03 for recurring and 04 for low value. The field is required in Europe. Each later rebill also carries the Trace ID of the initial payment in DE 48 SE 63. Stored-card indicators ride alongside the reason code. C103 marks the first subscription payment, and M103 marks each fixed-amount rebill.

SCA exemption flags travel a different path from MIT flags. Visa carries them in Field 34, with Tag 89 for TRA and Tag 87 for low value. Send one indicator per authorization. Visa passes every indicator you send to the bank, and extra indicators may lower approval rates. If you request an exemption during 3DS, repeat it in the authorization. Otherwise the claim never reaches the bank. In 3DS itself, challenge indicator 05 requests TRA. Indicators 09 and then 08 add and use a trusted-beneficiary listing.

Trusted beneficiary and 3DS-routed TRA both need version 2.2 or later of EMV 3DS (EMV stands for Europay, Mastercard and Visa), the card networks' shared 3DS standard. If your stack still runs older versions, the differences between 3DS1 and 3DS2 decide which of these requests you can send at all.

Enforcement of the TLID is still unsettled. Known: Mastercard began returning the TLID on all transactions on June 2, 2026. Unknown: how strictly banks will decline rebills without it. Adyen warns that issuers may decline. Gr4vy reports that Mastercard is not declining for it in the near term. Assumed: storing the TLID from each signup payment before October 23, 2026 costs less than rebuilding the chain afterward.

Why do issuers still soft-decline exempt rebills, and what do those decline codes mean?

Banks soft-decline flagged rebills mostly because the MIT signal arrived broken. Visa tells issuers not to send its SCA decline code, 1A, on a properly flagged MIT. So a 1A on a rebill usually means the bank did not recognize an MIT. Checkout.com names two usual causes. One is an unauthenticated first payment. The other is rebills not flagged as out of scope.

A soft decline means the bank will approve if you authenticate. A hard decline means the bank will not approve whatever you send. On a customer checkout, 1A and 65 are soft declines. On an off-session rebill they act like hard declines, because nobody is there to authenticate. Visa says you must treat a 1A you cannot authenticate as a hard decline. What you may retry depends on the soft vs hard decline split.

What you seeWhere it comes fromWhat it usually means on a rebillFirst check
1AVisa, Field 39The bank saw no valid MIT flag or original ID.Is the original Transaction ID present in Field 125?
65Mastercard, DE 39SCA required, or the older "exceeds withdrawal count limit" meaning.Read it next to the flag you sent; after a low-value claim it means the counter tripped.
130American ExpressAuthentication required.Check which stored-card flags your gateway sends to Amex.
05 Do Not Honor rising on EEA cardsVisa, rewritten from 1AA 1A converted for a non-EEA acquirer that has not activated the SCA code.Ask the acquirer whether its VisaNet parameter is active.
authentication_requiredStripeThe gateway-level form of an issuer SCA soft decline.Log outcome.network_decline_code to see the raw code.
AUTHENTICATION_REQUIREDAdyenOne label for 1A, 65, 130 and other schemes' codes.Enable "Raw acquirer result" per merchant account.
20154Checkout.comSCA soft decline, including an exemption rejected at authorization.Confirm the first payment was authenticated and rebills carry merchant_initiated.
111Global PaymentsAn authorization-only exemption request was rejected.Retry through 3DS while the customer is present.
478Visa Acceptance (CyberSource)Strong Customer Authentication Required, a soft decline.Report it apart from 203 General Decline.

Codes differ by gateway, but each one asks the same question: did the bank see a valid authentication, exemption or MIT signal?

Intermediaries can hide the signal entirely. VisaNet is Visa's processing network. If an acquirer outside the EEA has not activated the VisaNet parameter, Visa converts 1A into 05 (Do Not Honor). Code 05 is the generic code banks use when they give no reason. Visa requires acquirers to pass 1A through to merchants. A gateway that normalizes codes can still fold it into a generic decline. Mastercard's 65 is easier to miss, because its original text reads "exceeds withdrawal count limit".

The Merchant Risk Council describes the same failure from the operator side. When the first payment's network ID is not linked into later MITs, issuers fall back to "Authentication Required". This happens even though the cardholder approved the setup. The cost is the rebill itself. The customer is not in session, so nobody can step up the charge with authentication. That loss lands in your rebill approval rates as involuntary churn.

How do you verify per MID whether an exemption was applied, refused or silently dropped?

Verify each MID by reading transaction data, not the integration guide. Pull a sample of recent rebills and customer-initiated payments for each merchant ID. Then compare three things: the flag you requested, the flag the bank received, and the result the bank returned. Where they differ, something between you and the bank changed the message.

  1. Pick a cohort per MID: last month's rebills and signups, split by card brand and by the issuing bank's country.
  2. Check the anchor. Confirm each subscription's first payment was authenticated and its network ID captured; on Stripe, a null network_transaction_id on the setup charge leaves nothing to chain to.
  3. Check the chain. Confirm each rebill carries the original ID (Visa Field 125, Mastercard DE 48 SE 63) and, on Mastercard, the TLID; Stripe exposes transaction_link_id on the charge.
  4. Check the claim. Log which exemption was requested per payment; Adyen returns additionalData.scaExemptionRequested and offers a 3D Secure Authentication report per merchant account.
  5. Check the outcome. Log what the bank applied separately from what you requested, using fields such as Stripe's exemption_indicator or Worldpay's honored, outOfScope, rejected or unknown result.
  6. Check the raw code. Turn on raw issuer responses so 1A and 65 are not hidden behind a generic label; on Adyen that is the "Raw acquirer result" setting.

