What Is Chargeback Management? How Merchants Can Protect Against Disputes
When a cardholder disputes a transaction with their bank, merchants face both financial and operational risk. We break down how the chargeback process...
Read More →EMV 3D Secure (3DS 2.0) has been one of the most comprehensive protocols developed to secure card payments since 2016. Yet many PSPs, banks and merchants still misunderstand it or see it merely as a legal obligation. In this article, we explore the true power of the protocol and the right integration strategies.
EMV 3D Secure (commonly referred to as 3D Secure 2.0) has been part of our world since 2016. Developed in response to the Strong Customer Authentication (SCA) requirements of PSD2, this protocol is one of the most comprehensive standards aimed at ensuring the security of card payments in the online environment. Yet to this day, misconceptions on both the industry and user side have overshadowed the true potential of this system.
Today, many PSPs, banks and merchants still view EMV 3D Secure as nothing more than a "legal obligation," unaware of or unable to take advantage of the strategic benefits it offers. The purpose of this article is not to explain what EMV 3D Secure is, but rather what it is not, how it is being misapplied, and why it deserves renewed attention today.
The 3-D Secure protocol was first introduced by Visa in 2001. Other schemes such as Mastercard, JCB and American Express adopted the same model under their own brands with similar systems. In version 1.0 of the protocol, the primary goal was to create a verification bridge between the cardholder and their bank to make CNP (card-not-present) transactions secure. However, the first version introduced numerous problems from a user experience perspective.
EMV 3D Secure (also known as 3DS 2.x), published by EMVCo in 2016, was developed as a solution to these issues. Unlike the old system, 3DS 2.x is compatible with mobile devices and multiple authentication methods, operates with rich data sharing, and only directs the user to a verification screen when necessary.
EMVCo's specifications, ranging from v2.0 through to v2.3.1.1, demonstrate how this protocol has evolved not only in terms of security, but also user experience and commercial efficiency.
In 3DS 1.0, users were forced to enter passwords on iframe pages they were redirected to. The pages appeared untrustworthy, creating fertile ground for phishing incidents. Cart abandonment rates increased by 10–12%.
EMV 3DS, on the other hand, offers a structure that can integrate with banks' mobile applications and supports methods such as biometric authentication (fingerprint, face recognition), mobile push notifications and passkeys. Users can now approve a payment with a single tap in their app, rather than waiting for an SMS.
EMV 3DS allows nearly 100 data fields to be sent to the card-issuing institution during a transaction. These fields include details such as device information, IP address, transaction location and previous purchase history. The issuing bank analyses the transaction risk using this information and, if it deems it appropriate, completes the transaction without directing the user to any verification screen (frictionless flow).
The risk scoring system (RBA – Risk Based Authentication) is one of the strongest aspects of EMV 3DS. Through analyses based on user habits, the system can avoid unnecessary challenge screens. For example, if a user is making a payment from the same device at a site where they regularly shop, the system may assess the transaction as low risk and approve it automatically.
This frequently heard remark is a bias left over from the 3DS 1.0 experience. When EMV 3DS is correctly integrated, it actually increases transaction approval rates. As long as users are not forced into verification, cart abandonment rates fall.
Many banks still use only SMS OTP for verification today. Yet alternatives offered by EMV 3DS, such as push notifications and biometrics, speed up the verification process and make it more secure.
EMV 3DS systems integrated at a minimum level to achieve PSD2 and SCA compliance lack the potential to create real value. Yet when used correctly, this system reduces fraud risk, prevents chargebacks and optimises the customer experience.
Transactions are managed through message pairs such as AReq (Authentication Request) and ARes (Authentication Response). The payment service provider or virtual POS sends these messages to the card-issuing bank via the 3DS server. An EMV 3DS AReq message can contain more than 150 data elements. This enables the system to conduct more accurate risk analysis, increase frictionless flows and reduce unnecessary "challenge" steps.
Thanks to this data set, the bank can evaluate the transaction in the background and route it towards a "frictionless," i.e. verification-free, approval.
In the European Union, PSD2 requires all online transactions to be subject to SCA (Strong Customer Authentication). EMV 3DS is the most effective solution meeting this requirement.
For transactions processed through EMV 3DS: if verification is successful, liability shifts to the card-issuing institution in the event of fraud. If verification fails or has not been applied, liability remains with the merchant. This makes a critical difference for merchants. Chargeback costs arising from fraud — particularly for high-volume e-commerce operations — can be significantly reduced in this way.
Many PSPs and banks today are still unable to fully benefit from the advantages offered by EMV 3DS due to the following reasons:
Such shortcomings not only increase cart abandonment rates but also fail to reduce fraud risk.
With the release of EMV 3DS v2.3.1.1 in 2023, significant new features were introduced:
These features reduce the vulnerabilities created by password-dependent systems and optimise the user experience.
EMV 3DS is not merely an obligation — when used correctly, it is a competitive advantage. As an industry, we must understand this protocol "correctly," reshape our integration strategies, and provide customers with a genuinely secure yet frictionless experience.
"Those who misapply EMV 3D Secure today will not be ready for tomorrow's passkey-based world either."
For this reason, we must reunderstand the past, optimise the present, and invest in the future today. EMV 3D Secure is still far behind its potential. Now is the time to close that gap.
For virtual POS, payment orchestration and integration needs, let our expert team guide you to the best solution.
When a cardholder disputes a transaction with their bank, merchants face both financial and operational risk. We break down how the chargeback process...
Read More →Rule-based fraud systems are no longer enough. We explain how machine learning models use device fingerprinting, behavioural biometrics, and real-time...
Read More →With the advancement of technology, the way we pay for goods and services has changed significantly. Pay by Link Payment allows customers to make paym...
Read More →