Skip to main content

3D Secure

Last Updated: 2025-02-17 Status: Complete

3D Secure (3DS) is an authentication protocol that adds a layer of security for card-not-present transactions. For PayFac platforms, 3DS is essential for reducing fraud and shifting liability away from merchants.

Quick Reference

ItemStatus (2026)
Current Version3DS 2.2
3DS 1.0Discontinued October 2022
Global Merchant Adoption65%
Frictionless Success Rate90-95%
Top Performing RegionsUK, Ireland, Netherlands

What is 3D Secure?

3D Secure adds cardholder authentication to CNP transactions. "3D" refers to three domains involved:

Brand Names

Network3DS Brand Name
VisaVisa Secure
MastercardMastercard Identity Check
American ExpressSafeKey
DiscoverProtectBuy
JCBJ/Secure

3DS2 vs 3DS1

3DS1 Discontinued

Visa discontinued 3DS 1.0 support in October 2022. All merchants must use 3DS2.

Feature3DS13DS2
User experiencePage redirectEmbedded/native
Mobile supportPoorOptimized
Data points~15~100+
Frictionless flowNoYes
Risk-based authNoYes
Abandonment rate10-15%3-5%

Authentication Flows

Frictionless Flow

Most transactions (90-95%) complete without customer interaction:

Challenge Flow

High-risk transactions require customer verification:

Challenge Methods

MethodDescriptionUser Experience
OTP via SMSCode sent to phoneMedium friction
OTP via AppCode in banking appMedium friction
Push notificationApprove in appLow friction
BiometricFingerprint/Face IDLow friction
Knowledge-basedSecurity questionsHigh friction

ECI Indicators

ECI (Electronic Commerce Indicator) values indicate the authentication result and determine liability shift:

Visa / Amex / Discover / JCB

ECIMeaningLiability Shift
05Fully authenticatedYes
06Attempted (cardholder not enrolled)Yes
07Authentication failed/not availableNo

Mastercard

ECIMeaningLiability Shift
02Fully authenticatedYes
01Attempted (stand-in service)Yes
00Authentication failedNo
04Data Only (frictionless)No
06SCA exemption appliedNo
07Recurring authenticatedYes
Key Values

ECI 05 (Visa) / 02 (MC) = Full authentication, full liability shift

Liability Shift

When 3DS authentication succeeds, liability for fraud chargebacks shifts from merchant to issuer.

How Liability Shift Works

Liability Shift by Network

NetworkShift DurationCoverage
Visa90 daysFraud chargebacks only
Mastercard30 days → 90 daysFraud chargebacks only
AmexVariesFraud chargebacks only
DiscoverVariesFraud chargebacks only

What Liability Shift Does NOT Cover

Not CoveredExplanation
Friendly fraudCardholder disputes legitimate purchase
Not receivedDelivery disputes
Not as describedProduct quality disputes
Service disputesAny non-fraud reason code
Critical Limitation

Liability shift only applies to fraud chargebacks (reason codes 10.4/4837). Friendly fraud, which represents up to 75% of all chargebacks (source: industry estimates 2024-2025), is NOT covered by liability shift.

PSD2 & Strong Customer Authentication (SCA)

PSD2 (Payment Services Directive 2) requires Strong Customer Authentication for European transactions.

SCA Requirements

SCA requires two of three authentication factors:

FactorTypeExamples
KnowledgeSomething you knowPassword, PIN, security question
PossessionSomething you havePhone, token, card
InherenceSomething you areFingerprint, face, voice

SCA Timeline

DateEvent
September 14, 2019PSD2 SCA mandate effective
December 31, 2020Final enforcement deadline
October 14, 2024France: €100 daily exemption limit
March 10, 2025France: Auth exemptions restricted to EMV 3DS
~2026PSD3/PSR1 expected

SCA Exemptions

ExemptionCriteria3DS Required?
Low value< €30 (max 5 consecutive or €100 cumulative)No
Low risk (TRA)Fraud rate thresholds metNo
Trusted beneficiaryCardholder whitelisted merchantNo
RecurringSame amount, same merchantFirst transaction only
Corporate cardsB2B paymentsMay be exempt

Transaction Risk Analysis (TRA) Thresholds

PSPs meeting fraud rate thresholds can request exemptions:

Fraud RateMaximum Exemption Value
≤ 0.01%€500
≤ 0.06%€250
≤ 0.13%€100

Implementation Considerations

Integration Approaches

ApproachDescriptionComplexity
RedirectCustomer redirected to 3DS pageLow
Embedded (iframe)3DS in modal on checkoutMedium
SDK (mobile)Native in-app experienceHigh
APIFull control via APIsHigh

Impact on Conversion

FactorImpact
Challenge flow5-20 second delay
Abandonment (3DS2)3-5%
Abandonment (3DS1)10-15%

Best Practices

PracticeBenefit
Send maximum dataHigher frictionless rate
Use current SDKBest mobile experience
Handle timeoutsGraceful fallback
Test thoroughlySandbox testing essential
Monitor auth ratesTrack and optimize

Regional Requirements

Japan (April 2025)

RequirementDetail
Effective dateApril 1, 2025
Mandate3DS2 required on all transactions
ImpactAll merchants must implement

Australia (AusPayNet)

RequirementThreshold
Fraud losses> AUD 50,000
Fraud ratio> 0.2% for 2 consecutive quarters
ActionMust implement 3DS2

Europe (PSD2/SCA)

RequirementStatus
SCA mandateIn effect
ExemptionsAvailable with TRA
EnforcementActive

3DS Data Elements

Key Data Points Sent

CategoryExamples
CardholderName, email, phone
BillingAddress, postal code, country
ShippingAddress, method, indicator
AccountAccount age, transactions in 24h
DeviceIP, user agent, screen size
TransactionAmount, currency, type

Impact of Data Quality

Data QualityFrictionless RateAuth Success
Minimal data50-60%70-75%
Standard data70-80%80-85%
Full data85-95%85-90%

PayFac 3DS Implementation

Responsibilities

PartyResponsibility
PayFacIntegrate 3DS solution
PayFacConfigure risk thresholds
PayFacMonitor authentication rates
Sub-merchantEnable 3DS for their transactions
IssuerPerform authentication

Architecture

Monitoring Metrics

MetricTargetAlert Threshold
Auth success rate> 85%< 75%
Frictionless rate> 80%< 60%
Challenge completion> 70%< 50%
Timeout rate< 5%> 10%

References

Share: