Skip to content
All resources

Reference 4 min read

What are Standard Entry Class (SEC) codes?

The three-letter codes that classify every ACH entry — PPD, CCD, WEB, TEL and more — and why using the right one is an audit issue.

A guide by Clusia Editorial

Last updated

Last reviewed by Clusia Editorial in September 2026 against the 2026 Nacha Operating Rules & Guidelines.

Every ACH entry carries a Standard Entry Class (SEC) code: a three-letter code that tells the network what kind of transaction it is and, critically, which authorization and format rules apply to it. The SEC code is not a label you choose for convenience — it is a compliance decision, because it determines the authorization standard you must meet and the proof you must be able to produce.

The codes you will see most

  • PPD (Prearranged Payment and Deposit) — consumer credits and debits such as payroll direct deposit and recurring consumer bill payments; requires a written authorization for debits.
  • CCD (Corporate Credit or Debit) — business-to-business payments between companies; governed by the trading-partner relationship rather than consumer authorization rules.
  • WEB (Internet-Initiated/Mobile Entry) — consumer debits authorized over the internet or a mobile channel; carries heightened fraud-detection and account-validation obligations.
  • TEL (Telephone-Initiated Entry) — consumer debits authorized by telephone; requires either a recording of the oral authorization or written notice sent before settlement.
  • IAT (International ACH Transaction) — entries that involve a financial agency outside the United States; carries OFAC screening and additional data requirements.
  • CTX (Corporate Trade Exchange) — business payments that carry structured remittance information, such as ANSI or EDI data.

Why the code drives authorization

The authorization standard follows the code. A PPD debit to a consumer requires a written, signed or similarly authenticated authorization. A WEB debit requires that the Originator use a commercially reasonable fraudulent-transaction-detection system and validate the Receiver’s account. A TEL debit requires an oral authorization that is either recorded or confirmed in writing before settlement. Choose the wrong code and you have, by definition, applied the wrong authorization standard — even if you collected some form of consent.

A concrete example

Suppose a company signs up customers through an online checkout and debits them monthly. The correct code is WEB, and the company must run account validation and fraud detection on those debits. If it instead codes the entries as PPD to avoid the WEB obligations, an auditor will flag it: the entries were authorized over the internet, so WEB was required, and the company is now missing the account-validation control the Rules demand for that channel. The mis-coding is the finding, and it can also skew how return-rate rules are applied.

Where SEC codes show up in an audit

During an ACH audit, SEC codes are checked in two directions. First, the auditor confirms that each entry type is coded correctly for how it was actually authorized. Second, the auditor confirms that the authorization on file matches the code’s standard. Because SEC-code errors are common, avoidable, and easy to detect in a sample, they are one of the most frequent audit findings — and one of the easiest to prevent with a clear mapping of channel to code.

Why auditors care

The SEC code determines the authorization standard. Using WEB when you should have used PPD — or the reverse — changes what proof of authorization you must hold and which channel-specific controls apply. Map each way you collect authorization to a single, correct SEC code and document it.

Frequently asked questions

What does SEC code stand for?
SEC stands for Standard Entry Class. It is a three-letter code carried on every ACH entry that identifies the type of transaction and determines the authorization and formatting rules that apply.
What is the difference between PPD and WEB?
PPD is used for prearranged consumer payments such as payroll and recurring bills and requires a written authorization for debits. WEB is used for consumer debits authorized over the internet or a mobile device and adds fraud-detection and account-validation obligations.
Which SEC code should I use for a business-to-business payment?
Business-to-business payments generally use CCD, or CTX when structured remittance data must travel with the payment. These corporate codes are governed by the trading-partner agreement rather than consumer authorization rules.
Is using the wrong SEC code really a problem?
Yes. The SEC code sets the authorization standard and channel-specific controls, so mis-coding means you applied the wrong requirements. It is one of the most common ACH audit findings and can also affect how return-rate thresholds are measured.

Go to the source

Use Nacha's official resources to confirm current requirements and effective dates.

This resource is published by Clusia for educational purposes and is not legal, accounting, or compliance advice. This site is independent of Nacha. Always confirm requirements against the current Nacha Operating Rules and your own institution's policies.