I simply don't think that CC provider restrictions are a good way to deal with CSAM in the first place, basically.
How much harmful policy has been pushed through with the excuse that it will stop CSAM? Often without having any particular effect on the issues it claims to be working against. People who spread or produce CSAM will use encryption and cryptocurrencies, leaving everyone else to be under permanent surveillance.
How do you stop them? By investigating and hitting down hard when you catch them irl, just like we always have. Not by racing to a dystopian surveillance state.
Having providers of financial infrastructure assume the legal risk for its users without due process is not how things should work in a democracy with rule-of-law, because it will adversely affect innocents.