Network tokenisation has moved from an optional enhancement to a compliance requirement with hard deadlines, pricing consequences, and measurable fraud reduction. For card issuers, acquirers, merchants, and payment service providers operating in the UAE, Saudi Arabia, and the wider GCC, the window to treat this as a future initiative has closed. Mandates are live, certification milestones have been reached, and the commercial penalties for inaction are already visible in authorisation rates.

What Network Tokenisation Actually Does

Network tokenisation replaces a card's primary account number (PAN) with a scheme-issued payment token that is specific to a device, merchant, or channel. Unlike a merchant-vault token, a network token is managed by the scheme itself, which means the issuing bank can update it automatically on card reissue or expiry without any action from the merchant. The practical consequence is that reason code 54 (expired card) declines fall to near zero for tokenised credentials, and the liability for fraud on a tokenised transaction shifts to the issuing bank rather than the merchant, provided the transaction is authenticated correctly.

Visa reports that network tokenisation reduces fraud risk by as much as 28% and improves authorisation rates by 2 to 6 percentage points for card-not-present merchants. Mastercard publishes comparable figures. These are not projections; they are outcomes drawn from live transaction populations that now represent the majority of scheme e-commerce volume globally. As of Visa's Q3 2026 earnings call, CEO Ryan McInerney confirmed that 59% of Visa's global e-commerce transactions are tokenised, up from 48% in April 2025. Mastercard reports that three in five of its European e-commerce transactions now run on tokens, with Mastercard Digital Enablement Service (MDES) merchant tokenisation live across 45 European countries and territories.

The Deadline Landscape: Dates That Cannot Move

GCC operators need to map three distinct mandate timelines, two of which are already in effect.

For Mastercard, the first deadline landed this month. As of October 2026, all Credential on File (CoF) transactions must use network tokens where the credential is stored in a vault. The second deadline falls in April 2028, when guest checkout transactions must also be tokenised. The third, representing 100% of Mastercard e-commerce transactions on network tokens, falls in April 2030. Mastercard is reinforcing these deadlines with pricing changes: from 1 July 2026, it standardised rates for 3DS and MDES authentication across most European countries, replacing a fragmented country-specific structure. A further revision to the Customer Performance Development Fund pricing takes effect 1 January 2027, with four phased rate changes over three years designed explicitly to accelerate tokenisation adoption.

For Visa, the Visa Credential Enrichment Service (VCES) began applying to card-on-file transactions on 30 October 2026. VCES requires token requests for cards on file within four of Visa's geographical regions to resolve expiry exception cases, meaning acquirers and processors must now route these requests through Visa's token infrastructure rather than relying on legacy expiry-update mechanisms.

In the UAE, the Central Bank of the UAE issued Notice 3057, setting a March 2026 enforcement deadline for tokenisation and authentication standards applicable to licensed payment institutions. That deadline has passed. Firms that have not completed their compliance work are now operating outside the supervisory expectation, with associated licensing and examination risk.

GCC and MENA Context: The Region Is Moving Faster Than Expected

The regional data point that reframes the urgency is this: a white paper jointly published by Mastercard and Checkout.com on 7 May 2026 in Dubai recorded a 344.9% year-on-year surge in tokenisation transactions processed through Mastercard in the MENA region. That is not a global figure applied to the region. It is a MENA-specific measurement, and it makes MENA one of the fastest-accelerating tokenisation markets in the world by volume growth rate.

Saudi Arabia reached a separate infrastructure milestone in September 2026, when Visa received certification from the Saudi Central Bank (SAMA) for locally hosted e-commerce tokenisation infrastructure. Local hosting is material because it addresses SAMA's data residency requirements directly, removing a structural objection that some Saudi issuers had cited as a barrier to tokenisation rollout. With that certification in place, the remaining obstacles for Saudi card programmes are operational and commercial, not regulatory or technical in principle.

In the UAE, Wio Bank became the first UAE issuer to auto-enable Click to Pay for its cardholders on 6 October 2026. Click to Pay is built on EMVCo's Secure Remote Commerce specification and uses network tokens as its underlying credential layer. Wio's deployment is a reference point for other UAE issuers: it demonstrates that a locally licensed digital bank can move from integration to live auto-enablement within the current regulatory environment, without requiring a separate Central Bank approval for each cardholder enrolment.

The GCC payments market context matters because regional card programmes have historically lagged European counterparts on token adoption, partly due to lower e-commerce penetration and partly due to issuer technology constraints. Both factors have shifted materially. E-commerce penetration across the GCC accelerated sharply post-2020, and several regional issuers have completed or are completing core banking and card management system modernisation projects that make MDES and Visa Token Service (VTS) integration technically straightforward.

The Commercial Case Beyond Compliance

Compliance framing tends to produce minimum-viable implementations. The commercial case for network tokenisation justifies a more ambitious programme scope.

Authorisation rate improvement of 2 to 6 percentage points on card-not-present volume has a direct revenue value that is calculable at the transaction portfolio level. For a GCC acquirer processing $500 million annually in e-commerce volume, a 3-point authorisation rate improvement translates to $15 million in transaction value recovered per year. For issuers, the fraud liability shift on authenticated tokenised transactions reduces provisioning requirements. For merchants, the elimination of expired-card declines removes a customer attrition pathway that is disproportionately damaging in subscription and recurring billing models, which are growing across regional streaming, SaaS, and utility payment contexts.

There is also a competitive dimension. Merchants and platforms that have implemented network tokenisation are already seeing lower interchange costs in markets where schemes have introduced tokenisation-differentiated pricing. As Mastercard's January 2027 Customer Performance Development Fund revision takes effect, the pricing gap between tokenised and non-tokenised transaction populations will widen. Acquirers that cannot offer merchant clients a clear tokenisation migration path will face pressure from those that can.

What Payments Firms Should Do Now

The action set differs by role, but the immediate priorities are consistent across issuer, acquirer, and merchant operator positions.

Issuers in the UAE and Saudi Arabia should confirm their MDES and VTS integration status and verify that their token service provider agreements are in place for both schemes. Issuers that have not yet enabled automatic token refresh on card reissue should treat that as the single highest-priority technical item, given VCES is now live. Those considering Click to Pay rollout should review Wio Bank's October 2026 deployment as a local implementation reference and engage their scheme account managers for the auto-enablement configuration documentation.

Acquirers and PSPs should audit their merchant portfolios for CoF and recurring-transaction merchants specifically, as these are the populations subject to the October 2026 Mastercard mandate. Any merchant storing credentials in a vault without network token replacement is now outside mandate compliance. Acquirers should issue formal notification to affected merchants and set a remediation timeline. For merchants processing across both Mastercard and Visa rails, the VCES and MDES mandates require separate technical integration paths, and the scope of that work should not be underestimated.

Merchants with subscription or recurring billing models should prioritise token provisioning for existing card-on-file credentials before addressing new enrolment flows. The economic return on reducing expired-card declines in existing recurring populations is immediate and measurable within one billing cycle post-implementation.

For all parties, the regulatory clock in the UAE has already passed its enforcement point under CBUAE Notice 3057. Firms that have not completed their compliance documentation should engage legal and regulatory counsel to assess their current exposure and establish a remediation timeline that can be presented to the Central Bank if required.

The schemes have provided the infrastructure, published the deadlines, and quantified the commercial case. The remaining variable is execution speed. In a market where 344.9% annual growth signals that regional adoption is compressing years of transition into months, firms that have not begun implementation are not waiting for the right moment. They are falling behind counterparts that have already moved.