Security Violation
A Security Violation decline means the issuer detected a security-related problem with the transaction, such as a failed cryptographic check or a violation of a required security protocol, rather than a general suspicion of fraud. It typically points to a technical integrity issue in how the transaction was submitted.
Decline code by card network
| Card network | Code | Network's wording |
|---|---|---|
| Visa | 63 | Security Violation |
| Mastercard | 63 | Security Violation |
Common causes
- A cryptogram or chip/contactless security check failed during processing.
- The transaction was submitted with an invalid or mismatched security element, such as a corrupted EMV data field.
- The terminal or payment application used an outdated or non-compliant security protocol version.
What merchants should do
- Retry the transaction, since some occurrences stem from a transient terminal or network communication issue rather than a persistent problem.
- If the issue recurs, contact your payment processor or terminal vendor to check for outdated firmware or software that may be generating invalid security data.
- Escalate to your acquirer if the pattern persists across multiple customers or cards, since it may indicate a terminal-level compliance issue.
How to prevent this
- Keep POS terminals, payment SDKs, and EMV kernels updated to current security specifications.
- Work with your processor to validate your integration passes required certification and security testing.
- Monitor for clusters of this decline tied to a specific terminal or software version, which usually points to the root cause.
Because this code points to a security-protocol or cryptographic failure rather than a business decision by the issuer, recurring instances are best treated as a technical support case with your processor rather than a customer-facing payment problem.
Frequently asked questions
Is this decline the customer's fault?
Rarely. It usually reflects a technical security-check failure in how the transaction was processed, often related to terminal or software configuration, rather than anything the cardholder did.
Should I keep retrying if I see this repeatedly?
A single retry is reasonable, but if the decline recurs across multiple transactions, stop retrying and involve your payment processor or terminal vendor to investigate the underlying security protocol issue.