

Choosing a 3DS Server: An Evaluation Guide for Acquirers and PSPs
The 3DS Server sits on the acquirer side of the 3D Secure protocol: it builds and validates authentication requests, routes them to the correct issuer via the Directory Server, and interprets the result. For acquirers, PSPs, and payment gateways,…

EMV Token vs Network Token: What Issuers Need to Know for 3DS Provisioning
Tokenisation and 3D Secure get bundled into the same conversation often enough that the distinction between them, and how they need to work together, gets lost. Tokenisation replaces a Primary Account Number (PAN) with a surrogate value so…

PSD3 and the Payment Services Regulation: What Issuers Need to Do Before Late-2027 Enforcement
PSD3 and the Payment Services Regulation (PSR) stopped being a proposal and became a confirmed timeline this year. The European Parliament, Council, and Commission agreed final compromise texts on 23 April 2026, following provisional political…

RBA Rule Tuning: A Practical Guide to Improving Frictionless Authentication Rates
Frictionless authentication rates vary enormously between issuers running the same EMV 3DS specification, and the gap is rarely down to the ACS software itself. It's down to configuration: how much data is being fed into the risk engine, how…

Secure Payment Confirmation (SPC) and WebAuthn: Is Your ACS Ready for Passwordless 3DS?
One-time passwords sent by SMS remain the default challenge method for most 3D Secure deployments, despite being phishable, dependent on carrier delivery, and a well-documented source of cardholder drop-off. Secure Payment Confirmation (SPC)…

3D Secure Testing Before Certification: How to Avoid Costly Failures
Every 3D Secure Certification — whether it’s a 3DS Server, an Access Control Server, or a mobile SDK — must pass card scheme certification testing before it can process live transactions. Visa requires testing on its VSTS environment.…

How to Choose an ACS for 3D Secure: An Enterprise Evaluation Guide
The Access Control Server (ACS) is the issuer’s central decision-making engine in the 3D Secure protocol. It determines whether a transaction authenticates frictionlessly or requires a cardholder challenge, which authentication method to…

How 3DS2 Reduces Card-Not-Present Fraud Without Hurting Conversion
Card-not-present (CNP) fraud cost Australian businesses $816 million in 2024, accounting for 90% of all card fraud on Australian-issued cards, according to the Australian Payments Network (AusPayNet). Globally, payment card fraud losses reached…

Decoupled Authentication in EMV 3DS: Use Cases and Implementation Guide
Not every payment transaction takes place in a browser with a cardholder actively waiting for an authentication prompt. IoT devices, smart kiosks, digital wallets initiating recurring charges, and voice-activated payment interfaces all create…
