Remote card payments are changing in France, and 2026 puts MOTO under pressure
Fernanda Cruz
14th Sep 2026
What changes for MOTO payments in France, and when
Hotels in France have run phone bookings under a raised MOTO ceiling since June 2024, currently €4,000. That arrangement is ending. Hotels sit in the second of two groups whose sector exemptions are being wound down, and from 10 September 2026 the limit drops to €2,000, then €1,000 on 12 October and €500 on 12 November. €500 has been the standard limit for unexempted sectors since 10 June 2024, and the first group of exempted sectors, including telecoms, utilities, insurance and legal services, reached it on 11 May 2026.
The figure is a velocity limit. It caps the cumulative amount spent on one card, at one merchant, over a rolling 24 hours. So it isn’t a cap on the card, and it’s measured separately from any non 3D Secure internet payments the property takes. Where the characteristics of the payment allow it, issuers are asked to use a soft decline rather than a flat rejection, which lets the payment be resubmitted through 3D Secure without the cardholder re-entering their details.
Where the pressure comes from
A MOTO payment carries no authentication at the moment it’s made. The cardholder passes a card number and expiry date over an insecure channel, a telephone call, an email, a letter or a fax, and an operator keys it into the terminal. Anyone who obtains those two details can initiate a payment without holding the card and without access to the cardholder’s strong authentication device. Banque de France notes that this arrangement encourages both internal and external fraud.
There’s a second concern behind the schedule. MOTO is also used as a route around strong authentication for payments a guest actually made online, and the plan closes that door. MOTO is for bookings genuinely taken by phone or post, and where the nature of the contract allows a proximity payment or a secure internet payment, that’s what should be used.
What hotels can do before November 2026
Stop taking card details over the phone. One of the safest alternatives is to move the payment off the call. For example, with Prommt you can send the guest a payment request they complete on their own device, authenticated by their own bank. That takes the property out of the velocity limit and out of the card handling problem in one move.
Where a phone payment genuinely can’t be avoided, Banque de France asks that the guest key the number into a controller themselves, through the keypad or voice recognition, so no member of staff ever handles it. That reduces exposure but doesn’t authenticate anything, so the ceiling still applies.
Properties whose acceptance rates suffer can apply for an individual derogation through the Observatory secretariat, usually via their acquiring PSP. The bar is a MOTO fraud rate below 0.13% by value over at least six months, or a refusal rate above 20%, plus evidence of the anti-fraud measures already running and those planned. Banque de France grants them, and the list isn’t published.
The authentication gap
Nobody has agreed on a standard method for authenticating a telephone payment. The technical standards allow for one, but nothing uniform has been identified, and some methods built for internet payments don’t transfer to a phone call. The industry has been asked to develop something during 2026. Until then, the ceiling is the tool available.
One caveat on the calendar. A steering committee under the Observatory’s strong customer authentication working group oversees the rollout and can adjust dates if legitimate transactions are being rejected. September and October are firm as published, and the committee has the power to change them.
Where Prommt fits
Instead of taking a payment over the phone, Prommt offers a more secure alternative. A Prommt payment request is a 3D Secure, fully authenticated eComm transaction, so the velocity limit doesn’t apply to it. The guest completes the payment themselves, on their own device, authenticated by their own bank. That takes the transaction outside the scope of the plan altogether rather than putting it under a falling ceiling, so a deposit on a wedding block or a suite booking isn’t something the calendar affects. And because the payment is customer initiated and 3DS2 compliant, fraud liability sits with the issuer rather than with the property.
See how Prommt works for hotel groups: Prommt’s hospitality overview.
Source: Banque de France