A customer disputes a recurring subscription charge as fraud months after happily paying the same charge multiple times before. Visa's Compelling Evidence 3.0 (CE3.0) standard, effective since April 2023, exists specifically for this pattern — but it has a precise evidentiary bar, and recurring-billing merchants hit a specific gap in meeting it that a one-time-purchase merchant doesn't.

What CE3.0 actually covers

CE3.0 applies to reason code 10.4 (Fraud — Card-Absent Environment) disputes. It gives merchants a defined, structured way to prove the disputed transaction was authorized by the actual cardholder by pointing to their own prior undisputed history with that same customer — rather than relying on a general narrative argument about legitimacy that Visa's dispute-resolution process might or might not find persuasive.

The core evidentiary requirement

To qualify under CE3.0, a merchant needs at least two matching data elements from a prior undisputed transaction with the same customer, where that prior transaction occurred between 120 and 365 days before the disputed one. The data elements Visa recognizes for this match include the customer's account or login ID, delivery address, device ID or device fingerprint, and IP address. Two matches from that list, on a transaction inside that specific 120-to-365-day window, is what clears the bar — fewer than two matches, or a matching transaction outside that window, does not.

Why recurring billing specifically runs into trouble here

CE3.0 does allow data captured during the initial customer-initiated setup of a recurring subscription to carry forward and support later merchant-initiated billing cycles, which sounds like it should make recurring billing easier to defend, not harder. The practical problem is that most of CE3.0's strongest data points — IP address and device ID specifically — are naturally captured only when the customer is actively present and interacting with a checkout flow. Every billing cycle after the first is processed automatically, with no customer interaction and therefore no fresh IP address or device fingerprint to capture. A recurring-billing merchant can usually supply account/login ID and delivery address reliably across cycles, but often cannot supply a second matching data point beyond those two — which is fine if account ID and address both qualify, but leaves no backup if either one is disputed or unclear.

What this means for how you should be capturing data now

If your subscription checkout captures IP address and device fingerprint at the moment of initial signup, and that signup event itself falls within the 120-to-365-day window relative to a later disputed charge, that initial signup's IP and device data may be usable as one of the two required matches even though later billing cycles didn't independently capture new IP or device data. This makes capturing and retaining IP address and device fingerprint data specifically at initial subscription signup — not just customer ID and address — meaningfully more valuable for recurring-billing merchants than it might initially seem, since that one signup event may be the only opportunity to capture those two stronger data points at all.

What happens when the evidence is accepted

When a merchant successfully submits CE3.0-qualifying evidence, Visa may prevent the chargeback from proceeding at all, or shift liability for the disputed amount to the issuing bank rather than the merchant. This is a materially better outcome than a standard dispute-response process, where a merchant is arguing a case rather than meeting a defined evidentiary bar that, once met, tends to resolve in the merchant's favor.

Building your evidence file before you need it

Don't wait for a dispute to go looking for this data. Set up your billing and CRM systems to retain, per customer, the account/login ID, delivery address, device ID or fingerprint, and IP address from every transaction — including the very first signup — and keep that data retrievable for at least the 365-day window CE3.0's evidentiary rule references. A merchant who has to reconstruct this data manually after receiving a dispute notice is working against Visa's response deadline with an incomplete picture; a merchant with this data already logged per transaction can pull a CE3.0 evidence package in minutes.

What CE3.0 does not cover

CE3.0 is specific to reason code 10.4 fraud disputes. It does not apply to disputes coded as "product not received," "product not as described," or other non-fraud reason codes, each of which has its own evidence standard entirely separate from CE3.0's data-matching approach — don't reach for a CE3.0-style two-data-point argument on a dispute that was never coded as fraud in the first place.

How this interacts with your payment processor's own dispute tools

Most payment processors and gateways (Stripe, Braintree, and similar) have their own automated fraud and dispute-evidence tools that may already be capturing some CE3.0-relevant data points without labeling them as such. Ask your processor directly whether their fraud-prevention or Radar-style tooling logs device fingerprint and IP address per transaction, and whether that data is retrievable in a format you can attach to a formal CE3.0 evidence submission — the data may already exist in your systems even if no one has connected it to this specific dispute pathway before.

Why merchants often miss the 120-to-365-day window entirely

A common mistake is submitting the customer's very first transaction as the prior undisputed transaction, assuming any prior history helps. If that first transaction happened only 30 or 60 days before the dispute, it falls outside CE3.0's required window and doesn't qualify no matter how clearly legitimate it was. Build your evidence search specifically around the 120-to-365-day range rather than simply pulling the oldest or most recent prior transaction on file.