Direct Answer
3-D Secure is a cardholder authentication protocol for online card purchases. EMVCo, which maintains the EMV 3DS specifications, describes it as a message exchange between the merchant and the card issuer carrying transaction, payment-method and device data, which the issuer uses to decide whether the payer is the legitimate cardholder. Many payments clear on that data alone; higher-risk ones get a challenge such as a one-time passcode or biometrics. Authentication is a step before authorization, and, where scheme rules and the recorded result allow, it can also change who carries a fraud dispute.
Source: EMVCo, “EMV® 3-D Secure” (protocol scope and outcomes); Visa, “Visa Product and Service Rules, §11.7.5.3 (edition 18 April 2026)” (Visa fraud-dispute rules; ECI 5/6 rows, Country/Region “All”), accessed 2026-09-04.
What 3DS checks, and who decides
3-D Secure is an authentication protocol for card-not-present purchases. EMVCo, which maintains the EMV 3DS specifications, describes it as an exchange of messages between the merchant and the card issuer carrying data about the transaction, the payment method and the device. The issuer uses that data to judge whether the person paying is the legitimate cardholder. The decision belongs to the issuer, not to the merchant or to the payment gateway that carries the message.
Source: EMVCo, “EMV® 3-D Secure” (protocol scope and authentication outcomes), accessed 2026-09-04.
Frictionless and challenge outcomes
EMVCo describes two broad results. For many purchases the submitted data is enough and the shopper simply completes the order. For higher-risk ones the issuer may require a challenge — a one-time passcode, knowledge-based questions, biometrics or another method. Adyen documents the same split in its native implementation as a frictionless flow and a challenge flow, and offers a redirect implementation that sends the shopper to the issuer’s site instead. Which path a given payment takes is the issuer’s call, so a checkout has to handle both.
Source: EMVCo, “EMV® 3-D Secure” (protocol scope and authentication outcomes); Adyen, “3D Secure 2 authentication” (this provider’s native, redirect, frictionless and challenge flows), accessed 2026-09-04.
Authentication is not authorization
A completed authentication does not settle whether the payment will be approved. Authentication and payment authorization are separate steps, and an authenticated transaction can still be refused. Adyen’s refusal-reason list includes “3D Not Authenticated” for authentication that was not executed or did not succeed, “3DS Authentication Error” for a failure at the card network or issuer, and “Authentication required” where the issuing bank declined an exemption request. Those names are Adyen’s; other providers label the same conditions differently.
Source: Adyen, “Refusal reasons” (this provider’s refusal-reason names), accessed 2026-09-04.
How liability moves under scheme rules
The liability shift is a dispute rule, not a payment feature. Under the Visa rules, a card-absent fraud dispute is invalid where the transaction carried Electronic Commerce Indicator 5, the issuer answered the authentication request with an authentication confirmation using Visa Secure with EMV 3DS, and the Cardholder Authentication Verification Value (CAVV) was in the authorization request. A separate entry covers an attempt response with ECI 6 and excludes non-reloadable prepaid card transactions. Both entries are listed under Country/Region “All”; other entries in the same table apply only to named countries. That closes one fraud chargeback condition; it says nothing about non-fraud dispute reasons, and each scheme publishes its own rules.
Source: Visa, “Visa Core Rules and Visa Product and Service Rules, §11.7.5.3 Dispute Condition 10.4: Other Fraud – Card-Absent Environment – Invalid Disputes (edition 18 April 2026)” (Visa rules only, other schemes publish their own; the ECI 5 and ECI 6 entries are listed under Country/Region “All”, while other entries in the same table are country-specific); Visa, “Visa Core Rules and Visa Product and Service Rules, §5.8.4.4 Visa Secure Acquirer and Merchant Participation Requirements (edition 18 April 2026)” (Visa rules only; clearing-record requirement, no region limit stated), accessed 2026-09-04.
What to record on an authenticated payment
A 3DS dispute defense depends on the evidence you can produce later, not only on having the feature switched on. Record these fields with the order, not only in the provider dashboard.
What to record | Why it matters | Where to check it |
|---|---|---|
Electronic Commerce Indicator | Visa permits ECI 5 or 6 in the clearing record only when the CAVV was in the authorization request, and for ECI 6 only if the CAVV was provided by the issuer or Visa | Visa rules §5.8.4.4 and your acquirer’s clearing spec |
CAVV presence | The invalid-dispute entries turn on that value being present | Visa rules §11.7.5.3 |
Frictionless or challenge result | Separates issuer friction from a payment problem when you review drop-off | Provider authentication result fields |
Refusal reason on a decline | An authentication failure and a risk decline need different follow-up | Provider refusal-reason reference |
Issuing country and scheme of the card | Rule wording and acquirer obligations differ by both | Scheme rules and acquirer guidance |
Source: Visa, “Visa Core Rules and Visa Product and Service Rules, §5.8.4.4 Visa Secure Acquirer and Merchant Participation Requirements (edition 18 April 2026)” (Visa rules only; clearing-record requirement, no region limit stated); Visa, “Visa Core Rules and Visa Product and Service Rules, §11.7.5.3 Dispute Condition 10.4: Other Fraud – Card-Absent Environment – Invalid Disputes (edition 18 April 2026)” (Visa rules only, other schemes publish their own; the ECI 5 and ECI 6 entries are listed under Country/Region “All”, while other entries in the same table are country-specific); Adyen, “Refusal reasons” (this provider’s refusal-reason names), accessed 2026-09-04.