Stripe's Charge object fills network_transaction_id only when the network returns one. That makes the setup charge a quick test. On Visa, ask your acquirer to expose the Field 34 response values. A value of 2 means honored, and 3 means not honored. Tag 8C can add the bank's reason, such as "did not meet the exemption criteria".

Where the data is invisible, ask for a transcript. Spreedly, for example, sends stored-credential data to only a select number of gateways. If one of the two required fields is missing, Spreedly still processes the payment. It leaves out all stored-credential data and returns no error. The raw gateway request transcript shows what actually left your system.

When should you stop claiming an exemption and step up to 3DS, and what happens to liability?

Stop claiming an exemption once the bank has refused it. Step up to authentication in advance where refusals cluster. After a 1A, Visa forbids resubmitting with a different exemption flag. You must authenticate first. On customer checkouts, completed SCA shifts fraud liability to the bank. On rebills you cannot step up, so the fix is the data chain.

  1. The bank returned 1A or 65 on a customer checkout: retry once through 3DS while the customer is present. Adyen does this automatically unless executeThreeD is set to false.
  2. The card was issued in France: send exemptions through EMV 3DS. Since 10 March 2025, French issuers soft-decline direct-to-authorization exemptions on customer-initiated payments.
  3. One bank identification number (BIN) range refuses an unusual share of your TRA claims: route those through 3DS. Visa reports 3DS-routed TRA had a challenge rate three times lower than typical EMV 3DS and approval 1.5% to 3% higher than direct authorization.
  4. The customer changed card details, or a fixed-amount plan changed price: take a new authenticated payment. Mastercard's gateway requires one in both cases.
  5. A rebill got 1A or 65: do not resend the same data. Fix the flags or the anchor, then bring the customer back on-session if the chain cannot be repaired.

Liability follows who asked. When you or your acquirer request an exemption and the bank accepts, fraud liability stays with you. When the bank applies an exemption inside 3DS, or the customer completes SCA, liability shifts to the bank. Under Visa's rules, a rebill sent without 3DS sits at acquirer liability, marked by electronic commerce indicator (ECI) 07. Your acquirer passes that liability to you. If you want chargeback protection instead of an exemption, send a 3DS request and let the bank choose.

On a customer checkout, you trade a possible challenge against a possible refusal. A challenge moves fraud liability to the bank. A refused exemption costs you a retry anyway. For the retry mechanics, see how to retry a soft decline with 3DS. For what the customer sees, see how 3D Secure authentication works. Then run the evidence checklist below for each MID.

  • Each subscription's first payment was authenticated with SCA, and its network transaction ID is stored.
  • Each rebill is flagged as an MIT with the original ID, and carries no exemption flag.
  • Mastercard rebills carry both the Trace ID and the TLID before October 23, 2026.
  • Customer-initiated authorizations carry one exemption indicator, mirrored from 3DS where it was requested there.
  • Raw issuer codes such as 1A and 65 are logged per MID, not only the gateway's label.
  • Requested and applied exemptions are logged as separate fields for each payment.
  • Your own fraud-to-sales rate per MID is ready for an acquirer TRA review.
  • Card changes and brand switches trigger a new authenticated payment before the next rebill.

Frequently Asked Questions

Who decides whether an SCA exemption is granted?

The cardholder's bank decides whether an SCA exemption is granted. Your acquirer or gateway can request one, but the EBA and Visa both say the issuer makes the final decision. It can accept the claim, ask the customer to authenticate through 3DS, or decline the payment outright.

What happens when an issuer rejects an exemption request?

The payment comes back as a soft decline asking for authentication, shown as 1A on Visa and 65 on Mastercard. If the customer is present, you retry through 3DS. If it is an off-session rebill, nobody can authenticate, so Visa says the decline must be treated as a hard decline.

Are recurring subscription payments exempt from SCA?

Most recurring subscription payments are out of scope rather than exempt. Once the first payment is authenticated and the customer gives you a mandate, later merchant-initiated charges do not need SCA. Each rebill still has to carry the MIT flag and the original transaction ID, or the bank may ask for authentication.

What is the difference between an SCA exemption and an out-of-scope transaction?

An exemption is a payment SCA covers, where someone asks the bank to skip the check. An out-of-scope payment is one SCA does not cover, such as a properly flagged MIT or a phone order. Exemptions can be refused, while out-of-scope payments depend on correct flags instead of a claim.

What is the transaction risk analysis exemption and who qualifies for it?

TRA lets a payment provider skip SCA on a low-risk, customer-initiated payment. Only a regulated provider, meaning the acquirer or the issuer, qualifies on its own fraud rate: 0.13% up to EUR 100, 0.06% up to EUR 250 and 0.01% up to EUR 500. Merchants cannot qualify on their own numbers.

Do you still get liability shift if an SCA exemption is applied?

No liability shift applies when you or your acquirer requested the exemption. If the bank accepts that request, fraud chargeback liability stays with you. Liability moves to the bank only when it applies the exemption itself inside 3DS, or when the customer completes SCA.

Related articles

TC40 Fraud Reports: What They Are and How to See Yours

A TC40 fraud report is filed by the cardholder's bank, counted by Visa, and acted on by your acquirer, all without you being told. Here is how the record works, how to obtain your own counts, and which controls actually reduce issuance instead of just shifting cost.

PCI DSS Compliance Checklist for Merchants in 2026: SAQ Selector, Evidence Pack, and Year-Round Calendar

The complete PCI DSS compliance checklist for 2026. Pick the right SAQ, scope your CDE, and stay audit-ready all year under PCI DSS v4.0.1.

How a Pre-Authorization Charge Can Improve Customer Experience

Learn how pre-authorization charges help prevent revenue leaks, reduce chargebacks, and turn payment uncertainty into predictable cash flow for high-risk merchants.