Editor's Note:Jeremy Layton is the CEO of Verisave, a consulting firm that reviews merchant accounts on behalf of retailers, restaurants, and other businesses to identify unnecessary credit card processing fees. He and the company are based in Salt Lake City, Utah.

I have worked in the credit card processing industry for 25 years. Visa's new Commercial Enhanced Data Program (CEDP) is the biggest change I have seen during this time.

With little guidance from Visa, the industry has collaborated on its own to try to meet the new requirements. Unfortunately, some processors and gateways are already trying to cut corners. This is a mistake, and their merchant customers will pay for it.

CEDP, which took effect on October 17, completely overhauls how Visa grants Level 2 and Level 3 interchange discounts. For years, many merchants obtained these discounts by submitting—to put it kindly—creative transaction data. Gateways auto-populated data fields, and processors passed along fake invoice numbers. Everyone turned a blind eye because the data met technical requirements, even if it was fabricated.

Verisave CEO Jeremy Layton
Jeremy Layton
Image licensed via Pitchr.ai

Visa's CEDP aims to close this door. The new rules require that transaction data must come from real invoices and enterprise resource planning (ERP) systems and be genuine and legitimate. Visa is using AI/ML-based audits to verify data authenticity. If the same "invoice number" is submitted across thousands of transactions, the system flags it.

Visa must walk a tightrope here: on one hand, they have an obligation to protect issuing banks' interchange fee revenue; on the other, they also have an obligation to keep interchange fees affordable for merchants to encourage high levels of acceptance. While some of this may seem self-serving, there are also some good intentions behind CEDP.

Detailed transaction data helps Visa prevent fraud. Credit card fraud is rampant—according to a 2025 AFP survey, 79% of organizations experienced payment fraud attempts last year. Real invoice information, product details, purchase order numbers—these create verifiable audit trails that make fraudulent transactions less likely.

What troubles me is that despite CEDP's new data requirements, some processors and gateways are still looking for shortcuts by submitting randomized fake data—essentially a more sophisticated form of "dummy data"—to obtain discounted interchange fees for their clients. Visa will not tolerate this behavior indefinitely.

Visa has invested billions of dollars in fraud detection and data analytics. Their systems will eventually catch on. Give it a few months, maybe six, and they will flag randomized dummy data just as they flag duplicate or auto-filled values. When that happens, merchants relying on these workarounds will lose their discounts overnight.

The financial impact is significant. I recently spoke with a CFO whose company paid over $300,000 in additional processing fees in the second half of October due to CEDP, because they lost Level 2 and Level 3 interchange discounts overnight. November will be worse. For many B2B merchants, this is the difference between a profitable quarter and a painful one.

Merchants in trouble often have no idea this is happening. They trust their processors to handle compliance. They see "Product 3" (replacing Visa's Level 2 and Level 3) on their merchant statements and assume they are covered, not knowing that these discounted rates will disappear when Visa eventually catches on. Processors and gateways that choose quick fixes are abusing that trust.

For merchants, achieving compliance is not quick or easy. It requires integrating ERP data with payment workflows, testing connections, validating inputs, and becoming a Visa Verified Merchant. This can be a four-to-eight-week implementation process. For every month merchants delay, they pay another month of higher fees that can never be recovered.