---
title: "DCAP explained: Boosting approval rates and reducing fraud with Visa's new program"
date: 2026-06-15T09:30:00+01:00
author: James Hogan
canonical_url: "https://www.ravelin.com/blog/visa-dcap-program-explained"
section: Blog
---
Blog /[Payments &amp; payment fraud](/resources?search=&category%5B0%5D=189241#resourceContainer "Go to Payments & payment fraud")

# DCAP explained: Boosting approval rates and reducing fraud with Visa's new program

Online payments are increasingly won or lost on decisioning quality. With DCAP, Visa is signaling that better context will be a first-class input to authorization.

15 June 2026

![DCAP explained: Boosting approval rates and reducing fraud with Visa's new program](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_blogSmall/502-DCAP-Article-image-Feature-885x505_1x.webp)

Visa is rolling out DCAP across the world, and it’s one of the more meaningful shifts in [card-not-present payments](https://www.ravelin.com/resources?search=&category%5B0%5D=189241#resourceContainer) we’ve seen in a while, promising up to 5 basis point net savings for eligible transactions.

Here’s your short yet meaningful explainer of what it means for merchants.

### What is DCAP – the Digital Commerce Authentication Program?

DCAP is Visa’s voluntary program to improve authorization performance and reduce fraud by encouraging merchants/acquirers/payment partners to share richer risk signals with issuers – ***without*** *adding checkout friction*.

Instead of treating every CNP transaction as “issuer sees very little, merchant sees a lot”, **DCAP pushes toward better data symmetry**.

###  What data does DCAP refer to?

DCAP can include device ID, IP address, email/phone, billing address, and related context that helps issuers distinguish legitimate customers from suspicious activity that could be related to fraud.

###  How does the data get shared?

There are a few different rails that DCAP can use, but two common patterns are:

1\. Within the [3D Secure](https://www.ravelin.com/solutions/3ds-product-3d-secure-server-sdks) flow (data-only/enriched authentication)

Risk and context gets attached inside the authentication message flow – often positioned as “[data-only 3DS](https://developer.ravelin.com/psp/guides/3d-secure/data-only/)”.

2\. Via a separate data-sharing API + a link key in the auth message

Risk data is sent to Visa first. Then, the authorization request references it via a match key so issuers can access the context when deciding to approve or decline.

### The benefits of DCAP and how to implement

Reasons for merchants to consider the voluntary DCAP program include potential for fraud reduction, more approvals and lower costs.

1. **Higher approval rates** (especially for good customers): DCAP enables issuers to say “yes” with more confidence – thus reducing friction.
2. **Lower fraud**: Better signals reduce blind spots.
3. **No extra step for the customer**: The goal of DCAP is *security by better data*, not more friction.
4. **Cost implications**: There are financial incentives tied to meeting data-quality requirements (so data quality starts to matter commercially, not just technically) as well as potential interchange reductions. Visa promises up to 5 basis points of savings for eligible transactions, made up of 10 basis points interchange incentive minus 5 basis points in fees.

To qualify for DCAP interchange benefits, merchants [must meet specified data quality standards](https://www.visa.co.uk/content/dam/VCOM/download/about-visa/visa-rules-public.pdf).

If you’re a merchant (or work at a PSP/acquirer), look into what applies in your locale, and keep in mind that there are different rollout dates for different regions.

It’s worth pressure‑testing:

- what risk signals you already capture reliably
- where your coverage is weak (common gaps: mobile device IDs, billing address completeness)
- how consistently those fields are passed through your payment/auth flows

Ravelin’s approach to DCAP is about making sure the right signals are captured cleanly and passed through consistently.

If you already use [Ravelin for 3DS](https://www.ravelin.com/solutions/3ds-product-3d-secure-server-sdks?token=U0d7pazof1ZRKbWeaIy5pHGfIE0BF3j-&x-craft-preview=48e0a046d53216056a30b28c2b9cbeaa2d8054568bb14649aaa8fe7141185973xbjftfhast) or for [payment fraud detection](https://www.ravelin.com/solutions/online-payment-fraud?token=U0d7pazof1ZRKbWeaIy5pHGfIE0BF3j-&x-craft-preview=48e0a046d53216056a30b28c2b9cbeaa2d8054568bb14649aaa8fe7141185973xbjftfhast), please don't hesitate to reach out to your AM to discuss.

To hear more about our data-focused, AI-first approach to payments and fraud, please [reach out to the Ravelin team](https://www.ravelin.com/contact-us).

**CNP payments are increasingly won or lost on *decisioning quality.* And DCAP is Visa signalling that better context will be a first-class input to authorization.**

![Ravelin Logo](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/ravelin-symbol-logo-transparent.webp)

## Stay up to speed

Get the latest reports, analysis and advice on fraud, payments and growing securely online in your inbox.

Subscribe 

   

## Frequently Asked Questions

**Is DCAP for Visa payments only?**

DCAP is Visa's Digital Commerce Authentication Program. However, Mastercard has also announced its own minimum data quality requirements, under the name of "Enhanced Data Standards Requirements."

**Is Mastercard's Enhanced Data Standard Requirements the same as DCAP?**

The two programs have similar goals – to encourage richer, higher-quality signals. They both push the ecosystem toward consistently providing more identifiers such as email, phone, address, etc.  
  
Mastercard's program does not incur any costs or penalties at the moment, though this may change in the future.  
  
Both programs use 3DS but DCAP offers a direct API, while Mastercard does not.

The minimum data points are currently one for Mastercard versus two for Visa, with regional nuances.

 

## Author

![James Hogan](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_avatarSmall/274718/james-hogan.webp)

James HoganSenior Product Manager – Payments Engineering

For the past 12 years, James has led product teams at iconic companies such as Ebay, Mastercard, Worldpay and Ocado, specializing in…

[More from this author](https://www.ravelin.com/author/james-hogan)

## Related content

[Blog / Payments &amp; payment fraud

### Card payment liability shift – everything you need to know to reduce chargeback burden

The knowledge you need to make the most of liability shifts and reap the benefits for your company – including saving money on chargebacks.

![Freddie burgess](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_33x33_crop_center-center_none_ns/281707/freddie-burgess.webp)Freddie Burgess,Senior Product Support Analyst](https://www.ravelin.com/blog/card-payment-liability-shift-for-chargebacks)

[Blog / Fraud analytics

### Refund abuse KPIs: How to measure and reduce refund fraud rates

What you need to know to assess and quantify refund abuse – as well as to measure whether your refund abuse solution and strategy are delivering results.

![Can](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_33x33_crop_center-center_none_ns/280078/can.webp)Can Colak,Senior Product Manager](https://www.ravelin.com/blog/how-to-measure-refund-abuse-kpis)

[Blog / Press release

### Driven by AI, customers now rival criminals for ecommerce fraud, say merchants

Global ecommerce fraud enters a new phase as losses continue to climb. Merchants now view criminals and their own customers as presenting a comparable risk, and there's a gap in AI adoption.

![Ravelin Symbol Blue 1](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_33x33_crop_center-center_none_ns/187712/Ravelin-Symbol-Blue-1.webp)Ravelin Technology](https://www.ravelin.com/blog/ravelin-fraud-survey-2026-press-release)
