Network tokenisation has moved from an optional enhancement to a compliance requirement with hard deadlines, pricing consequences, and measurable fraud reduction. For card issuers, acquirers, merchants, and payment service providers operating in the UAE, Saudi Arabia, and the wider GCC, the window to treat this as a future initiative has closed. Mandates are live, certification milestones have been reached, and the commercial penalties for inaction are already visible in authorisation rates.
What Network Tokenisation Actually Does
Network tokenisation replaces a card's primary account number (PAN) with a scheme-issued payment token that is specific to a device, merchant, or channel. Unlike a merchant-vault token, a network token is managed by the scheme itself, which means the issuing bank can update it automatically on card reissue or expiry without any action from the merchant. The practical consequence is that reason code 54 (expired card) declines fall to near zero for tokenised credentials, and the liability for fraud on a tokenised transaction shifts to the issuing bank rather than the merchant, provided the transaction is authenticated correctly.
Visa reports that network tokenisation reduces fraud risk by as much as 28% and improves authorisation rates by 2 to 6 percentage points for card-not-present merchants. Mastercard publishes comparable figures. These are not projections; they are outcomes drawn from live transaction populations that now represent the majority of scheme e-commerce volume globally. As of Visa's Q3 2026 earnings call, CEO Ryan McInerney confirmed that 59% of Visa's global e-commerce transactions are tokenised, up from 48% in April 2025. Mastercard reports that three in five of its European e-commerce transactions now run on tokens, with Mastercard Digital Enablement Service (MDES) merchant tokenisation live across 45 European countries and territories.
The Deadline Landscape: Dates That Cannot Move
GCC operators need to map three distinct mandate timelines, two of which are already in effect.
For Mastercard, the first deadline landed this month. As of October 2026, all Credential on File (CoF) transactions must use network tokens where the credential is stored in a vault. The second deadline falls in April 2028, when guest checkout transactions must also be tokenised. The third, representing 100% of Mastercard e-commerce transactions on network tokens, falls in April 2030. Mastercard is reinforcing these deadlines with pricing changes: from 1 July 2026, it standardised rates for 3DS and MDES authentication across most European countries, replacing a fragmented country-specific structure. A further revision to the Customer Performance Development Fund pricing takes effect 1 January 2027, with four phased rate changes over three years designed explicitly to accelerate tokenisation adoption.
For Visa, the Visa Credential Enrichment Service (VCES) began applying to card-on-file transactions on 30 October 2026. VCES requires token requests for cards on file within four of Visa's geographical regions to resolve expiry exception cases, meaning acquirers and processors must now route these requests through Visa's token infrastructure rather than relying on legacy expiry-update mechanisms.
In the UAE, the Central Bank of the UAE issued Notice 3057, setting a March 2026 enforcement deadline for tokenisation and authentication standards applicable to licensed payment institutions. That deadline has passed. Firms that have not completed their compliance work are now operating outside the supervisory expectation, with associated licensing and examination risk.
GCC and MENA Context: The Region Is Moving Faster Than Expected
The regional data point that reframes the urgency is this: a white paper jointly published by Mastercard and Checkout.com on 7 May 2026 in Dubai recorded a 344.9% year-on-year surge in tokenisation transactions processed through Mastercard in the MENA region. That is not a global figure applied to the region. It is a MENA-specific measurement, and it makes MENA one of the fastest-accelerating tokenisation markets in the world by volume growth rate.
Saudi Arabia reached a separate infrastructure milestone in September 2026, when Visa received certification from the Saudi Central Bank (SAMA) for locally hosted e-commerce tokenisation infrastructure. Local hosting is material because it addresses SAMA's data residency requirements directly, removing a structural objection that some Saudi issuers had cited as a barrier to tokenisation rollout. With that certification in place, the remaining obstacles for Saudi card programmes are operational and commercial, not regulatory or technical in principle.
In the UAE, Wio Bank became the first UAE issuer to auto-enable Click to Pay for its cardholders on 6 October 2026. Click to Pay is built on EMVCo's Secure Remote Commerce specification and uses network tokens as its underlying credential layer. Wio's deployment is a reference point for other UAE issuers: it demonstrates that a locally licensed digital bank can move from integration to live auto-enablement within the current regulatory environment, without requiring a separate Central Bank approval for each cardholder enrolment.
