Skip to main content

3D Secure

Last Updated: 2025-02-17 Status: Complete

3D Secure (3DS) is an authentication protocol that adds a layer of security for card-not-present transactions. For PayFac platforms, 3DS is essential for reducing fraud and shifting liability away from merchants.

Quick Reference​

ItemStatus (2026)
Current Version3DS 2.2
3DS 1.0Discontinued October 2022
Global Merchant Adoption65%
Frictionless Success Rate90-95%
Top Performing RegionsUK, Ireland, Netherlands

What is 3D Secure?​

3D Secure adds cardholder authentication to CNP transactions. "3D" refers to three domains involved:

Brand Names​

Network3DS Brand Name
VisaVisa Secure
MastercardMastercard Identity Check
American ExpressSafeKey
DiscoverProtectBuy
JCBJ/Secure

3DS2 vs 3DS1​

3DS1 Discontinued

Visa discontinued 3DS 1.0 support in October 2022. All merchants must use 3DS2.

Feature3DS13DS2
User experiencePage redirectEmbedded/native
Mobile supportPoorOptimized
Data points~15~100+
Frictionless flowNoYes
Risk-based authNoYes
Abandonment rate10-15%3-5%

Authentication Flows​

Frictionless Flow​

Most transactions (90-95%) complete without customer interaction:

Challenge Flow​

High-risk transactions require customer verification:

Challenge Methods​

MethodDescriptionUser Experience
OTP via SMSCode sent to phoneMedium friction
OTP via AppCode in banking appMedium friction
Push notificationApprove in appLow friction
BiometricFingerprint/Face IDLow friction
Knowledge-basedSecurity questionsHigh friction

ECI Indicators​

ECI (Electronic Commerce Indicator) values indicate the authentication result and determine liability shift:

Visa / Amex / Discover / JCB​

ECIMeaningLiability Shift
05Fully authenticatedYes
06Attempted (cardholder not enrolled)Yes
07Authentication failed/not availableNo

Mastercard​

ECIMeaningLiability Shift
02Fully authenticatedYes
01Attempted (stand-in service)Yes
00Authentication failedNo
04Data Only (frictionless)No
06SCA exemption appliedNo
07Recurring authenticatedYes
Key Values

ECI 05 (Visa) / 02 (MC) = Full authentication, full liability shift

Liability Shift​

When 3DS authentication succeeds, liability for fraud chargebacks shifts from merchant to issuer.

How Liability Shift Works​

Liability Shift by Network​

NetworkShift DurationCoverage
Visa90 daysFraud chargebacks only
Mastercard30 days → 90 daysFraud chargebacks only
AmexVariesFraud chargebacks only
DiscoverVariesFraud chargebacks only

What Liability Shift Does NOT Cover​

Not CoveredExplanation
Friendly fraudCardholder disputes legitimate purchase
Not receivedDelivery disputes
Not as describedProduct quality disputes
Service disputesAny non-fraud reason code
Critical Limitation

Liability shift only applies to fraud chargebacks (reason codes 10.4/4837). Friendly fraud, which represents up to 75% of all chargebacks (source: industry estimates 2024-2025), is NOT covered by liability shift.

PSD2 & Strong Customer Authentication (SCA)​

PSD2 (Payment Services Directive 2) requires Strong Customer Authentication for European transactions.

SCA Requirements​

SCA requires two of three authentication factors:

FactorTypeExamples
KnowledgeSomething you knowPassword, PIN, security question
PossessionSomething you havePhone, token, card
InherenceSomething you areFingerprint, face, voice

SCA Timeline​

DateEvent
September 14, 2019PSD2 SCA mandate effective
December 31, 2020Final enforcement deadline
October 14, 2024France: €100 daily exemption limit
March 10, 2025France: Auth exemptions restricted to EMV 3DS
~2026PSD3/PSR1 expected

SCA Exemptions​

ExemptionCriteria3DS Required?
Low value< €30 (max 5 consecutive or €100 cumulative)No
Low risk (TRA)Fraud rate thresholds metNo
Trusted beneficiaryCardholder whitelisted merchantNo
RecurringSame amount, same merchantFirst transaction only
Corporate cardsB2B paymentsMay be exempt

Transaction Risk Analysis (TRA) Thresholds​

PSPs meeting fraud rate thresholds can request exemptions:

Fraud RateMaximum Exemption Value
≤ 0.01%€500
≤ 0.06%€250
≤ 0.13%€100

Implementation Considerations​

Integration Approaches​

ApproachDescriptionComplexity
RedirectCustomer redirected to 3DS pageLow
Embedded (iframe)3DS in modal on checkoutMedium
SDK (mobile)Native in-app experienceHigh
APIFull control via APIsHigh

Impact on Conversion​

FactorImpact
Challenge flow5-20 second delay
Abandonment (3DS2)3-5%
Abandonment (3DS1)10-15%

Best Practices​

PracticeBenefit
Send maximum dataHigher frictionless rate
Use current SDKBest mobile experience
Handle timeoutsGraceful fallback
Test thoroughlySandbox testing essential
Monitor auth ratesTrack and optimize

Regional Requirements​

Japan (April 2025)​

RequirementDetail
Effective dateApril 1, 2025
Mandate3DS2 required on all transactions
ImpactAll merchants must implement

Australia (AusPayNet)​

RequirementThreshold
Fraud losses> AUD 50,000
Fraud ratio> 0.2% for 2 consecutive quarters
ActionMust implement 3DS2

Europe (PSD2/SCA)​

RequirementStatus
SCA mandateIn effect
ExemptionsAvailable with TRA
EnforcementActive

3DS Data Elements​

Key Data Points Sent​

CategoryExamples
CardholderName, email, phone
BillingAddress, postal code, country
ShippingAddress, method, indicator
AccountAccount age, transactions in 24h
DeviceIP, user agent, screen size
TransactionAmount, currency, type

Impact of Data Quality​

Data QualityFrictionless RateAuth Success
Minimal data50-60%70-75%
Standard data70-80%80-85%
Full data85-95%85-90%

PayFac 3DS Implementation​

Responsibilities​

PartyResponsibility
PayFacIntegrate 3DS solution
PayFacConfigure risk thresholds
PayFacMonitor authentication rates
Sub-merchantEnable 3DS for their transactions
IssuerPerform authentication

Architecture​

Monitoring Metrics​

MetricTargetAlert Threshold
Auth success rate> 85%< 75%
Frictionless rate> 80%< 60%
Challenge completion> 70%< 50%
Timeout rate< 5%> 10%

References​

Share: