What is 3D Secure?
Also: 3DS, 3DS2, EMV 3DS
A card-network authentication protocol that shifts fraud liability from the merchant to the issuer when a cardholder is verified.
3D Secure, or 3DS, is a security protocol standardised by EMVCo to reduce fraud in online Card-Not-Present (CNP) transactions. The '3-D' refers to the three domains involved in the process: the merchant and acquirer domain, the issuer domain, and the interoperability domain that connects them.
When a cardholder initiates a payment, 3DS facilitates a real-time data exchange between the merchant and the card issuer, allowing the issuer to authenticate the cardholder's identity before authorising the transaction. Its primary benefit for merchants is the 'Liability shift'.
For successfully authenticated transactions, the financial liability for certain types of fraudulent chargebacks, such as those claiming 'unauthorised transaction', shifts from the merchant to the issuer.
The latest version, 3DS2, is a significant enhancement designed to support modern authentication methods and minimise friction. It allows merchants to send a rich set of data elements, including device information, transaction history, and behavioural biometrics, to the issuer's risk engine.
This enables many transactions to be approved through a 'Frictionless flow' without requiring any cardholder interaction.
When the risk is deemed higher, the cardholder is presented with a 'Challenge flow', requiring them to provide a second factor of authentication like a one-time password or a biometric confirmation on their banking app.
A common misconception is that liability shift is absolute; it does not apply to non-fraud disputes like 'goods not received' and can be voided if a merchant's overall fraud rates are excessively high.
Worked example
A customer is purchasing a €250 watch from an online store. At Checkout, the merchant's payment gateway initiates a 3DS2 authentication request.
It sends over 20 data points to the customer's issuer, including their browser details, IP address, billing information, and the fact that this is their third purchase from the site.
The issuer's Access Control Server (ACS) analyses this data and assesses the transaction as low risk. It decides on a 'Frictionless flow' and sends an authentication success message back to the merchant without challenging the user.
The transaction proceeds to authorisation and is approved. The liability for a potential 'fraudulent transaction' chargeback (e. g. , Mastercard R/C 4837) now rests with the issuer.
Had the customer been using a new device from a different country, the ACS would likely have triggered a 'Challenge flow', asking for a fingerprint confirmation in their banking app.
Scheme notes
All major schemes support the EMVCo 3DS protocol under their own branding. Visa's programme is called Visa Secure (formerly Verified by Visa), and Mastercard's is Mastercard Identity Check (formerly SecureCode).
American Express uses Safekey, and Discover offers ProtectBuy. While the underlying protocol is standardised, issuer implementation of risk-based analysis varies significantly.
Some issuers are more aggressive in challenging transactions, while others favour frictionless flows to preserve the user experience. The exact data points required or valued by each issuer's risk engine are proprietary, making it difficult for merchants to optimise for all issuers universally.
This is one area where an orchestration provider can add value by analysing performance across different acquirer and issuer combinations.
Why it matters for merchants
The primary impact of 3D Secure is the trade-off between fraud reduction and customer friction. Correct implementation of 3DS2 is crucial; sending rich data maximises the chance of a Frictionless flow, maintaining high approval rates and a smooth Checkout experience.
The liability shift provides direct financial protection against certain fraud-related chargebacks, reducing a significant cost for many e-commerce businesses. Under PSD2, using 3DS is mandatory for most European transactions to meet SCA requirements.
Cardflo's payment orchestration can ensure merchants are sending the most complete data set possible for 3DS2 authentication and can use smart routing to direct payments to acquirers who demonstrate superior 3DS handling and higher approval rates.
Frequently asked
How does 3D Secure 2 improve the user experience compared to the original version?
3DS2 supports risk-based authentication by sharing extensive data points, such as device IDs and transaction history, with the issuer. This allows for a Frictionless flow where the cardholder is not required to take any action for low-risk payments.
If a challenge is required, it can now be completed via biometrics or app-based notifications rather than old-fashioned static passwords.
Does 3D Secure eliminate all types of chargebacks for a merchant?
No, 3DS only provides a liability shift for specific fraud-related reason codes. It does not protect the merchant against disputes related to goods not received, service quality, or administrative errors.
Merchants must still manage their internal processes to prevent non-fraud chargebacks which are not covered by the protocol.
Does using 3D Secure guarantee I won't get any fraud chargebacks?
No. 3D Secure provides a liability shift for specific fraud-related chargeback reason codes, typically related to unauthorised use of the card.
It does not protect against other dispute types, such as 'goods not received' or 'product not as described'.
Furthermore, if a merchant is enrolled in a scheme's excessive fraud programme, the issuer may be able to return liability to the merchant even if 3DS was successfully used. It is a powerful tool for reducing fraud losses, not a complete shield.
What is the difference between 3DS1 and 3DS2?
3DS1 was the original protocol, known for redirecting the user to the issuer's webpage to enter a static password. This created a disruptive user experience, was not mobile-friendly, and led to high cart abandonment.
3DS2 is a fundamental upgrade that supports data-rich, 'frictionless' authentication within the Checkout flow, allows for biometric challenges, and is designed for mobile and in-app payments. It is the core technology used to meet SCA requirements under PSD2.
Will 3D Secure hurt my conversion rate?
Poorly implemented 3DS1 was notorious for harming conversion. Modern 3DS2, when implemented correctly with rich data sharing, should not significantly harm conversion for most businesses.
The majority of transactions for legitimate customers can be approved via the Frictionless flow, with no user interaction. While challenge flows do add a step, consumers in regions like Europe are now accustomed to it as a standard security measure.
The marginal drop in conversion from challenges is often outweighed by the increase in approvals from previously declined transactions and the reduction in fraud costs.
Is 3D Secure mandatory for all transactions?
It depends on the region. For transactions where both the merchant's acquirer and the cardholder's issuer are in the European Economic Area (EEA) or the UK, 3DS is mandatory for most transactions due to Strong Customer Authentication (SCA) rules.
However, certain exemptions apply for low-value transactions, subscriptions, and low-risk payments. For transactions outside this region, such as in the US, 3DS is optional but highly recommended as a best practice for fraud prevention and liability shift benefits.
What happens if a customer's bank doesn't support 3D Secure?
If a card is not enrolled in 3DS, the authentication process cannot be completed. This is logged as an 'attempt' in the system.
The transaction may still be sent for authorisation, but without successful authentication, there is no liability shift. The merchant would be liable for any subsequent fraudulent chargeback.
In regions where SCA is mandatory, an issuer that does not support 3DS would be non-compliant, and transactions may be declined by the acquirer or scheme.
See how 3D Secure plays out in practice
Industries and regions where this term drives real acquiring, routing, or dispute decisions.
Related terms
PSD2 requirement that customer-initiated electronic payments in the EEA and UK be authenticated with two of: knowledge, possession, inherence.
The EU's Payment Services Directive 2, which mandates SCA, opens banking APIs, and reshapes payment liability.
Scheme rule moving fraud liability from merchant to issuer once 3DS authentication succeeds, defended by ECI 05 (Visa) or ECI 02 (Mastercard) flags.
3DS2 outcome where the issuer authenticates the cardholder purely from device and transaction data, with no challenge shown to the customer.
Related guides.
Ready to improve your payments setup?
Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.