3D Secure 2.0 (3DS2): What It Is and How It Protects Merchants

blog-12-1

Learn how Justt can help you keep more revenue.

Book a demo today.

3D Secure 2.0 (3DS2) is a security protocol designed to prevent card-not-present fraud developed by EMVCo, a consortium of all major credit card networks. Its adoption has continued to grow worldwide since the 2021 introduction of Secure Customer Authentication (SCA) requirements in the UK and EU with PSD2. 3DS2 is the chosen method of  SCA compliance across Europe, the UK, India, Japan and Asia-Pacific markets.

Despite these gains, many merchants around the globe are still wondering what this fraud protection technology can do for them. Below we summarize what 3DS2 is, how it compares to previous versions, and where its limitations lie.

Key Takeaways

  • 3DS2 is a security protocol used to reduce card-not-present fraud
  • 3DS2 differs from 3DS1 by sending more data elements, enabling risk-based authentication, changing technically how the prompt for authentication appears to the cardholder to make cart abandonment less likely and replacing static passwords with more secure methods of authentication.
  • Risked-based authentication (RBA) refers to the ability to exclude low risk transactions from the 3DS2 challenge flow based on information received in the 3DS2 data elements.
  • “Frictionless flow” refers to the passive authentication path that low-risk transactions are filtered through so as to not disturb the cardholder, reducing checkout abandonment. 
  • For fraud reason codes, 3DS2 shifts liability from the merchant to the issuer. However, 3DS2 authentication does not protect from friendly fraud perpetrated on service-oriented chargeback reason codes.

What Is 3D Secure?

3D Secure is a security protocol that protects online debit and credit card transactions. It adds an authentication step for shoppers before payment authorization. This protocol prevents fraud by verifying the cardholder’s identity directly with the issuing bank, reducing unauthorized chargebacks for online merchants

The 3D Secure protocol protects cardholder payment details from unauthorized use across three domains: the acquirer, the card issuer and the credit card network infrastructure between them that supports the protocol. This basic definition remains the same regardless of whether we are talking about 3D Secure 1.0 or 3D Secure 2.0.

How 3D Secure Works?

To use 3D Secure 1.0, the customer first registers with their issuing bank and sets up a static password. When the customer checks out on the websites of participating merchants, they are directed to a popup or inline frame belonging to their issuing bank to fill their password to authenticate their identity and enable the bank to authorize the online transaction. Following the authorization, the merchant sends the transaction to their payment service provider for processing.

3D Secure 2.0 works by routing online payment data through three distinct domains to verify shopper identity. The merchant payment gateway triggers an enrollment check via the card network. The issuing bank then challenges the user with a biometric prompt or one-time password before authorizing the final transaction instead of using a static password.

Frictionless Flow vs. Challenge Flow

Under 3D Secure 2.0, merchants can determine whether to require their customers to fulfill the strong customer authentication aspect by providing an one-time password (OTP) or a biometric identifier on file with the issuer or to exempt them from the challenge flow and provide them with  a frictionless user journey. 

Frictionless flow authenticates typically smaller transactions, using in the background the 100+ data elements 3DS2 shares without any cardholder input required. The cardholder must establish their identity in the challenge flow only.

Data-only Flow

3D Secure isn’t limited to full authentication. The data-only flow runs on the same 3DS protocol, but instead of authenticating the cardholder it sends a data-collection session before authorization: the collected cardholder data is transmitted to the issuing bank through the card scheme’s directory server. No authentication is requested, and no liability shift takes place, but in return the merchant receives an indication that the issuer performed its own risk assessment of the transaction.

If that assessment took place and the transaction was then approved at authorization, the indication reflects a risk assessment the issuer itself carried out, showing it viewed the transaction as legitimate at the time of processing. For the merchant, that becomes powerful evidence: the cardholder’s own bank assessed the transaction and approved it, which is hard to reconcile with a later fraud claim, so it gives merchants a strong way to contest friendly-fraud disputes filed under a fraud reason code. For more on the data-only flow, talk to a Justt expert. 

3DS2 vs 3DS1

3D Secure 2.0 was jointly created by Visa and Mastercard in 2016, and aimed to remedy some of the problems with 3DS 1.0. One major change is that the protocol now sends over 100 data elements for each transaction and enables risk-based authentication (RBA) decisions, which benefits both merchants and issuers. RBA means that the decision to challenge the cardholder to authenticate their identity is based on the perceived risk of the transaction as determined by data elements passed through 3DS2.

Transactions that are deemed low risk are passively authenticated through a “frictionless flow” that does not disturb the cardholder, reducing checkout abandonment. 3DS2 was also designed to be mobile responsive with native in-app payment options, instead of iframes or popups, making it easier to retain mobile users. Finally, 3DS 2.0 supports token-based and biometric authentication, and removes static passwords, making it more difficult for fraudsters to compromise credentials.