The GCC payments market context matters because regional card programmes have historically lagged European counterparts on token adoption, partly due to lower e-commerce penetration and partly due to issuer technology constraints. Both factors have shifted materially. E-commerce penetration across the GCC accelerated sharply post-2020, and several regional issuers have completed or are completing core banking and card management system modernisation projects that make MDES and Visa Token Service (VTS) integration technically straightforward.
The Commercial Case Beyond Compliance
Compliance framing tends to produce minimum-viable implementations. The commercial case for network tokenisation justifies a more ambitious programme scope.
Authorisation rate improvement of 2 to 6 percentage points on card-not-present volume has a direct revenue value that is calculable at the transaction portfolio level. For a GCC acquirer processing $500 million annually in e-commerce volume, a 3-point authorisation rate improvement translates to $15 million in transaction value recovered per year. For issuers, the fraud liability shift on authenticated tokenised transactions reduces provisioning requirements. For merchants, the elimination of expired-card declines removes a customer attrition pathway that is disproportionately damaging in subscription and recurring billing models, which are growing across regional streaming, SaaS, and utility payment contexts.
There is also a competitive dimension. Merchants and platforms that have implemented network tokenisation are already seeing lower interchange costs in markets where schemes have introduced tokenisation-differentiated pricing. As Mastercard's January 2027 Customer Performance Development Fund revision takes effect, the pricing gap between tokenised and non-tokenised transaction populations will widen. Acquirers that cannot offer merchant clients a clear tokenisation migration path will face pressure from those that can.
What Payments Firms Should Do Now
The action set differs by role, but the immediate priorities are consistent across issuer, acquirer, and merchant operator positions.
Issuers in the UAE and Saudi Arabia should confirm their MDES and VTS integration status and verify that their token service provider agreements are in place for both schemes. Issuers that have not yet enabled automatic token refresh on card reissue should treat that as the single highest-priority technical item, given VCES is now live. Those considering Click to Pay rollout should review Wio Bank's October 2026 deployment as a local implementation reference and engage their scheme account managers for the auto-enablement configuration documentation.
Acquirers and PSPs should audit their merchant portfolios for CoF and recurring-transaction merchants specifically, as these are the populations subject to the October 2026 Mastercard mandate. Any merchant storing credentials in a vault without network token replacement is now outside mandate compliance. Acquirers should issue formal notification to affected merchants and set a remediation timeline. For merchants processing across both Mastercard and Visa rails, the VCES and MDES mandates require separate technical integration paths, and the scope of that work should not be underestimated.
Merchants with subscription or recurring billing models should prioritise token provisioning for existing card-on-file credentials before addressing new enrolment flows. The economic return on reducing expired-card declines in existing recurring populations is immediate and measurable within one billing cycle post-implementation.
For all parties, the regulatory clock in the UAE has already passed its enforcement point under CBUAE Notice 3057. Firms that have not completed their compliance documentation should engage legal and regulatory counsel to assess their current exposure and establish a remediation timeline that can be presented to the Central Bank if required.
The schemes have provided the infrastructure, published the deadlines, and quantified the commercial case. The remaining variable is execution speed. In a market where 344.9% annual growth signals that regional adoption is compressing years of transition into months, firms that have not begun implementation are not waiting for the right moment. They are falling behind counterparts that have already moved.
انتقل توكن الشبكة من كونه تحسيناً اختيارياً إلى متطلب امتثال مقرون بمواعيد نهائية صارمة، وتداعيات تسعيرية، وانخفاض قابل للقياس في الاحتيال. بالنسبة لمُصدري البطاقات والمُحيلين والتجار ومزودي خدمات الدفع العاملين في الإمارات العربية المتحدة والمملكة العربية السعودية ودول مجلس التعاون الخليجي الأوسع، فقد أُغلق باب التعامل مع هذا الملف باعتباره مبادرة مستقبلية. الالتزامات الإلزامية سارية، وبلغت المعالم التقنية حد الاعتماد، والعقوبات التجارية على التقاعس باتت ظاهرة فعلاً في معدلات التفويض.
ما الذي يفعله توكن الشبكة فعلياً
توكن الشبكة يستبدل الرقم الأساسي لحساب البطاقة (PAN) برمز دفع تُصدره شبكة البطاقات، مخصص لجهاز أو تاجر أو قناة بعينها. على خلاف رمز مخزن التاجر، يُدار رمز الشبكة من قِبل الشبكة ذاتها، مما يتيح للبنك المُصدر تحديثه تلقائياً عند إعادة إصدار البطاقة أو انتهاء صلاحيتها دون أي تدخل من التاجر. والنتيجة العملية لذلك أن الرفض وفق رمز السبب 54 (بطاقة منتهية الصلاحية) ينخفض إلى ما يقارب الصفر بالنسبة للبيانات الرمزية، وتنتقل المسؤولية عن الاحتيال في المعاملات الرمزية إلى البنك المُصدر بدلاً من التاجر، شريطة أن تكون المعاملة مُصادقاً عليها بصورة صحيحة.
تُفيد Visa بأن توكن الشبكة يقلل مخاطر الاحتيال بنسبة تصل إلى 28% ويُحسّن معدلات التفويض بمقدار 2 إلى 6 نقاط مئوية للتجار الذين لا يشترطون حضور البطاقة. وتنشر Mastercard أرقاماً مماثلة. وهذه ليست توقعات، بل نتائج مستخلصة من مجموعات معاملات فعلية باتت تمثل الغالبية العظمى من حجم التجارة الإلكترونية عبر الشبكات على مستوى العالم. وفي مكالمة نتائج Visa للربع الثالث من 2026، أكد الرئيس التنفيذي Ryan McInerney أن 59% من معاملات التجارة الإلكترونية العالمية لـ Visa باتت مرمّزة، ارتفاعاً من 48% في أبريل 2025. وتُفيد Mastercard بأن ثلاثة من كل خمس معاملات تجارة إلكترونية أوروبية تجري الآن عبر الرموز، مع تفعيل Mastercard Digital Enablement Service (MDES) لترميز التجار في 45 دولة وإقليماً أوروبياً.
مشهد المواعيد النهائية: تواريخ لا تقبل التأجيل
يتعين على المشغّلين في دول مجلس التعاون الخليجي رسم خريطة لثلاثة جداول زمنية منفصلة للالتزامات الإلزامية، اثنان منها ساريان فعلاً.
بالنسبة لـ Mastercard، حلّ أول موعد نهائي هذا الشهر. اعتباراً من أكتوبر 2026، يجب أن تستخدم جميع معاملات Credential on File (CoF) رموز الشبكة حيثما كانت بيانات الاعتماد مخزنة في مستودع بيانات. ويحل الموعد النهائي الثاني في أبريل 2028، عندما يجب أن تكون معاملات الدفع كزيارة أيضاً مُرمَّزة. أما الثالث، الذي يمثل 100% من معاملات التجارة الإلكترونية عبر Mastercard على رموز الشبكة، فيحل في أبريل 2030. وتُعزز Mastercard هذه المواعيد بتغييرات في التسعير: اعتباراً من 1 يوليو 2026، وحّدت الأسعار لمصادقة 3DS وMDES عبر معظم الدول الأوروبية، محلّة هيكلاً مجزأ قائماً على دول بعينها. ويدخل تعديل إضافي على تسعير Customer Performance Development Fund حيز التنفيذ في 1 يناير 2027، مع أربعة تغييرات مرحلية في الأسعار على مدى ثلاث سنوات مصممة صراحةً لتسريع اعتماد الترميز.
بالنسبة لـ Visa، بدأ تطبيق Visa Credential Enrichment Service (VCES) على معاملات البطاقة المحفوظة اعتباراً من 30 أكتوبر 2026. يشترط VCES طلبات رمز للبطاقات المحفوظة ضمن أربع مناطق جغرافية لـ Visa لمعالجة حالات استثناء انتهاء الصلاحية، مما يعني أن المُحيلين والمعالجين ملزمون الآن بتوجيه هذه الطلبات عبر البنية التحتية للرمز التابعة لـ Visa بدلاً من الاعتماد على آليات تحديث انتهاء الصلاحية القديمة.
في الإمارات العربية المتحدة، أصدر مصرف الإمارات العربية المتحدة المركزي الإشعار رقم 3057، محدداً موعد إنفاذ مارس 2026 لمعايير الترميز والمصادقة المطبقة على مؤسسات الدفع المرخصة. وقد مضى ذلك الموعد. والشركات التي لم تستكمل أعمال الامتثال لديها تعمل الآن خارج التوقع الرقابي، مع ما يترتب على ذلك من مخاطر تتعلق بالترخيص والفحص الرقابي.
سياق دول مجلس التعاون الخليجي والشرق الأوسط وشمال أفريقيا: المنطقة تتحرك بوتيرة أسرع مما كان متوقعاً
نقطة البيانات الإقليمية التي تُعيد صياغة مستوى الإلحاح هي التالية: سجّلت ورقة بيضاء نشرتها مشتركةً Mastercard وCheckout.com في 7 مايو 2026 في دبي ارتفاعاً بنسبة 344.9% على أساس سنوي في معاملات الترميز المُعالجة عبر Mastercard في منطقة الشرق الأوسط وشمال أفريقيا. وهذا ليس رقماً عالمياً مُسقطاً على المنطقة، بل هو قياس خاص بمنطقة الشرق الأوسط وشمال أفريقيا، ويجعل هذه المنطقة واحدة من أسرع أسواق الترميز نمواً في العالم من حيث معدل نمو الحجم.
بلغت المملكة العربية السعودية معلماً بنيوياً منفصلاً في سبتمبر 2026، عندما حصلت Visa على اعتماد من البنك المركزي السعودي (SAMA) للبنية التحتية للتجارة الإلكترونية المُرمَّزة المستضافة محلياً. والاستضافة المحلية مادية الأهمية لأنها تُعالج متطلبات SAMA المتعلقة بإقامة البيانات مباشرةً، مُزيلةً اعتراضاً هيكلياً كان بعض المُصدرين السعوديين قد استشهدوا به عائقاً أمام طرح الترميز. ومع هذا الاعتماد، تصبح العقبات المتبقية أمام برامج البطاقات السعودية عملياتية وتجارية، لا تنظيمية أو تقنية من حيث المبدأ.
في الإمارات العربية المتحدة، أصبح Wio Bank أول مُصدر إماراتي يُفعّل تلقائياً Click to Pay لحاملي بطاقاته في 6 أكتوبر 2026. تقوم Click to Pay على مواصفة EMVCo للتجارة عن بُعد الآمنة وتستخدم رموز الشبكة طبقةً اعتمادية أساسية. ويُمثّل نشر Wio نقطة مرجعية للمُصدرين الإماراتيين الآخرين: إذ يُثبت أن بنكاً رقمياً مرخصاً محلياً قادر على الانتقال من التكامل إلى التفعيل التلقائي المباشر في البيئة التنظيمية الراهنة، دون الحاجة إلى موافقة منفصلة من المصرف المركزي لكل تسجيل لحامل بطاقة.
سياق سوق المدفوعات في دول مجلس التعاون الخليجي مهم لأن برامج البطاقات الإقليمية تأخرت تاريخياً عن نظيراتها الأوروبية في اعتماد الرموز، جزئياً بسبب انخفاض مستوى اختراق التجارة الإلكترونية وجزئياً بسبب قيود تقنية لدى المُصدرين. وقد تغيّر كلا العاملين تغيراً جوهرياً. فقد تسارع اختراق التجارة الإلكترونية في دول مجلس التعاون بشكل حاد بعد عام 2020، وأتمّ عدد من المُصدرين الإقليميين أو يوشكون على إتمام مشاريع تحديث أنظمة الصيرفة الجوهرية وإدارة البطاقات التي تجعل التكامل مع MDES وVisa Token Service (VTS) أمراً تقنياً مباشراً.
الحجة التجارية لما هو أبعد من الامتثال
يميل إطار الامتثال إلى إنتاج تطبيقات بالحد الأدنى المقبول. أما الحجة التجارية لتوكن الشبكة فتُسوّغ نطاقاً برنامجياً أكثر طموحاً.
تحسين معدل التفويض بمقدار 2 إلى 6 نقاط مئوية على حجم المعاملات التي لا تشترط حضور البطاقة له قيمة إيرادية مباشرة قابلة للاحتساب على مستوى محفظة المعاملات. بالنسبة لمُحيل في دول مجلس التعاون يعالج ما قيمته 500 مليون دولار سنوياً في حجم التجارة الإلكترونية، يُترجم تحسين معدل التفويض بمقدار 3 نقاط إلى 15 مليون دولار من قيمة المعاملات المستردة سنوياً. وبالنسبة للمُصدرين، يُقلل انتقال مسؤولية الاحتيال في المعاملات الرمزية المُصادق عليها من متطلبات المخصصات. وبالنسبة للتجار، يُزيل القضاء على رفض البطاقات منتهية الصلاحية مساراً لتسرب العملاء يكون ضرراً مفرطاً في نماذج الاشتراك والفوترة المتكررة، وهي نماذج تنمو في سياقات المدفوعات الإقليمية للبث ومنصات SaaS والمرافق.
