{"id":2941,"date":"2026-08-17T13:58:58","date_gmt":"2026-08-17T03:58:58","guid":{"rendered":"https:\/\/www.gpayments.com\/blog\/?p=2941"},"modified":"2026-08-17T14:27:34","modified_gmt":"2026-08-17T04:27:34","slug":"acs-vs-3ds-server-difference","status":"publish","type":"post","link":"https:\/\/www.gpayments.com\/blog\/user-guide\/acs-vs-3ds-server-difference\/","title":{"rendered":"ACS vs 3DS Server vs Directory Server: What&#8217;s the Difference and Who Needs Which"},"content":{"rendered":"\n<p>As online payments grow and AusPayNet and PSD2\/PSD3 rules enforce Strong Customer Authentication (SCA), implementing 3D Secure (3DS2) is essential for preventing payment fraud and securing liability shifts. However, technical buyers often struggle to distinguish between Access Control Servers (ACS), 3DS Servers, and Directory Servers (DS).<\/p>\n<p>Understanding the distinction between issuer vs acquirer authentication infrastructure is critical to selecting the right technology stack. This guide clarifies the operational roles of each component and explains which solution your organisation requires.<\/p>\n<h2><b>The Three Roles in a 3D Secure Transaction<\/b><\/h2>\n<p>A 3D Secure transaction relies on three operational domains &#8211; Issuer Domain, Acquirer Domain, and Interoperability Domain &#8211; working together to authenticate payments.<\/p>\n<p>EMVCo architected 3D Secure to maintain clear operational boundaries:<\/p>\n<ul>\n<li aria-level=\"1\"><b>Issuer Domain<\/b>: Card-issuing bank and cardholder verifying identity and assessing risk<\/li>\n<li aria-level=\"1\"><b>Acquirer Domain<\/b>: Merchant, acquiring bank, and PSP collecting device telemetry and initiating authentication<\/li>\n<li aria-level=\"1\"><b>Interoperability Domain<\/b>: Card networks (including EFTPOS, Visa, and Mastercard) routing messages between domains<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-2942 aligncenter\" src=\"https:\/\/www.gpayments.com\/blog\/wp-content\/uploads\/2026\/08\/Diagram-1.png\" alt=\"\" width=\"1694\" height=\"702\" srcset=\"https:\/\/www.gpayments.com\/blog\/wp-content\/uploads\/2026\/08\/Diagram-1.png 1694w, https:\/\/www.gpayments.com\/blog\/wp-content\/uploads\/2026\/08\/Diagram-1-300x124.png 300w, https:\/\/www.gpayments.com\/blog\/wp-content\/uploads\/2026\/08\/Diagram-1-1030x427.png 1030w, https:\/\/www.gpayments.com\/blog\/wp-content\/uploads\/2026\/08\/Diagram-1-768x318.png 768w, https:\/\/www.gpayments.com\/blog\/wp-content\/uploads\/2026\/08\/Diagram-1-1536x637.png 1536w, https:\/\/www.gpayments.com\/blog\/wp-content\/uploads\/2026\/08\/Diagram-1-1500x622.png 1500w, https:\/\/www.gpayments.com\/blog\/wp-content\/uploads\/2026\/08\/Diagram-1-705x292.png 705w\" sizes=\"auto, (max-width: 1694px) 100vw, 1694px\" \/><\/p>\n<h2><b>Access Control Server (ACS) &#8211; The Issuer&#8217;s Side<\/b><\/h2>\n<p>An Access Control Server (ACS) is the software component in 3D Secure owned and operated by card-issuing banks (issuers) to verify cardholder identity during online purchases.<\/p>\n<p>Positioned in the Issuer Domain, the ACS receives authentication requests from card networks. It evaluates transaction details and behavioural analytics to decide between passive approval (frictionless flow) or step-up verification (challenge flow).<\/p>\n<h3><b>Key Responsibilities of an ACS<\/b><\/h3>\n<ul>\n<li aria-level=\"1\"><b>Risk-Based Analysis (RBA)<\/b>: Evaluates device fingerprints and IP data to approve low-risk transactions silently.