You can compare the differences between 3DS1 and 3DS2 in the table below:

 

Feature 3DS 1.0 3DS 2.0
Data elements exchanged ~10 static data elements 100+ data elements
Authentication method Static password Risk-based authentication, biometrics, OTP
Mobile experience Browser redirect, not mobile-optimized Native in-app SDK support
Friction Full-page redirect for every transaction Frictionless flow for low-risk transactions
SCA/PSD2 compliance Not designed for SCA Built to meet SCA requirements
Status Decommissioned by major card schemes (Oct 2022) Current standard

Why Did 3D Secure 1.0 Struggle?

3D Secure 1 was launched in 2001 as Verified by Visa and MasterCard SecureCode, followed several years later by branded versions for American Express, Discover and JCB as well. Its twenty year run came to an end in October 2022, when it was finally decommissioned by the major card schemes.

3DS 1.0 adoption stalls

However, problems existed from the beginning. Early adoption of the technology was low in many of the largest Western markets, such as France (19 percent), Germany (46 percent), Spain (17 percent) and the U.K. (29 percent), according to the 2016 Arvato Payments Review. Among the worst was the world’s largest market, the U.S., where adoption stalled at just 5 percent.

Overall adoption was weak because the net benefits of 3D Secure implementation were a mixed bag. The primary benefit to merchants of enrolling in 3D Secure was that it facilitated a  liability shift for fraudulent transactions from them to the issuer. However, this was tempered by significantly lowered customer conversion rates. Customers on a 3D Secure enrolled merchant site would abandon checkout because they weren’t comfortable being dragged in the middle of a transaction to a third-party site to authenticate.

Not mobile responsive, hurting conversion

Another factor in low conversion rates over the past decades is that many bank pages weren’t optimized for mobile, and were caught off-guard by the boom in mobile commerce. This left mobile-based customers dealing with long load times and complicated forms to complete, pushing them to abandon transactions.

A raw deal for issuers, too

For card issuers, 3D Secure only represented added costs. For starters, if fraud occurred on an authenticated transaction, it was the bank’s responsibility. This liability issue was exacerbated by the fact that 3-D Secure wasn’t very secure. The use of static passwords was problematic because they weren’t very difficult for motivated fraudsters to compromise and then use to bypass the 3D Secure process.

All the issuing bank would receive to determine the likelihood of fraud was 10 static data elements. Lastly, the issuing banks had to shoulder the cost of implementing and supporting access control servers (ACS) to receive 3D Secure messages, process the messages and authenticate the card user. In short, there were plenty of stakeholders dissatisfied with the original 3D Secure

PSD2 Pushes 3DS2 Adoption

The adoption of 3DS2 was significantly accelerated by the implementation of the Revised Payments Service Directive (PSD2) in the European Economic Area (EEA). PSD2 set a new standard in European countries for protecting  online payments by mandating SCA for most transactions.

To fulfill the SCA requirement merchants must authenticate a customer’s identity using two of the following three things: 

  • Something they know
  • Something they have 
  • Something they are

“Something they know” includes password, PIN, or personal facts. “Something they have” might be a mobile phone (i.e. SIM card), security token, or smart card. “Something they are” could consist of a fingerprint, facial features, or voice pattern.

Adoption of 3DS 2.0 has been uneven by region, with massive adoption in regions where it was mandated by the regulator, while much lower levels of implementation in regions where implementation is still optional. For example, European issuers and merchants flocked to 3DS2 to meet the SCA requirement that went into effect in January 2021. 3DS2 was also designed with PSD2 in mind, including exemptions from SCA, for example, when dealing with small transaction amounts. Below is a table covering the adoption of 3DS2 in different regions.

Market What is required? Current status
Europe (EU / EEA / UK) The law requires Strong Customer Authentication (SCA). 3DS2 is the standard card-rail mechanism used to meet this law. These rules have been fully in force since 2020 and 2021. An updated version of the law, called PSD3, is currently in progress.
India The Reserve Bank of India (RBI) mandates an additional factor of authentication for all domestic online card transactions. This rule has been strictly in force for well over a decade, making India one of the most experienced markets for mandatory authentication.
Japan The Ministry of Economy, Trade and Industry (METI) issued Credit Card Security Guidelines 5.0. This requires EMV 3DS on all e-commerce credit card transactions, including both domestic and cross-border purchases. This requirement has been fully in force since April 1, 2025.
Australia The Australian Competition and Consumer Commission (ACCC) authorized the payments industry to coordinate a massive cleanup. The goal is to migrate all card payments to the enhanced authentication standard. The migration is currently underway across the country.
Latin America (Brazil, Mexico & LatAm) Scheme-driven 3DS adoption; requirements vary by country. Use of the protocol is growing quickly, but it is not yet uniformly mandated across every country in the region.
United States 3DS adoption is still optional and promoted by the credit card schemes. Adoption is still voluntary.

