Skip to content

How Card Scheme Mandates Reach You: Release Cycles and Notice

Amex publishes its change cadence and notice period. Visa and Mastercard largely do not. How operators actually find out what changes and when.

PB
By Shaun Toh
Last updated: September 12, 2026 Last reviewed: September 1, 2026
TL;DR

The compliance date your acquirer quotes almost never comes from a scheme document you can read. Amex states its cadence and notice period publicly. For Visa and Mastercard, your PSP's release guide is the primary source in practice.

Operator Summary

Card schemes change their rules on a schedule, but only American Express publishes that schedule and a notice period in a document anyone can read: technical specifications twice a year in April and October, with certification requirements communicated six months before publication. Visa runs a real spring and autumn release pattern, but Visa states that its Business News articles are not public materials, so the pattern is visible to most operators only through PSP release guides. Mastercard's rulebook carries a 2 June 2026 edition date, yet its 2025 and 2026 mandate effective dates land in February, June, July and October rather than in two clean windows. The practical consequence is that for Visa and Mastercard your acquirer or PSP is the primary source of mandate dates, not the scheme.

Somewhere in the next six months your acquirer will email you a compliance date. A field becomes mandatory, a threshold tightens, a programme changes shape, and you have until a stated date to be ready.

The reasonable next question is: where did that date come from, and how do I see the next one coming?

For most operators the honest answer is uncomfortable. You cannot read the change stream for Visa or Mastercard. The standing rulebooks are public. The operational traffic that carries dated mandates is not. What you can read is your PSP's summary of it — which makes your PSP, not the scheme, the primary source in practice.

That is worth stating plainly, because a great deal of planning advice assumes a scheme calendar exists that you can consult. One scheme publishes one. The two that matter most to volume do not.

What is actually public

DocumentStatusCurrent edition
Visa Core Rules and Product and Service RulesPublic PDF18 April 2026
Mastercard RulesPublic PDF2 June 2026
Amex Merchant Regulations InternationalPublic PDFApril 2026
Amex Notice of Specification ChangePublic PDFCurrent
Visa Business NewsNot public — Visa states the articles are not public materials
Mastercard Announcements (AN bulletins)Requires sign-in

The split matters more than it looks. The public rulebooks tell you what the rules are. The gated material tells you what is changing and when. Operators need the second and can generally only obtain the first.

American Express is the exception, and it is instructive

Amex publishes what the others do not. From its own Notice of Specification Change documentation:

American Express Network publishes the Technical Specifications twice a year, in April and October.

Certification requirements ... will be communicated six (6) months prior to publication in a Notice of Specification.

Changes published in April will be incorporated into the October Technical Specifications. Changes published in October will be incorporated into the April Technical Specifications.

American Express will publish any changes occurring outside of the April and October publication schedule in Technical Bulletins.

That is a complete, public, plannable contract: a fixed cadence, a stated notice period, a defined mechanism for out-of-cycle changes, and a rule for how changes roll into the next edition.

Amex is a fraction of most operators' volume. But it demonstrates that a scheme can publish this, which reframes the Visa and Mastercard position as a choice about disclosure rather than an inherent property of how card schemes work.

Visa: a real pattern, visible mostly through other people's documents

Visa does run release periods. The clearest public description of them found in the sources reviewed comes from a PSP, not from Visa:

The card networks (Visa, Mastercard, Amex, Discover, etc.) introduce and make updates to their operating rules throughout the year. Most of the changes come during two release periods – Spring and Fall.

Mandate effective dates bear this out, clustering around April and October, with an additional January cluster for some fee and programme items.

What could not be established from Visa's own public material is a stated minimum notice period or a published calendar of release dates. The documents that would carry that are Visa Business News and the technical implementation guides. Visa's own digest page states that Business News articles are not public materials, and PaymentBrief found no public copy of the implementation guides. Visa does publish a lighter public merchant-facing digest, which carries real dated entries, but it is a digest rather than the operational change stream.

This is a limitation of what is published, not a finding that no such notice commitment exists. It is, though, exactly the situation an operator has to plan inside: if you cannot read the commitment, you cannot rely on it, and your acquirer's notice becomes the operative date.

Industry commentary on at least one recent Visa programme change described merchant communication as limited and, in many cases, delayed. Treat that as a planning assumption rather than an accusation: build your compliance runway from the date your PSP tells you, not from a date you assume the scheme guaranteed.

Mastercard: the tidy story is only half true

The commonly repeated description is that Mastercard runs a June and October rhythm. The evidence is genuinely mixed and worth reporting as mixed.

For it: the Mastercard Rules document is reported to have carried a June edition date across several years, including a 2 June 2026 edition. The current edition, dated 2 June 2026, confirms the anchor for this year; the earlier years' June dates are as reported by industry sources.

