{"id":2459,"date":"2025-09-09T09:50:00","date_gmt":"2025-09-08T23:50:00","guid":{"rendered":"https:\/\/www.gpayments.com\/blog\/?p=2459"},"modified":"2025-09-09T10:35:11","modified_gmt":"2025-09-09T00:35:11","slug":"us-3d-secure-3ds2-explained-for-us-merchants","status":"publish","type":"post","link":"https:\/\/www.gpayments.com\/blog\/article\/us-3d-secure-3ds2-explained-for-us-merchants\/","title":{"rendered":"3D Secure 2 Explained for US Merchants: What\u2019s New and Why It Matters"},"content":{"rendered":"\n<p style=\"text-align: left;\" data-start=\"828\" data-end=\"1260\">If <a href=\"https:\/\/www.gpayments.com\/blog\/article\/opting-for-the-right-3d-secure-provider-a-comprehensive-guide\/\">3D Secure<\/a> still means clunky redirects and forgotten passwords to your team, you are thinking of 3DS1. EMV <a href=\"https:\/\/www.gpayments.com\/blog\/article\/evolution-of-3d-secure-2\/\">3D Secure 2<\/a> primarily operates in the background, incorporates mobile-friendly SDKs, and provides richer data, enabling issuers to approve more legitimate orders without slowing down the checkout process. The 2.3.1 update streamlines flows and broadens where it applies.<\/p>\n<h2 style=\"text-align: left;\" data-start=\"828\" data-end=\"1260\">3DS2 vs 3DS1: The Practical differences<\/h2>\n<table class=\" alignleft\">\n<thead>\n<tr>\n<th><strong>Area<\/strong><\/th>\n<th><strong>3DS1 (legacy)<\/strong><\/th>\n<th><strong>3DS2 (modern)<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>\n<p>Customer experience<\/p>\n<\/td>\n<td>Static passwords, page redirects<\/td>\n<td><strong>Frictionless by default<\/strong>, step-up only when risk is high<\/td>\n<\/tr>\n<tr>\n<td>Data sent to issuer<\/td>\n<td>Limited<\/td>\n<td><strong>Dozens of additional data elements<\/strong> to improve decisions<\/td>\n<\/tr>\n<tr>\n<td>Mobile support<\/td>\n<td>Weak, browser detours<\/td>\n<td><strong>Native iOS\/Android SDKs<\/strong> for in-app flows<\/td>\n<\/tr>\n<tr>\n<td>Use cases<\/td>\n<td>One-off web payments<\/td>\n<td>Web and app, recurring (<a href=\"https:\/\/www.gpayments.com\/blog\/user-guide\/understanding-3ri-in-3d-secure-a-business-friendly-guide\/\">3RI<\/a>), stored credentials, decoupled\/OOB<\/td>\n<\/tr>\n<tr>\n<td>Outcomes<\/td>\n<td>Interruptions, drop-off<\/td>\n<td><strong>Higher approval confidence with lower friction<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: left;\">The frictionless flow is core to 3DS2: issuers silently evaluate rich context and approve without interrupting the shopper; only higher-risk cases see a challenge.<\/p>\n<h2 style=\"text-align: left;\" data-start=\"2076\" data-end=\"2111\">Why US merchants should care now<\/h2>\n<p style=\"text-align: left;\" data-start=\"2112\" data-end=\"2320\"><strong data-start=\"2112\" data-end=\"2148\">Less friction, better decisions:<\/strong> With a richer data set and risk-based checks, issuers can approve more genuine orders and prevent more fraud without blanket challenges.<\/p>\n<p style=\"text-align: left;\" data-start=\"2322\" data-end=\"2612\"><strong data-start=\"2322\" data-end=\"2351\">Current network programs:<\/strong>\u00a0Visa Secure (3DS) and Mastercard Identity Check govern how 3DS2 is used on their networks, replacing Verified by Visa and SecureCode from the 3DS1 era. These programs align 3DS2 to modern KPIs and implementation practices.<\/p>\n<p style=\"text-align: left;\" data-start=\"2614\" data-end=\"2880\"><strong data-start=\"2614\" data-end=\"2651\">Fresh guidance for the US market:<\/strong>\u00a0The US Payments Forum continues to publish practical resources on 3DS and related mobile and ecommerce security topics, useful for aligning stakeholders across risk, product, and engineering.<\/p>\n<h2 style=\"text-align: left;\" data-start=\"3500\" data-end=\"3546\">Data Only 3DS: Zero-friction Signal Sharing<\/h2>\n<p style=\"text-align: left;\" data-start=\"3547\" data-end=\"3877\">Not ready to authenticate every transaction? <strong data-start=\"3592\" data-end=\"3605\">Data Only<\/strong> lets you send EMV 3DS data to issuers without asking the customer to complete a challenge. It boosts issuer confidence and can improve authorisation outcomes while keeping checkout fast, often a stepping stone to a fuller 3DS program.<\/p>\n<h2 style=\"text-align: left;\" data-start=\"4439\" data-end=\"4495\">Liability shift in the United States (quick overview)<\/h2>\n<p style=\"text-align: left;\" data-start=\"4496\" data-end=\"4896\">3DS can provide <strong data-start=\"4512\" data-end=\"4543\">fraud-chargeback protection<\/strong> on qualifying transactions when authentication succeeds (or under program-specific conditions). It is not a blanket shield for every dispute type, so fold authentication results into a broader disputes playbook. Check your acquirer and the relevant network program for exact eligibility and reason-code handling.