<\/li>\n<li aria-level=\"1\"><b>Challenge Management<\/b>: Presents step-up verification prompts &#8211; such as biometrics or OTPs &#8211; for high-risk transactions.<\/li>\n<li aria-level=\"1\"><b>Cryptogram Generation<\/b>: Issues digital signatures and Authentication Values (CAVV\/AAV) confirming identity verification.<\/li>\n<li aria-level=\"1\"><b>Regulatory Compliance<\/b>: Ensures issuing banks meet mandatory regulations, including AusPayNet rules and PSD2\/PSD3 SCA mandates.<\/li>\n<\/ul>\n<p>Issuing banks, neobanks, and credit unions require an ACS (such as GPayments&#8217; <a href=\"https:\/\/www.gpayments.com\/solutions\/issuing\/\">ActiveAccess<\/a>) to protect card portfolios.<\/p>\n<h2><b>3DS Server &#8211; The Acquirer&#8217;s Side (current standard, replaces the legacy MPI)<\/b><\/h2>\n<p>A 3DS Server is the modern 3D Secure 2.x protocol engine operated on the acquirer or merchant side that initiates authentication requests, collects device data, and processes cryptograms prior to payment authorisation.<\/p>\n<p>Operating in the Acquirer Domain, the 3DS Server connects checkout environments (via web or mobile SDKs) to card scheme networks. It orchestrates data exchanges, formatting authentication requests (AReq) and consuming responses (ARes).<\/p>\n<h3><b>Key Responsibilities of a 3DS Server<\/b><\/h3>\n<ul>\n<li aria-level=\"1\"><b>Device Telemetry Orchestration<\/b>: Communicates with front-end SDKs to collect browser or app telemetry.<\/li>\n<li aria-level=\"1\"><b>Protocol Messaging<\/b>: Formats and transmits encrypted AReq payloads to the card scheme Directory Server.<\/li>\n<li aria-level=\"1\"><b>Cryptogram Handling<\/b>: Passes cryptograms and liability shift indicators to the gateway or acquirer for authorisation.<\/li>\n<li aria-level=\"1\"><b>Frictionless Optimisation<\/b>: Formats data payloads cleanly to maximise frictionless approval rates by issuing banks.<\/li>\n<\/ul>\n<p>Merchants, PSPs, gateways, and acquiring banks require a 3DS Server (such as GPayments&#8217; <a href=\"https:\/\/www.gpayments.com\/solutions\/acquiring\/\">ActiveServer<\/a>) to initiate 3DS2 authentication.<\/p>\n<h2><b>Where MPI Fits In (and Why It&#8217;s Being Phased Out)<\/b><\/h2>\n<p>A Merchant Plug-In (MPI) is a legacy software component used strictly under obsolete 3D Secure 1.0.2, which has been phased out in favour of modern 3DS Servers.<\/p>\n<p>Historically, merchants integrated an MPI to handle pop-up password redirects. However, legacy MPIs lacked mobile SDKs, could not process telemetry, and caused cart abandonment. With 3DS 1.0.2 deprecated globally, MPIs have been replaced by 3DS Servers.<\/p>\n<p><i>(Note: ActiveMerchant served as an MPI during 3DS 1.0. Modern merchant integrations rely on ActiveServer).<\/i><\/p>\n<h2><b>Directory Server (DS) &#8211; Owned by the Card Schemes, Not by 3DS Vendors<\/b><\/h2>\n<p>A Directory Server (DS) is a central payment network server operated exclusively by card schemes (e.g., Visa, Mastercard, EFTPOS) to validate and route 3D Secure authentication traffic.<\/p>\n<p>The Directory Server acts as a central switchboard, verifying Bank Identification Numbers (BINs) and routing messages to the designated issuer ACS. Commercial vendors do not sell production Directory Servers because card schemes operate their own production DS infrastructure.<\/p>\n<p>However, vendors offer simulated Directory Server modules within sandbox environments. For instance, <a href=\"https:\/\/www.gpayments.com\/solutions\/testing\/\">TestLabs<\/a> includes a simulated Directory Server alongside test ACS and 3DS Server nodes for end-to-end integration testing.