
Multi-Jurisdictional 3DS Compliance: PSD2, PSD3 & AusPayNet
A global processor or an issuer with cardholders across the European Union and Australia cannot simply pick one regulatory regime and apply it everywhere. EU cardholders fall under PSD2's Strong Customer Authentication rules today and the incoming…

Full-Stack 3D Secure: Cutting Integration Risk vs Multi-Vendor
Every EMV 3D Secure deployment starts with an architecture decision that outlasts vendor selection itself: will the 3DS Server, ACS, mobile SDK and test environment come from one provider, or be stitched together from several? That decision…

Why SPC Support for Issuers Matters Ahead of FIDO Adoption
Passwordless authentication has moved from a browser specification to a live capability inside EMV 3D Secure, and issuers who wait for a card scheme mandate before evaluating it will be planning reactively rather than ahead of the curve. Secure…

ACS Multi-Tenancy Architecture: Managing Multiple Issuers
Processors and programme managers rarely serve a single issuer. A typical portfolio might include a dozen community banks, several fintech card programmes and one or two large issuing clients, each needing its own branding, risk rules and card…

Choosing a 3DS Server: An Evaluation Guide for Acquirers and PSPs
The 3DS Server sits on the acquirer side of the 3D Secure protocol: it builds and validates authentication requests, routes them to the correct issuer via the Directory Server, and interprets the result. For acquirers, PSPs, and payment gateways,…

EMV Token vs Network Token: What Issuers Need to Know for 3DS Provisioning
Tokenisation and 3D Secure get bundled into the same conversation often enough that the distinction between them, and how they need to work together, gets lost. Tokenisation replaces a Primary Account Number (PAN) with a surrogate value so…

PSD3 and the Payment Services Regulation: What Issuers Need to Do Before Late-2027 Enforcement
PSD3 and the Payment Services Regulation (PSR) stopped being a proposal and became a confirmed timeline this year. The European Parliament, Council, and Commission agreed final compromise texts on 23 April 2026, following provisional political…

RBA Rule Tuning: A Practical Guide to Improving Frictionless Authentication Rates
Frictionless authentication rates vary enormously between issuers running the same EMV 3DS specification, and the gap is rarely down to the ACS software itself. It's down to configuration: how much data is being fed into the risk engine, how…

Secure Payment Confirmation (SPC) and WebAuthn: Is Your ACS Ready for Passwordless 3DS?
One-time passwords sent by SMS remain the default challenge method for most 3D Secure deployments, despite being phishable, dependent on carrier delivery, and a well-documented source of cardholder drop-off. Secure Payment Confirmation (SPC)…

3D Secure Testing Before Certification: How to Avoid Costly Failures
Every 3D Secure Certification — whether it’s a 3DS Server, an Access Control Server, or a mobile SDK — must pass card scheme certification testing before it can process live transactions. Visa requires testing on its VSTS environment.…
