EMV Token vs Network Token: What Issuers Need to Know for 3DS Provisioning

Tokenisation and 3D Secure get bundled into the same conversation often enough that the distinction between them, and how they need to work together, gets lost. Tokenisation replaces a Primary Account Number (PAN) with a surrogate value so…

PSD3 and the Payment Services Regulation: What Issuers Need to Do Before Late-2027 Enforcement

PSD3 and the Payment Services Regulation (PSR) stopped being a proposal and became a confirmed timeline this year. The European Parliament, Council, and Commission agreed final compromise texts on 23 April 2026, following provisional political…

RBA Rule Tuning: A Practical Guide to Improving Frictionless Authentication Rates

Frictionless authentication rates vary enormously between issuers running the same EMV 3DS specification, and the gap is rarely down to the ACS software itself. It's down to configuration: how much data is being fed into the risk engine, how…

Secure Payment Confirmation (SPC) and WebAuthn: Is Your ACS Ready for Passwordless 3DS?

One-time passwords sent by SMS remain the default challenge method for most 3D Secure deployments, despite being phishable, dependent on carrier delivery, and a well-documented source of cardholder drop-off. Secure Payment Confirmation (SPC)…
3DS Testing

3D Secure Testing Before Certification: How to Avoid Costly Failures

Every 3D Secure Certification — whether it’s a 3DS Server, an Access Control Server, or a mobile SDK — must pass card scheme certification testing before it can process live transactions. Visa requires testing on its VSTS environment.…
Choosing ACS

How to Choose an ACS for 3D Secure: An Enterprise Evaluation Guide

The Access Control Server (ACS) is the issuer’s central decision-making engine in the 3D Secure protocol. It determines whether a transaction authenticates frictionlessly or requires a cardholder challenge, which authentication method to…

How 3DS2 Reduces Card-Not-Present Fraud Without Hurting Conversion

Card-not-present (CNP) fraud cost Australian businesses $816 million in 2024, accounting for 90% of all card fraud on Australian-issued cards, according to the Australian Payments Network (AusPayNet). Globally, payment card fraud losses reached…
Decoupled authentication flow in EMV 3DS

Decoupled Authentication in EMV 3DS: Use Cases and Implementation Guide

Not every payment transaction takes place in a browser with a cardholder actively waiting for an authentication prompt. IoT devices, smart kiosks, digital wallets initiating recurring charges, and voice-activated payment interfaces all create…
3-D Secure authentication for Australian merchants

3-D Secure for Australian Merchants: What You Need to Know in 2026

Card-not-present (CNP) fraud on Australian-issued cards reached $913 million in 2024, a 20% increase year-on-year, according to the Australian Payments Network’s (AusPayNet) 2025 Australian Payment Fraud Report. CNP fraud now accounts for…
PSD2 Europe

3D Secure and PSD2 Strong Customer Authentication: A Guide for European and UK PSPs

PSD2 SCA requires most remote card payments in the EU and UK to use at least two independent authentication factors. EMV 3DS2 is the main way to meet this for card‑not‑present transactions, via challenges or eligible frictionless exemptions.