The value of global e-commerce sales in 2026 is projected to reach USD 6.42 trillion, with more than 3 billion people making purchases online. While this growth creates opportunities for merchants, it also heightens the challenge of card fraud. A report projects that global card fraud will reach USD 41.06 billion in 2030 and USD 48.50 billion in 2034, a significant increase from USD 33.41 billion in 2024. As a result, there is a growing need for stronger card authentication to protect businesses and customers without disrupting the checkout experience. 3D Secure offers a solution by adding an extra layer of authentication that helps verify legitimate cardholders before a transaction is approved.
What is 3D Secure?

3D Secure (3DS) is a security protocol that requires customers to verify their identities before completing online transactions. Major card schemes developed this protocol to reduce card-not-present (CNP) fraud, where criminals use stolen card details to make purchases online. It involves a 3-domain model that includes:
-
An acquirer domain: The merchant and the acquiring bank that processes the payment
-
Issuer domain: The customer’s card issuing bank
-
Interoperability domain: The payment infrastructure that supports 3DS
When a customer initiates an online payment, 3DS runs a risk assessment in milliseconds. A high-risk transaction triggers a verification challenge, where the customer receives a one-time code. They enter it to verify their identity, and if verified, the transaction goes through.
From 3D Secure 1 to 3D Secure 2
Initially, CNP transactions were secured simply by verifying the card number, expiry date, and CVV. However, banks and merchants realised these details did not provide sufficient protection, as cyber criminals could still use stolen cards. As a result, card networks developed the first protocol, 3D Secure 1.0 (3DS1), to strengthen the security of online card transactions.
Arcot Systems developed the first protocol version for Visa. The protocol launched in 2001 under the Verified by Visa brand. Later that year, Mastercard introduced its version of the technology branded as Mastercard SecureCode. These 3DS1 protocols allowed customers to verify their identity using a static password or OTP sent via SMS or email.
While 3DS1 enhanced card authentication, it created lengthy procedures that resulted in cart abandonment. For instance, some issuers sent a code that customers had to wait for and enter before completing the payment, while others redirected them to a bank-hosted page where they entered a PIN or password. The design was primarily built for desktop browsers, which created a significant UX challenge for mobile users.
These challenges created the foundation for the 3D Secure 2.0 (3DS2) protocol. EMVCo, a collaboration between Visa, American Express, Mastercard, China UnionPay, Discover, and JCB, introduced 3DS2 in 2018. It includes a software development kit (SDK) that enables merchants to integrate authentication directly into their mobile applications.
The issuers' Access Control Server (ACS) platforms perform risk-based and biometric authentication in the background without requiring customers to complete the process at checkout. Customers may still need to provide additional authentication information if the ACS platform detects high risk. This frictionless process improves customer experience while also strengthening card authentication.
How does 3D Secure work?
3D Secure works by allowing several systems to exchange authentication data in real time before authorising an online card payment. During checkout, these components communicate behind the scenes to determine whether a transaction can proceed without interruption or whether the cardholder needs to complete an additional verification step. Understanding the role of each component helps explain how 3D Secure reduces fraud while supporting a smoother checkout experience.
|
Component |
Managed by |
Role in the authentication process |
|
3DS Server |
Merchant or payment service provider (PSP) |
Initiates the authentication request and sends transaction data to the card network. |
|
Directory Server (DS) |
Card network |
Identifies the correct card issuer and routes the authentication request. |
|
Access Control Server (ACS) |
Card issuer |
Evaluates the transaction, applies risk-based authentication, and decides whether to approve the transaction silently, request additional verification, or reject the authentication. |
|
3DS SDK (mobile only) |
Merchant's mobile app |
Enables native 3D Secure authentication within mobile applications without redirecting customers to a browser. |
Once these components exchange the information, the authentication process typically follows these steps:
-
The customer initiates a payment. The customer enters their card details and submits the payment during checkout.
-
The merchant sends the authentication request. The merchant's payment gateway or PSP uses the 3DS Server to send the transaction details to the card network's Directory Server (DS).
-
The issuer assesses the transaction: The issuer checks its internal records to verify whether the card is enrolled in 3DS1 or 3DS2 services. If the card is enrolled, the authentication process proceeds; if not, it stops.
-
Authentication of the cardholder: The issuer conducts fraud screening and risk assessment in the background for low-risk transactions. If the issuer identifies a higher-risk transaction, it prompts the customer to verify their identity using a one-time password (OTP), biometric authentication, or approval through their banking app.