Against it: the Mastercard mandate effective dates collected below for 2025 and 2026 land in June, July, October and February — not two clean windows. Industry commentary explicitly notes that Mastercard's release habit does not mirror Visa's spring/autumn symmetry.

Mastercard also maintains more than one rules manual on separate schedules — the Switch Rules Manual carries its own edition date — so "the Mastercard release" is not a single event even in principle.

The honest operator conclusion: treat Mastercard as a rolling mandate schedule with a June rulebook anchor, and do not build a planning calendar around an assumed symmetric two-release year. Take dates from your processor.

The dates, so you can see the shape

Asserting that Mastercard's dates are scattered is worth less than showing them. These are effective dates collected for 2025 and 2026:

SchemeChangeEffective
MastercardAuthorisation-identification tightening17 June 2025
MastercardPIF fee changes1 July 2025
MastercardTransaction Link Identifier (DE 105) mandate17 October 2025
MastercardCredential Continuity Programme, Asia-PacificFebruary 2026
VisaCEDP participation fee introduced11 April 2025
VisaSmall-business Level 2 rate increase24 January 2026
VisaLevel 2 interchange programme discontinued17 April 2026

Two things fall out of this. Mastercard's four dates land in June, July, October and February — not a two-window year. Visa's three land in April, January and April — consistent with a spring anchor plus a January fee cluster, which is the pattern the PSP release guides describe.

Note also what the January and April Visa entries are: interchange programme changes, not technical mandates. A large share of what reaches merchants as "a scheme change with a date" is pricing and programme structure rather than a code change, and it arrives on the same release machinery. If your compliance process only routes technical mandates to engineering and never routes programme changes to commercial, half the release stream lands nowhere.

These dates come from PSP release guides and industry trackers rather than from scheme bulletins, which is the point of the article: the calendar is reconstructable from downstream sources, and not otherwise.

The chain that actually delivers your date

The route from a scheme decision to your engineering backlog runs through several hands:

  1. Scheme issues a bulletin to licensed participants — a Visa Business News item, a Mastercard AN.
  2. Processor or acquirer reviews it, assesses which of its own systems are affected and which clients are in scope. One large processor documents precisely this and states it will email clients.
  3. PSP surfaces the applicable subset, often in a periodic release guide.
  4. You receive a summary, usually already filtered to what someone else believed applied to you.

Every hop can add interpretation or lose detail. The filtering at step 3 is genuinely useful — most mandates do not apply to most merchants — but it means the thing you receive is a judgement about relevance, not the source document.

Two practical habits follow. If a date carries real commercial weight, ask your acquirer for the underlying bulletin reference, not the summary. And confirm the regional variant, because the same mandate frequently carries different dates and thresholds in different regions — a Visa acquirer-monitoring programme keeps a higher merchant threshold in one region than the others, and one Mastercard credential programme took effect in the United States roughly a year ahead of its Asia-Pacific date.

If you operate across regions, a single global compliance date in your plan is usually wrong.

Non-compliance, and where it shows up

Assessments for missed mandates are real but poorly documented publicly. Industry sources describe a Visa structure beginning around $1,000 for a first offence and escalating substantially for repeat or uncorrected violations, with monthly escalation after a prolonged period and, ultimately, loss of processing privileges.

Those figures are industry-reported and were not confirmed against Visa primary text. Treat them as an order of magnitude, not a schedule.

The more useful operational point is where the money surfaces. Scheme assessments reach you through your acquirer under the indemnification terms of your acquiring agreement, and they appear on your statement as a pass-through line rather than as anything labelled "mandate fine". If you cannot decompose your statement, you will not notice you are paying one — which is the practical argument for being able to read a processing statement line by line.

Programme-specific thresholds and their remediation paths are a separate subject, covered for Visa in the acquirer monitoring programme reference and for Mastercard in the merchant monitoring reference. This article is about how you learn a date, not about any individual programme.

Other schemes

Discover, JCB and UnionPay release cadences were not found in the sources reviewed — but the gate itself is visible. Discover names its own EASI (Enablement, Acceptance Support Info-center) Portal, open by registration, as the place technical specifications live. JCB routes partner and technical material through JCB Partner Online, a login-gated portal hosted on Salesforce. UnionPay International's merchant navigation links to a Merchant Service Platform that redirects unauthenticated visitors to a sign-in page. None of the three portals were accessible without an account, so no cadence, cycle or frequency is asserted for any of them — the operator action is to ask your acquirer for portal access or the underlying bulletin, not to assume the Visa or Mastercard rhythm transfers.

