The Ultimate Guide to Visa Compelling Evidence 3.0 (CE3.0)

Visa Compelling Evidence 3.0 (CE3.0) lets merchants shift fraud-dispute liability back to the issuer by matching data from a cardholder's prior undisputed purchases, and since October 17, 2025, Visa Secure and Data Only transactions can qualify automatically with no submission required.

Visa Compelling Evidence 3.0 (CE3.0) is a Visa dispute program. It lets you prove a cardholder authorized a transaction, using data from their earlier purchases. That shifts liability back to the issuer before a dispute becomes a chargeback.

Since October 17, 2025, many CE3.0-eligible transactions qualify automatically through Visa Secure or Data Only. You submit nothing.

I've disputed chargebacks and built the evidence for my own stores. Other merchants have gotten my advice on it too. Most of what they call friendly-fraud losses turn out to be CE3.0-eligible once they know to check.

This guide shows you how to tell fast whether a Visa dispute qualifies. It also covers what to send when it doesn't auto-qualify.

Key takeaways

  • CE3.0 shifts liability to the issuer when your data matches a prior sale.
  • Visa Secure transactions can qualify automatically as of October 17, 2025.
  • A qualifying dispute needs 2 data points matched to a recent sale.
  • 93% of merchants using CE3.0 rate it effective or better.
  • CE3.0 rebuts fraud codes like 10.4 and skips non-fraud codes.
  • Alerts stop many disputes early, so treat CE3.0 as a fallback.

What is Visa Compelling Evidence 3.0?

Visa Compelling Evidence 3.0 (CE3.0) is a Visa rule that lets you fight friendly-fraud disputes with matching data from a cardholder's earlier purchases. A genuine match shifts liability to the card issuer.

The match comes from a few data elements, like the customer's IP address, device ID, shipping address, and login or account ID. Visa checks those against the same cardholder's earlier undisputed purchases. A real match across that history is what makes the evidence "compelling."

Ordinary transaction records without matching identifiers don't clear the bar.

Many of these disputes are friendly fraud, where a real customer files a chargeback on a purchase they actually made. We don't redefine it here. Our friendly fraud explainer covers why it happens and how to spot it.

CE3.0 only helps with fraud-type disputes. It's the wrong tool for a merchandise-not-received or cancelled-service claim. The section on reason codes below shows which codes it covers. New to Visa disputes? Start with our Visa chargeback guide.

Summary: CE3.0 shifts liability to the issuer when your data matches a cardholder's prior purchases, and it works on fraud disputes only.

Is CE3.0 automatic now?

Since October 17, 2025, transactions authenticated through Visa Secure (3D Secure) or covered under Data Only can qualify for CE3.0 protection automatically. You submit no data at all. This is the biggest change to the program, and it is easy to miss.

The automatic path works because Visa and the issuer already hold the authentication data from the original transaction. That record replaces the matching data points you'd otherwise assemble by hand. The system reads it when the dispute comes in and applies the liability shift on its own.

That only covers transactions that carried authentication. A charge with no Visa Secure and no Data Only coverage still needs the manual CE3.0 process below. The automatic path runs alongside that manual one.

Summary: Authenticated transactions now qualify on their own. Unauthenticated ones still need the manual submission.

How does the CE3.0 evidence process work?

When a transaction doesn't auto-qualify, the manual CE3.0 process runs in two stages. A pre-dispute stage comes before a formal dispute files, and a post-dispute stage comes after a chargeback posts.

Pre-dispute evidence submission

Pre-dispute is the earlier, cheaper stage. You submit CE3.0 matching data before the cardholder's inquiry becomes a formal dispute. If the data matches, the issuer resolves the inquiry in your favor and no chargeback posts.

The catch is timing. You only get this stage if you see the dispute early, which usually means an alert reached you before the chargeback filed. Miss that window and you're into the post-dispute stage.

Post-dispute (representment) evidence submission

Post-dispute is representment. You submit the same CE3.0 evidence after the chargeback has already posted, to reverse it. The data requirements match the pre-dispute stage, but the fee has already hit and the timeline is tighter.

If the issuer rejects your representment, the case can escalate to a pre-arbitration chargeback. Costs climb and the odds narrow. That's why the pre-dispute stage matters. Winning earlier costs you less.

Which disputes qualify for CE3.0?

A dispute qualifies for CE3.0 when it's a fraud-type dispute and you can match two data points to the cardholder's prior undisputed sale. That prior sale has to fall inside the 120 to 365 day window.

