Tag Archive for: 3DS2

The 3DS challenge iframe settings that are now requirements rather than recommendations
Most merchants set up their challenge iframe once, during the original 3DS integration, and have not looked at it since. That was defensible when the guidance was advisory. It is not any more.
EMVCo released the EMV 3D Secure Browser Flow…

How Bridging Message Extensions Support New Features in Older 3DS Products
No payments estate upgrades in a single step. Some components move to a new protocol version quickly, others are constrained by vendor release cycles, scheme certification windows or simply by the fact that they work and nobody wants to touch…

When an Issuer Lets the Merchant Authenticate the Cardholder
A cardholder unlocks a retailer's app with their face, browses, and checks out. They are then asked to authenticate again, this time by their bank, using a code sent by text message. The second authentication is weaker than the first and considerably…

How Trust Lists Reduce Challenges for Merchants Cardholders Trust
Every issuer has a cardholder who buys from the same three merchants every week and gets challenged every time. The risk model is not wrong exactly. It just has no way of knowing what the cardholder knows, which is that this particular…

How Exemptions Are Requested, Granted and Reported Across the 3DS Message Flow
Most discussion of Strong Customer Authentication exemptions happens at policy level. Which exemptions exist, what the thresholds are, when a regulator expects them to apply. That conversation is well covered.
What gets much less attention…

3-D Secure for Australian Merchants: What You Need to Know in 2026
Card-not-present (CNP) fraud on Australian-issued cards reached $913 million in 2024, a 20% increase year-on-year, according to the Australian Payments Network’s (AusPayNet) 2025 Australian Payment Fraud Report. CNP fraud now accounts for…

3D Secure and PSD2 Strong Customer Authentication: A Guide for European and UK PSPs
PSD2 SCA requires most remote card payments in the EU and UK to use at least two independent authentication factors. EMV 3DS2 is the main way to meet this for card‑not‑present transactions, via challenges or eligible frictionless exemptions.

What Is 3D Secure? A Complete 2026 Guide for Enterprise Payment Teams
3D Secure (3DS) is a payment authentication protocol that protects card-not-present transactions by adding a real-time identity verification step between the cardholder, their issuing bank, and the merchant.

EMV 3DS 2.x vs 3DS 1.0: What Changed and Why It Matters
EMV 3DS 2.x replaced 3DS 1.0 by shifting from static password authentication to risk-based authentication using more than 100 transaction data elements. The result is that over 90 percent of transactions are now approved frictionlessly without customer interaction.
The Evolution from Mobile SDK to Default SDK in EMV 3DS
Mobile authentication has changed noticeably since the early days of EMV 3DS. The original Mobile SDK was designed at a time when device operating systems, app security frameworks, and authentication methods were developing at different speeds.…
