Skip to main content
Category: Transaction Processing

Merchant Category Code

Also known as: MCC, Merchant Category Code (MCC), merchant category code
Simply put

A Merchant Category Code (MCC) is a four-digit number that classifies a business by the type of goods or services it provides. Payment processors and card networks assign these codes to give a more detailed view of what a merchant does. The code is used in retail financial services to categorize merchants.

Formal definition

A Merchant Category Code (MCC) is a four-digit classification value assigned to a merchant to identify the type of goods or services it provides for purposes of retail financial services. MCCs are typically assigned by payment processors or acquirers and are used within card-network processing to categorize merchant activity at a granular level. Example code assignments include 0742 (Veterinary Services), 0763 (Agricultural Co-operatives), and 0780 (Landscaping/Horticultural Services, per the referenced code list). Note that specific code-to-category mappings and assignment practices vary by network and processor, and readers should confirm current values against the applicable published code lists rather than assuming a fixed mapping.

Why it matters

Merchant Category Codes give card networks, acquirers, and processors a consistent way to describe what a merchant sells, which underpins a range of downstream decisions in payment processing. Because the code travels with transaction data, it can influence how activity is routed, categorized, and monitored, and it provides a granular signal about the nature of a business that would otherwise require manual review.

For risk and fraud teams, the MCC is one attribute among many that can help contextualize a transaction. A charge whose merchant category is inconsistent with a cardholder's typical spending patterns may warrant additional scrutiny, though the code alone does not establish fraud and should be weighted alongside other indicators. Relying on the MCC as a standalone control carries false-positive and false-negative trade-offs, since a single four-digit classification cannot capture the full behavior of a diverse merchant.

MCCs also matter because their mappings are not universal. Specific code-to-category assignments and the practices used to assign them vary by network and processor, so a code that means one thing in one program may differ elsewhere. Teams that build rules, reporting, or reconciliation logic on top of MCCs should confirm current values against the applicable published code lists rather than assuming a fixed, portable mapping.

Who it's relevant to

Acquirers and Payment Processors
Acquirers and processors typically assign MCCs to merchants and are responsible for ensuring the code reflects the merchant's actual goods or services. Because assignment practices and code lists vary across networks and processors, these teams should confirm mappings against the applicable current published lists.
Fraud and Risk Analysts
Analysts may use the MCC as one contextual attribute when evaluating whether a transaction is consistent with expected merchant activity. The code is a supporting signal rather than a determinative one, and using it in isolation carries false-positive and false-negative trade-offs; it should be combined with other indicators.
Merchant Risk and Onboarding Teams
Onboarding teams need the MCC to accurately describe the nature of a business being brought into a payment program. Because a single four-digit code cannot capture every aspect of a diverse merchant, these teams should verify that the assigned code aligns with the merchant's actual activity.
Reporting and Reconciliation Teams
Teams that build categorization, reporting, or reconciliation logic on MCC values should account for the fact that code-to-category mappings vary by network and processor. Logic built on assumed portable mappings can break when a code means something different in another program.

Inside MCC

Four-digit classification code
A Merchant Category Code is a four-digit number assigned to a merchant to classify the type of goods or services the merchant primarily provides. The code set is standardized under ISO 18245, and card networks maintain their own MCC lists that align with this classification.
Merchant business type designation
The MCC identifies the merchant's primary line of business, for example a grocery store, airline, or utility. It describes the merchant category rather than any individual transaction detail, and does not identify the specific product purchased.
Assignment by acquirer or payment facilitator
The MCC is typically assigned to a merchant by the acquirer or payment facilitator during onboarding, based on the merchant's described business activity. A single merchant may map to one MCC, though large or diversified merchants can have multiple depending on network and acquirer practices.
Uses in authorization and settlement messages
The MCC is carried in transaction messages and is used by card networks, issuers, and acquirers for purposes such as interchange determination, rewards eligibility, spending controls, and certain risk and reporting decisions. Exact behavior varies by card brand and network rules.
Relationship to network and card-brand rules
How an MCC affects interchange rates, acceptance restrictions, and permitted categories is governed by card brand and network rules, which vary by region and change over time. The MCC itself is a classification value, not a security control.

Common questions

Answers to the questions practitioners most commonly ask about MCC.

Were Merchant Category Codes originally created for tax reporting purposes?
No. MCCs are a merchant classification code set used by card networks to categorize merchants by the type of goods or services they provide, and the code set predates its use in tax information-reporting. Tax authorities later leveraged the existing network classification for certain information-reporting purposes, but that adoption was a subsequent use rather than the reason the codes were developed. Treat MCC primarily as a payments classification mechanism, and confirm any specific tax-reporting requirements against current published guidance from the relevant authority.
Does a merchant's MCC by itself determine whether a transaction is fraudulent or high-risk?
No. An MCC describes the category of the merchant, not the risk of an individual transaction. Some MCCs are associated with categories that risk teams may weight differently in fraud models, but the code alone does not indicate fraud and can produce both false positives and false negatives if used in isolation. MCC is one attribute among many, such as transaction amount, channel (card-present versus card-not-present), velocity, and authentication results, and it is intended to help inform risk decisioning rather than to decide it.
How is an MCC assigned to a merchant, and can it change?
MCCs are typically assigned by the acquirer or payment processor during merchant onboarding based on the merchant's business activity, following the card networks' classification rules. A merchant's MCC can change if its business activity changes or if a review determines a different category is more appropriate. Because network rules and category definitions vary by brand and can be updated, confirm assignment procedures and any reclassification processes with your acquirer and the applicable card brand documentation.
Can a single merchant have more than one MCC?
In many implementations a merchant location is assigned a single MCC that best reflects its primary business, but merchants operating multiple distinct business lines or multiple merchant identifiers may be associated with more than one MCC. How this is handled depends on acquirer setup and card brand rules. Verify the specific arrangement with your acquirer, since inconsistent categorization can affect interchange, routing, and reporting.
Does the MCC affect interchange or how a transaction is processed?
MCCs can be used as an input to interchange qualification, certain fee structures, and some processing or acceptance rules, but the specific effects are defined by card brand and network rules that vary by region and change over time. The MCC is a classification input, not the sole determinant. Confirm the current impact of a given MCC on interchange and processing against the applicable card brand rules and your processor's documentation rather than assuming a fixed outcome.
Is the MCC considered cardholder data or in scope for PCI DSS?
An MCC is a merchant classification attribute and is not cardholder data or sensitive authentication data as those terms are defined for PCI DSS. It does not by itself bring a system into PCI DSS scope. Scope is driven by the storage, processing, or transmission of account data such as the primary account number. Where an MCC appears alongside account data in the same systems or records, apply scoping analysis to those systems as a whole, and validate against the current published PCI DSS.

Common misconceptions

The MCC is a fraud-prevention or security control that reduces the risk of a compromised transaction.
The MCC is a merchant classification value used for categorization, routing, interchange, and reporting. It is not a security control and does not authenticate a cardholder, protect cardholder data, or determine PCI DSS scope. Fraud and authentication risks are addressed by separate controls such as EMV chip authentication, 3-D Secure, and multi-factor authentication, each of which is intended to mitigate different risks and none of which the MCC replaces.
The MCC precisely describes what an individual customer purchased in a given transaction.
The MCC describes the merchant's primary category of business, not the specific item or service bought in a particular transaction. A merchant with a single MCC may sell a range of products, and diversified merchants may be represented by more than one code depending on network and acquirer practices.
An MCC is a fixed attribute that a merchant assigns to itself and that never changes.
The MCC is typically assigned by the acquirer or payment facilitator based on the merchant's business activity, and it can be updated as the business or its classification changes. How codes are assigned and how they influence interchange or acceptance is governed by card brand and network rules, which vary by region and over time; practitioners should confirm current rules with the relevant network.

Best practices

Confirm each merchant's assigned MCC against the merchant's actual primary business activity during onboarding and periodic reviews, and correct misclassifications with the acquirer or payment facilitator.
Do not treat the MCC as a security or authentication control; rely on dedicated controls such as EMV chip authentication, 3-D Secure, and multi-factor authentication to address their respective risks.
Consult current card brand and network rules, which vary by region and change over time, when reasoning about how an MCC affects interchange, acceptance categories, or spending controls, rather than assuming static behavior.
For diversified merchants, clarify with the acquirer whether one or multiple MCCs apply, and document the mapping so downstream routing and reporting reflect the actual business lines.
Keep MCC assignment logic separate from PCI DSS scoping decisions, since the MCC classifies the merchant and does not itself expand or reduce the cardholder data environment.
Establish a review process to update a merchant's MCC when its business activity materially changes, and validate the change against the classification defined under ISO 18245 and the applicable network lists.