Visa accepts a defined set of data elements. Each one has to match the prior transaction exactly, so a near-match Visa rejects. Here is what counts as a match:

Data elementQualifies as a matchDoes not qualify
IP addressSame IP on 2+ prior undisputed salesA different IP, or IP from only the disputed charge
Device ID or fingerprintSame device across prior purchasesA new or unrecognized device
Shipping addressSame delivery address on prior ordersA first-time or changed address
Login or account IDSame account used beforeA guest checkout with no history
Prior transaction history2+ undisputed charges in the windowFewer than 2, or all outside the window

One boundary trips most failed submissions. A first-time customer has no prior transaction to match against. So a fraud dispute on their debut purchase can't generate CE3.0 evidence at all. No history, no match, no case.

Summary: You need a fraud dispute plus two real matches from a prior sale in the 120 to 365 day window, which rules out first-time buyers.

How effective is CE3.0 at avoiding liability?

93% of merchants using CE3.0 report it's effective or very effective at avoiding liability, according to Datos Insights. That splits into 61% who call it very effective and 32% who call it effective.

Awareness is highest where it matters most. That same Datos Insights report puts CE3.0 awareness at 70% among subscription-vertical merchants. That's higher than any other vertical.

It tracks, because recurring-billing merchants face the most first-party fraud. They go looking for the tool.

Read the figure for what it is. It reflects merchants already using CE3.0 and getting results. It does not reflect the wider merchant population that has yet to hear of the program at all. Datos Insights' data shows you earn that 93% only once you're collecting the data CE3.0 matches on.

CE3.0 is a fallback, not a first line of defense

CE3.0 fights a dispute after the cardholder has already filed it.

Alerts work earlier. They stop many of those disputes before they become a chargeback. Ethoca (Mastercard) and Verifi (Visa, which operates RDR and CDRN) match a dispute to the transaction. That lets you auto-refund it before it posts.

In our dataset, of alerts with a recorded network, Ethoca takes 42.1% of alerts. RDR and CDRN, both Visa-side, make up the other 57.9%.

In our dataset, the largest specific reason code is 10.4, fraud in a card-absent environment, at roughly 11.1% of alerts with a recorded code. That's the code CE3.0 is built to rebut. So the two defenses overlap. The order you use them in decides the cost.

An alert that catches a 10.4 dispute early lets you refund it before a fee lands. CE3.0 fights it after the fee hits. Deciding which alerts to enroll in? See how the networks differ.

Alerts have a limit. They only work when a dispute triggers an active alert before it files. A dispute that fires no alert, or hits a network your alerts don't cover, still needs CE3.0.

Set up alert-based chargeback prevention first, with Ethoca and RDR as the default pair. That way, CE3.0 catches only what slips through.

Which Visa reason codes does CE3.0 help with?

CE3.0 evidence rebuts Visa's fraud-type reason codes, chiefly 10.4 (other fraud, card-absent environment). It does nothing for non-fraud codes. Those need entirely different evidence:

  • 13.1 (services not provided): asks whether you delivered the service.
  • 13.7 (cancelled recurring transaction): asks whether you honored the cancellation.

Submit CE3.0 matching data against a 13.1 dispute and you've answered a question nobody asked. Proof of a matching prior sale doesn't show you delivered the service. So check the reason code before you build the evidence. Our Visa reason codes guide has the full list.

One wrinkle changes the answer mid-process.

An issuer can re-code a disputed transaction while it's open, say from a non-fraud code to 10.4 after the cardholder amends their claim. The code that governs your submission is the one live when you submit.

Look up any code you're unsure of in our reason code lookup tool.

Summary: CE3.0 rebuts fraud codes like 10.4. Match your evidence to the live reason code, which can change mid-dispute.

How we sourced our data

The reason-code and alert-network figures here come from anonymized, aggregated alert data across merchants on the Chargeback.io platform. We counted total alerts within each category, by network and by reason code, and report them as shares of the labeled total.

They describe our platform's own alert mix, so read them as our numbers rather than an industry benchmark.

Coverage is also thinner for American Express, Discover, and JCB than for Visa and Mastercard. So any network split understates the non-Visa and non-Mastercard share.

FAQ

Can tokenized transactions count as historical for CE3.0?

Tokenized and wallet payments, like Apple Pay or Stripe Link, don't always carry the raw data elements CE3.0 matches on. Check whether your processor passes through a stable device or account identifier before you count on them.

How long do I have to respond to a CE3.0 dispute?

Visa's dispute-response deadlines apply, usually around 30 days from when the dispute is assigned. Miss the window and you forfeit the case, however strong your evidence is.

What's the difference between CE3.0 and CE2.0?

CE2.0 relied on a broad list of matching details, and CE3.0 tightened that to two data elements, one being the IP address or device ID. More disputes can meet the clearer bar.

Does CE3.0 work if I don't use 3D Secure?

Yes, but not automatically. Without Visa Secure or Data Only, you skip the automatic path and fall back to the manual process of assembling and submitting the data yourself.

Disminuya su tasa de disputas hoy

Únase a más de 800 empresas que utilizan Chargeback para evitar las devoluciones de cargo automáticamente; la configuración lleva menos de 2 minutos.