What is 3DS2.2 and 3DS2.3?

3DS2.3 is the latest iteration of 3D Secure and was launched by EMVCo in 2022.  In mid-2024, both Visa and Mastercard deprecated 3DS2.1, leaving 3DS2.0 as the current minimum version supported and the most widespread version across PSPs today.

3DS2.2 is an upgraded security protocol that optimizes online credit card transactions. It introduces advanced features like delegated and decoupled authentication, which allow select merchants to authenticate transactions on a customer’s behalf – particularly valuable for recurring subscriptions or split shipments. This protocol also expands support for 3DS Requestor Initiated (3RI) authentication, enabling verification even when the customer isn’t present, such as for installment payments or buy-now-pay-later (BNPL) transactions. 

3DS 2.3 includes automated out-of-band transitions, device binding and FIDO authentication, among other benefits. Automated out-of-band transitions is a feature that securely redirects users from a merchant’s site to their mobile banking or authenticator app. It ensures that transaction approval happens over a separate, secure channel. Device binding removes extra challenges on future purchases by allowing consumers to securely link their browser or mobile device with an issuer or merchant. FIDO authentication mandates the use of cryptographic keys and biometrics like fingerprint or face scan to make logins password-less and resistant to phishing.

3DS2 Blindspots for Merchants

It’s important to point out that the liability shift from merchant to issuer in cases of 3DS authentication covers fraud chargebacks alone, and not service-related chargebacks. This still leaves merchants exposed to friendly fraud, which comprises over 80%of chargebacks, and continues to rise year on year. What is surprising is that, despite the vast majority of chargebacks being illegitimate – and therefore winnable – merchants only win 30% of disputes on average. This can result in devastating financial losses for businesses affected. In worst case scenarios, up to 25% of net income can be lost on chargebacks.

Another significant concern is that all chargebacks on 3DS-authenticated transactions count towards card scheme fraud monitoring programs, regardless of the liability shift. This means that even when merchants aren’t financially liable for fraud chargebacks due to 3DS authentication, these disputes still impact their fraud ratios. High fraud rates can trigger substantial fines from card networks and lead to decreased authentication rates as issuers become more cautious, potentially resulting in higher decline rates or even account termination.

How Justt Helps Merchants Fight Chargebacks 3DS2 Doesn't

To fight the friendly fraud chargebacks not prevented by 3DS2, consider using a comprehensive chargeback management solution. Justt’s solution is risk-free, with a success-based fee, and typically provides significant lift to win rates within weeks. 

Justt offers a tailor-made solution designed to maximize the amount of chargebacks won. Unlike template-based solutions, Justt’s AI-driven Dynamic Arguments technology creates unique, precise responses that account for the preferences of individual issuers examining your evidence, as well as the complex requirements of acquirers and card schemes. Everything from format, to layout, to argument type and style, is optimized for maximum effectiveness. This intelligent approach ensures each dispute is presented in the most compelling way possible, giving you the best chance to catch friendly fraud chargebacks that slip through 3DS2’s defenses.

Frequently Asked Questions

Is 3D Secure required for every online transaction?

  1. No, 3D Secure is optional for merchants in markets like the U.S. that do not require Strong Customer Authentication (SCA). Even in markets that mandate SCA, transactions are frequently passed through the “frictionless” flow that passively authenticates the customer without prompting them to identify themselves.

Does 3D Secure 2.0 guarantee protection against all chargebacks?

  1. No, 3DS 2.0 does not protect against service-related chargebacks. Also, issuers sometimes file fraud chargebacks on 3DS authenticated transactions in error, which can be successfully recovered by merchants in chargeback representment.

What happens when a customer fails 3D Secure authentication?

  1. The customer will receive an error message and must either try to authenticate again or they must contact their issuer to resolve the issue.

Which card brands use 3D Secure?

  1. All major card networks today use some version of 3D Secure, including Visa, Mastercard, American Express and Discover. Visa’s version is called Visa Secure (formerly Verified by Visa). Mastercard’s version is known as Mastercard Identity Check (formerly SecureCode). Amex uses American Express SafeKey. Lastly, Discover has ProtectBuy. 

 

Ronen Shnidman

Written by

Ronen Shnidman

Ex-journalist and major fan of fintech and OSINT, I write regularly for leading industry outlets in finance and fraud prevention. Outlets I contribute to include Payments Dive, Finextra, and Merchant Fraud Journal, and I have been cited by PYMNTS.com

Explore

Apply for this position