What to actually do

Given the disclosure asymmetry, a workable operator posture looks like this:

Treat your PSP's release guide as a primary source, and read it on a schedule. Braintree, SoFi and others publish these publicly, and they are frequently more concrete about dates than anything you can get from the scheme. Reading a competitor PSP's public release guide is a legitimate and underused way to sanity-check your own provider's notice.

Build a standing compliance runway rather than reacting per mandate. If Visa's real pattern is spring and autumn and Mastercard's is rolling, the planning unit is a recurring quarterly review, not a project per bulletin.

Ask for bulletin references on anything commercially material. The summary is someone's judgement; the reference is checkable.

Confirm regional variants per acquiring relationship. Not once, globally.

Assume the notice you get is the notice you have. For Visa and Mastercard, no publicly readable minimum notice commitment was found. Plan as though your acquirer's email is the start of the clock, because operationally it is.

The uncomfortable summary is that the change calendar for the two schemes carrying most of your volume is not something you can look up. Amex proves it could be. Until that changes, the workflow above is the honest substitute — and knowing that it is a substitute, rather than assuming you have missed a public calendar somewhere, is itself worth having.

Sources & methodology (12)

American Express publishes its Technical Specifications twice a year in April and October, communicates certification requirements six months prior to publication, cross-incorporates April changes into the October specification and vice versa, and publishes out-of-cycle changes in Technical Bulletins.

April and October; 6 months notice

This is the only scheme-stated cadence and notice period found in the sources cited here.

Checked:

Visa Core Rules and Visa Product and Service Rules are published publicly; edition dated 18 April 2026.

18 April 2026 edition

No clause-level quotation on the amendment or notice process is taken from this document; the release-cadence findings in this article are carried by the PSP and scheme sources below.

Checked:

Mastercard Rules are published publicly as a PDF; the current edition is dated 2 June 2026 and runs to 503 pages.

2 June 2026 edition

The article does not rest any conclusion on this document's contents — the scattered-dates finding is carried by the dated mandate table, which is sourced from PSP release guides and industry trackers.

Checked:

Visa's own Merchant Business News Digest page states: 'Actual Visa Business News articles are not public materials and should not be treated as public documents, e.g., posting on merchant websites, etc.' The digest itself is public and carries dated merchant-facing entries.

Visa Business News is not public, per Visa

Checked:

Card networks introduce operating-rule updates throughout the year, with most changes arriving in two release periods described as spring and autumn. PSP release guides list dated Visa and Mastercard fee and programme changes.

Directly quoted. This is the clearest public statement of the Visa release rhythm found, and it comes from a PSP rather than from Visa.

Checked:

A processor documents both the cadence at which card networks announce mandates and its own role in the chain: 'Card networks communicate these mandates through technical newsletters four times a year. SoFi Tech Solutions reviews these mandates and updates its systems and documentation to align with them.' The same guide names Mastercard, Visa, Discover, STAR and Pulse as networks that publish mandates for issuers, processors and acquirers.

A processor-published guide, quoted directly. It is the clearest public statement found of how often networks announce mandates — four technical newsletters a year — and it is a processor describing the networks' cadence rather than a scheme stating its own.

Checked:

Mastercard Announcements are distributed through a portal requiring authentication; an unauthenticated request returns a sign-in page rather than content.

The portal presents a sign-in page rather than content. This is a statement about access, not about whether the content exists.

Checked:

Regional variation in mandate application is attested: Visa acquirer-monitoring merchant thresholds differ by region, and a Mastercard credential programme took effect in the US in April 2025 against February 2026 in Asia-Pacific.

Industry-sourced. Programme-specific thresholds are covered in PaymentBrief's VAMP and Mastercard monitoring references and are not restated here.

Checked:

Discover names its own Enablement, Acceptance Support Info-center (EASI) Portal as the place technical specifications and enablement materials live, and gates it behind registration: the page's call to action reads 'Register for EASI Portal access'.

This page names the portal and its access requirement; it does not state a release cadence or notice period, and none is claimed here.

Checked:

JCB's merchant-acquiring page links its technical/partner content — specifications documents, promotional materials, monthly reports — to 'JCB Partner Online,' a dedicated partner site reached only after logging in; the page's login link resolves to a Salesforce-hosted address (jcb-partner-online.my.salesforce-sites.com).

This page names the portal and shows it is login-gated; it does not state a release cadence, and none is claimed here.

Checked:

UnionPay International's main site links to a 'Merchants Service Platform' from its navigation; that link (merchant.unionpayintl.com) redirects an unauthenticated visitor through to a dedicated sign-in page at merchant.unionpayintl.com/msp/login.htm.

The page is UnionPay's own merchant-platform login screen. It does not state a release cadence, and none is claimed here.

Checked:

Source types explained in our Methodology.

Shaun Toh By Shaun Toh · Director, Digital Payments · Razer

More Psp And Infrastructure briefings