ثمة أيضاً بُعد تنافسي. فالتجار والمنصات التي طبّقت توكن الشبكة تشهد بالفعل انخفاضاً في تكاليف الرسوم البينية في الأسواق التي طرحت فيها الشبكات تسعيراً مُميَّزاً للمعاملات المُرمَّزة. ومع دخول تعديل Mastercard لـ Customer Performance Development Fund في يناير 2027 حيز التنفيذ، سيتسع الفارق التسعيري بين مجموعات المعاملات المُرمَّزة وغير المُرمَّزة. والمُحيلون الذين لا يستطيعون تقديم لعملائهم من التجار مسار واضح للانتقال إلى الترميز سيتعرضون لضغوط من المُحيلين القادرين على ذلك.
ما الذي ينبغي لشركات الدفع فعله الآن
تختلف مجموعة الإجراءات بحسب الدور، غير أن الأولويات الفورية متسقة عبر موقعي المُصدر والمُحيل ومشغل التاجر.
ينبغي للمُصدرين في الإمارات العربية المتحدة والمملكة العربية السعودية تأكيد حالة تكاملهم مع MDES وVTS والتحقق من أن اتفاقيات مزود خدمة الرمز مُبرمة لكلا الشبكتين. والمُصدرون الذين لم يُفعّلوا بعد التحديث التلقائي للرموز عند إعادة إصدار البطاقة عليهم أن يُعاملوا ذلك باعتباره البند التقني ذا الأولوية القصوى الوحيدة، نظراً لأن VCES بات سارياً الآن. وأولئك الذين يدرسون طرح Click to Pay عليهم مراجعة نشر Wio Bank في أكتوبر 2026 كمرجع تطبيقي محلي، والتواصل مع مديري حساباتهم لدى الشبكات للحصول على وثائق تهيئة التفعيل التلقائي.
ينبغي للمُحيلين ومزودي خدمات الدفع مراجعة محافظ تجارهم تحديداً للتجار أصحاب معاملات CoF والمعاملات المتكررة، إذ هذه هي الفئات الخاضعة لالتزام Mastercard في أكتوبر 2026. وأي تاجر يخزن بيانات الاعتماد في مستودع بيانات دون استبدالها برموز الشبكة يقع الآن خارج نطاق الامتثال للالتزامات الإلزامية. وعلى المُحيلين إصدار إشعار رسمي للتجار المتأثرين وتحديد جدول زمني للمعالجة. وبالنسبة للتجار الذين يعالجون المعاملات عبر شبكتي Mastercard وVisa معاً، تستلزم التزامات VCES وMDES مسارات تكامل تقني منفصلة، ولا ينبغي الاستهانة بنطاق هذا العمل.
ينبغي للتجار أصحاب نماذج الاشتراك أو الفوترة المتكررة إيلاء الأولوية لتوفير الرموز لبيانات اعتماد البطاقة المحفوظة القائمة قبل معالجة تدفقات التسجيل الجديدة. والعائد الاقتصادي لتقليل رفض البطاقات منتهية الصلاحية في مجموعات التكرار القائمة فوري وقابل للقياس في غضون دورة فوترة واحدة بعد التطبيق.
بالنسبة لجميع الأطراف، فقد تجاوزت الساعة التنظيمية في الإمارات العربية المتحدة نقطة الإنفاذ المقررة بموجب إشعار CBUAE رقم 3057. وعلى الشركات التي لم تستكمل وثائق الامتثال لديها التواصل مع المستشارين القانونيين والتنظيميين لتقييم وضعها الراهن من المخاطر ووضع جدول زمني للمعالجة يمكن تقديمه إلى المصرف المركزي إن لزم الأمر.
وفّرت الشبكات البنية التحتية، ونشرت المواعيد النهائية، وقدّرت الحجة التجارية بأرقام. المتغير المتبقي هو سرعة التنفيذ. في سوق يُشير فيه نمو سنوي بنسبة 344.9% إلى أن الاعتماد الإقليمي يضغط سنوات من التحول في أشهر معدودة، فإن الشركات التي لم تبدأ التطبيق لا تنتظر اللحظة المناسبة. إنها تتأخر عن النظراء الذين تحركوا بالفعل.