<\/p>\n<h2><b>How the Three Connect (Authentication Flow, 3DS2)<\/b><\/h2>\n<p>In a 3DS2 transaction flow, authentication moves sequentially from the merchant&#8217;s 3DS Server through the card scheme&#8217;s Directory Server to the issuing bank&#8217;s Access Control Server (ACS), returning an authenticated cryptogram back along the same path.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-2943 aligncenter\" src=\"https:\/\/www.gpayments.com\/blog\/wp-content\/uploads\/2026\/08\/Diagram-2.png\" alt=\"\" width=\"484\" height=\"726\" srcset=\"https:\/\/www.gpayments.com\/blog\/wp-content\/uploads\/2026\/08\/Diagram-2.png 1024w, https:\/\/www.gpayments.com\/blog\/wp-content\/uploads\/2026\/08\/Diagram-2-200x300.png 200w, https:\/\/www.gpayments.com\/blog\/wp-content\/uploads\/2026\/08\/Diagram-2-687x1030.png 687w, https:\/\/www.gpayments.com\/blog\/wp-content\/uploads\/2026\/08\/Diagram-2-768x1152.png 768w, https:\/\/www.gpayments.com\/blog\/wp-content\/uploads\/2026\/08\/Diagram-2-1000x1500.png 1000w, https:\/\/www.gpayments.com\/blog\/wp-content\/uploads\/2026\/08\/Diagram-2-470x705.png 470w\" sizes=\"auto, (max-width: 484px) 100vw, 484px\" \/><\/p>\n\n\n\n\n\n<h3><b>Authentication Sequence:<\/b><\/h3>\n<ul>\n<li aria-level=\"1\"><b>1. Data Collection<\/b>: Merchant SDK gathers device parameters and sends them to the <b>3DS Server<\/b>.<\/li>\n<li aria-level=\"1\"><b>2. Request Routing<\/b>: <b>3DS Server<\/b> formats an AReq and sends it to the <b>Directory Server<\/b>, which routes it to the <b>ACS<\/b>.<\/li>\n<li aria-level=\"1\"><b>3. Evaluation<\/b>: <b>ACS<\/b> evaluates risk and returns an ARes with a CAVV\/AAV cryptogram.<\/li>\n<li aria-level=\"1\"><b>4. Completion<\/b>: <b>Directory Server<\/b> passes the ARes back to the <b>3DS Server<\/b>, which forwards the cryptogram for authorisation.<\/li>\n<\/ul>\n<h2><b>Which One Does Your Organisation Need?<\/b><\/h2>\n<p>Determining which 3D Secure component your organisation needs depends on whether you operate on the issuing side or acquiring side of payments.<\/p>\n<table style=\"width: 100%; height: 340px;\">\n<tbody>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\">\n<p><b>Organisation Type<\/b><\/p>\n<\/td>\n<td style=\"height: 68px;\">\n<p><b>Primary Responsibility<\/b><\/p>\n<\/td>\n<td style=\"height: 68px;\">\n<p><b>Required Component<\/b><\/p>\n<\/td>\n<td style=\"height: 68px;\">\n<p><b>Primary Goal<\/b><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\">\n<p>Card Issuer \/ Neobank<\/p>\n<\/td>\n<td style=\"height: 68px;\">\n<p>Authenticate cardholders &amp; manage risk<\/p>\n<\/td>\n<td style=\"height: 68px;\">\n<p>ACS<\/p>\n<\/td>\n<td style=\"height: 68px;\">\n<p>Prevent fraud, enforce SCA, reduce friction<\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\">\n<p>Merchant \/ PSP \/ Gateway<\/p>\n<\/td>\n<td style=\"height: 68px;\">\n<p>Collect telemetry &amp; initiate 3DS<\/p>\n<\/td>\n<td style=\"height: 68px;\">\n<p>3DS Server<\/p>\n<\/td>\n<td style=\"height: 68px;\">\n<p>Secure liability shift, lower cart abandonment<\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\">\n<p>Acquiring Bank<\/p>\n<\/td>\n<td style=\"height: 68px;\">\n<p>Process merchant payments<\/p>\n<\/td>\n<td style=\"height: 68px;\">\n<p>3DS Server<\/p>\n<\/td>\n<td style=\"height: 68px;\">\n<p>Provide integrated authentication to merchants<\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 68px;\">\n<td style=\"height: 68px;\">\n<p>Card Network \/ Scheme<\/p>\n<\/td>\n<td style=\"height: 68px;\">\n<p>Route 3DS messages across domains<\/p>\n<\/td>\n<td style=\"height: 68px;\">\n<p>Directory Server (DS)<\/p>\n<\/td>\n<td style=\"height: 68px;\">\n<p>Maintain global scheme routing infrastructure<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3><b>Decision Summary<\/b><\/h3>\n<ul>\n<li aria-level=\"1\"><b>Issuing Institutions<\/b>: Require an <b>ACS<\/b> (e.g., ActiveAccess).