-
Payment completed: The cardholder sees a payment confirmation on the merchant’s website.

How 3D Secure benefits merchants and customers
3DS adds an intelligent authentication layer to online card payments that allows businesses to reduce fraud and improve checkout security. It also creates a smoother payment experience for legitimate customers. As a result, these protocols allow issuers and merchants to balance security with convenience.
3DS2 supports frictionless authentication
Unlike earlier versions of the protocol, 3DS2 uses risk-based authentication to determine whether a transaction requires additional verification. The system sends payment-specific data to the cardholder’s bank, such as device ID, delivery address, and transaction history. The bank then uses this information to determine the transaction’s risk level. If the risk is low, the authentication proceeds automatically without requiring additional input. However, if the risk score is high, the system triggers a challenge flow that requires the customer to provide further proof.
Strengthens customer trust
Implementing 3DS protocols reassures customers that their payment information is safe. 79% of global consumers consider security as the most important concern when choosing a payment method. While these customers want frictionless payments, they also fear that fraud schemes are becoming increasingly sophisticated. As a result, integrating 3DS increases their trust in the payment process and their overall satisfaction, leading to repeat business.
Transfers responsibility
When a transaction is authenticated through 3DS, liability for certain types of fraudulent card-not-present (CNP) transactions may shift from the merchant to the card issuer. However, this liability shift depends on the scheme’s rules and applies only to authenticated transactions. Other scenarios, like technical failures, unenrolled cards, and bypass cases, may not be eligible for this liability shift.
Simplifies compliance
In many markets, 3DS helps businesses meet regulatory requirements for strong customer authentication. For example, businesses operating in regions subject to the European Union's Revised Payment Services Directive (PSD2) can use 3DS2 to support Strong Customer Authentication (SCA) for eligible online card transactions. In addition, the protocol provides a standardised authentication framework that helps businesses strengthen payment security across multiple markets.
Reduces the frequency of chargebacks
Since 3DS verifies the identity of the cardholder before the transaction is completed, it helps prevent unauthorised card use and reduces the number of successful fraudulent transactions. For this reason, merchants are less likely to receive fraud-related chargebacks. This lowers operational costs and reduces the time spent managing payment disputes.
What to look for in a 3DS provider
When selecting a 3DS provider, merchants should pay attention to the infrastructure and regulatory compliance. Some of the considerations include:
-
The provider should have the EMV 3DS certification across all major card networks, including Visa, Mastercard, Amex, and JCB. This helps ensure protection for customers using different cards for payments.
-
The protocol should support both the Access Control Server (ACS) and 3DS Server components.
-
The provider should offer services in all the markets where the merchant operates rather than focusing on a single market and support local card schemes to facilitate global expansion and scaling. For example, Antom supports the 3DS2 protocol through Antom Shield, which intelligently determines when to initiate 3DS authentication based on transaction risk characteristics and historical data. It then selects the appropriate frictionless or challenge authentication flow. Antom operates in more than 200 payment markets worldwide, supporting over 300 payment methods and 140 currencies to help merchants deliver secure, localised payment methods.
-
The system should provide real-time visibility into transaction activity to enable continuous monitoring, reporting, and timely escalation when issues arise.
Final takeaway
With the increase in online payment fraud, card authentication has become crucial for protecting businesses and customers. 3D Secure (3DS) contributes to this goal by adding a layer of card authentication that verifies the identity of the cardholder before approving a transaction. This process reduces fraud, increases conversion, and builds customer trust by reassuring them that the transactions are safe. However, merchants must partner with a 3DS provider whose infrastructure can deliver a smooth checkout experience without undermining the convenience of online transactions.
FAQs
1. What is the role of risk rules in 3D Secure authentication?
Risk rules assess the likelihood of fraud by analysing information, such as customer location, transaction amount, unusual user behaviour, and transaction frequency. This helps the issuer determine whether to trigger additional authentication.
2. Does 3D Secure work for recurring payments?
The initial payment for a recurring subscription may require 3D Secure authentication, while subsequent recurring transactions do not typically require re-authentication. However, this may vary depending on the card scheme, payment provider, and applicable regulations.
3. Does 3D Secure replace fraud prevention tools?
While 3D Secure adds a layer of cardholder authentication, it does not replace other fraud prevention measures. Merchants should use it alongside other tools that support transaction monitoring, risk scoring, and device intelligence to provide more comprehensive protection against payment fraud.