<\/p>\n<h2 style=\"text-align: left;\" data-start=\"4903\" data-end=\"4928\">Implementation options<\/h2>\n<ol style=\"text-align: left;\" data-start=\"4929\" data-end=\"5325\">\n<li data-start=\"4929\" data-end=\"5044\">\n<p data-start=\"4932\" data-end=\"5044\"><strong data-start=\"4932\" data-end=\"4957\">Via your gateway\/PSP:<\/strong> quickest path if your provider exposes 3DS2 and passes through the necessary fields.<\/p>\n<\/li>\n<li data-start=\"5045\" data-end=\"5160\">\n<p data-start=\"5048\" data-end=\"5160\"><strong data-start=\"5048\" data-end=\"5069\">3DS Server + ACS:<\/strong> choose your own server and (where applicable) ACS to optimise data, routing, and policy.<\/p>\n<\/li>\n<li data-start=\"5161\" data-end=\"5325\">\n<p data-start=\"5164\" data-end=\"5325\"><strong data-start=\"5164\" data-end=\"5180\">Mobile SDKs:<\/strong> keep authentication native in your iOS\/Android apps to reduce drop-off and gather better device signals.<\/p>\n<\/li>\n<\/ol>\n<h2 data-start=\"851\" data-end=\"859\">At a Glance<\/h2>\n<p data-start=\"860\" data-end=\"1235\">If your memory of 3D Secure is clunky pages and forgotten passwords, that was 3DS1. EMV 3DS version 2 uses risk-based checks and richer data so approvals can increase with less friction. US merchants can start with Data Only to send signals without challenges, then phase in full authentication for liability protection where it applies.<\/p>\n<h2 style=\"text-align: left;\" data-start=\"5922\" data-end=\"5929\">FAQs<\/h2>\n<p style=\"text-align: left;\" data-start=\"5930\" data-end=\"6173\"><strong data-start=\"5930\" data-end=\"5974\">Will 3DS2 hurt conversion like 3DS1 did?<\/strong><br data-start=\"5974\" data-end=\"5977\" \/>Implemented correctly, it should not. Most traffic should run frictionless when you send complete, high-quality data; only higher-risk cases are stepped up.<\/p>\n<p style=\"text-align: left;\" data-start=\"6175\" data-end=\"6371\"><strong data-start=\"6175\" data-end=\"6213\">Is 3DS2 available for mobile apps?<\/strong><br data-start=\"6213\" data-end=\"6216\" \/>Yes. Certified SDKs allow in-app authentication, avoiding clunky browser detours and improving device-data quality.<\/p>\n<p style=\"text-align: left;\" data-start=\"6373\" data-end=\"6649\"><strong data-start=\"6373\" data-end=\"6421\">Do I have to authenticate every transaction?<\/strong><br data-start=\"6421\" data-end=\"6424\" \/>No. Many US merchants start with <strong data-start=\"6457\" data-end=\"6470\">Data Only<\/strong> to share signals without challenges, then phase in full authentication for use cases that benefit from liability shift or added assurance.<\/p>\n<p style=\"text-align: left;\" data-start=\"6651\" data-end=\"6865\"><strong data-start=\"6651\" data-end=\"6689\">What changed recently in the spec?<\/strong><br data-start=\"6689\" data-end=\"6692\" \/>EMV 3DS <strong data-start=\"6700\" data-end=\"6710\">v2.3.1<\/strong> introduced additional data and features to streamline authentication and broaden support for channels and devices.<\/p>\n<p style=\"text-align: left;\" data-start=\"2614\" data-end=\"2880\">\u00a0<\/p>\n<p style=\"text-align: left;\" data-start=\"2614\" data-end=\"2880\">\u00a0<\/p>\n<p style=\"text-align: left;\">\u00a0<\/p>\n<p style=\"text-align: left;\">\u00a0<\/p>\n\n\n\n\n\n\n\n\n","protected":false},"excerpt":{"rendered":"<p>If 3D Secure still means clunky redirects and forgotten passwords to your team, you are thinking of 3DS1. EMV 3D Secure 2 primarily operates in the background, incorporates mobile-friendly SDKs, and provides richer data, enabling issuers to approve more legitimate orders without slowing down the checkout process. The 2.3.1 update streamlines flows and broadens where [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":2465,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[2],"tags":[13,10,128],"class_list":["post-2459","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-article","tag-3ds2","tag-liability-shift","tag-usa"],"aioseo_notices":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/posts\/2459","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/comments?post=2459"}],"version-history":[{"count":15,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/posts\/2459\/revisions"}],"predecessor-version":[{"id":2500,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/posts\/2459\/revisions\/2500"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/media\/2465"}],"wp:attachment":[{"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/media?parent=2459"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/categories?post=2459"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/tags?post=2459"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}