<\/li>\n<li aria-level=\"1\"><b>Merchants &amp; Acquirers<\/b>: Require a <b>3DS Server<\/b> (e.g., ActiveServer).<\/li>\n<li aria-level=\"1\"><b>Testing Teams<\/b>: Require a sandbox environment (e.g., TestLabs) with simulated ACS, 3DS Server, and DS endpoints.<\/li>\n<\/ul>\n<h2><b>Frequently Asked Questions (FAQs)<\/b><\/h2>\n<p><b>What is an ACS?<\/b><\/p>\n<p>An Access Control Server (ACS) is an issuer-side 3D Secure component operated by card-issuing banks to verify cardholder identity, assess transaction risk, and handle step-up authentication.<\/p>\n<p><b>What is a 3DS Server?<\/b><\/p>\n<p>A 3DS Server is an acquirer-side 3D Secure component operated by merchants, PSPs, and acquirers to collect device telemetry, initiate authentication requests (AReq), and process cryptograms under 3DS2 protocols.<\/p>\n<p><b>Is MPI still used?<\/b><\/p>\n<p>No, the Merchant Plug-In (MPI) was built for obsolete 3D Secure 1.0.2. Modern platforms use 3DS Servers, which support 3DS2 data flows, mobile SDKs, and frictionless authentication.<\/p>\n<p><b>Do I need both ACS and 3DS Server?<\/b><\/p>\n<p>No, single organisations rarely require both unless operating as both an issuer and acquirer. Merchants and acquirers only need a 3DS Server, while card issuers only need an ACS.<\/p>\n<p><b>Does GPayments offer a Directory Server?<\/b><\/p>\n<p>GPayments does not sell production Directory Servers, as card schemes operate production DS networks. However, GPayments provides TestLabs, an integrated sandbox containing a simulated Directory Server for end-to-end testing.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As online payments grow and AusPayNet and PSD2\/PSD3 rules enforce Strong Customer Authentication (SCA), implementing 3D Secure (3DS2) is essential for preventing payment fraud and securing liability shifts. However, technical buyers often struggle to distinguish between Access Control Servers (ACS), 3DS Servers, and Directory Servers (DS). Understanding the distinction between issuer vs acquirer authentication infrastructure [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":2954,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[9],"tags":[],"class_list":["post-2941","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-user-guide"],"aioseo_notices":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/posts\/2941","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/comments?post=2941"}],"version-history":[{"count":10,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/posts\/2941\/revisions"}],"predecessor-version":[{"id":2987,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/posts\/2941\/revisions\/2987"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/media\/2954"}],"wp:attachment":[{"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/media?parent=2941"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/categories?post=2941"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gpayments.com\/blog\/wp-json\/wp\/v2\/tags?post=2941"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}