Where the rules differ
Whether 3DS is required depends on where the card was issued and where the business operates. Visa sets acquirer obligations country by country in a table, with some entries applying only to listed merchant category codes, and a footnote to the same section states that a merchant must adhere to an issuer’s requested authentication method. Visa also requires participants to have their EMV 3DS components pass the EMVCo compliance testing program and Visa’s own test suite. In Europe the requirement is strong customer authentication under PSD2, detailed in the European Banking Authority’s regulatory technical standards, Regulation (EU) 2018/389, which also govern exemptions. Stripe states that card payments require 3D Secure to meet SCA, and that 3DS is optional in other regions.
Source: Visa, “Visa Core Rules and Visa Product and Service Rules, §5.8.4.3 Acquirer Support of Visa Secure (edition 18 April 2026)” (Visa rules only; obligations set country by country in Table 5-17); Visa, “Visa Core Rules and Visa Product and Service Rules, §10.15.1.1 Visa Secure Participation Requirements (edition 18 April 2026)” (Visa rules only; participation and testing requirements, no region limit stated); European Banking Authority, “Regulatory Technical Standards on strong customer authentication and secure communication under PSD2” (EU regulatory basis and exemptions); Stripe, “Strong Customer Authentication readiness” (this provider’s SCA scope guidance); Stripe, “3D Secure authentication” (this provider’s statement that 3DS is optional outside SCA regions), accessed 2026-09-04.
- Check the country rules for every card you accept, not only your home market.
- Ask your acquirer which authentication outcomes qualify under the invalid-dispute entries.
- Store the ECI and CAVV alongside the order record, not only in provider reports.
- Monitor a redirect challenge separately, because abandonment there looks like a decline.
- Re-check exemption handling whenever your provider changes its authentication behavior.
Source: Visa, “Visa Core Rules and Visa Product and Service Rules, §5.8.4.3 Acquirer Support of Visa Secure (edition 18 April 2026)” (Visa rules only; obligations set country by country in Table 5-17); Visa, “Visa Core Rules and Visa Product and Service Rules, §5.8.4.4 Visa Secure Acquirer and Merchant Participation Requirements (edition 18 April 2026)” (Visa rules only; clearing-record requirement, no region limit stated); Adyen, “3D Secure 2 authentication” (this provider’s native, redirect, frictionless and challenge flows), accessed 2026-09-04.
Read Address Verification Service (AVS) and Card Verification Value (CVV) for the other card-absent checks that sit next to authentication.
FAQ
No. EMVCo describes many purchases completing on the data exchanged in the background, with a challenge only where the issuer wants further authentication. Adyen calls those the frictionless flow and the challenge flow in its native implementation, and lists biometrics and two-factor methods alongside codes. A one-time passcode is one challenge option, not the protocol’s only outcome, and the issuer decides which applies to a given payment.
Source: EMVCo, “EMV® 3-D Secure” (protocol scope and authentication outcomes); Adyen, “3D Secure 2 authentication” (this provider’s native, redirect, frictionless and challenge flows), accessed 2026-09-04.
Sources
Related terms
Acquiring and settlement
Payment Authorization
Payment authorization checks whether a card transaction is approved by the cardholder’s issuing institution or a service acting for it before funds can later be captured.
Acquiring and settlement
Issuing Bank
An issuing bank provides payment cards to customers and manages the accounts used for those cards throughout authorization, clearing, and settlement.
Risk and compliance
Chargeback
A chargeback is a forced reversal of a card transaction initiated by the cardholder through their issuer, usually citing fraud, non-delivery, or billing disputes, and debited from the merchant through the acquirer.
Card scheme basics
Card Verification Value (CVV)
Card Verification Value (CVV) is the three- or four-digit security code printed on a payment card, used to verify that the customer likely possesses the physical or virtual card during checkout.
Risk and compliance
Address Verification Service (AVS)
Address Verification Service (AVS) compares the billing address submitted at checkout with the address on file at the card issuer to flag mismatches that may indicate fraud.
Acquiring and settlement
Payment Gateway
A payment gateway is technology that passes payment information from a business's checkout to the systems that process the transaction.
Usage Guide
- Read Guide
Payment Roles
Merchant Acquiring Explained: Acquirer vs Processor vs Acquiring Bank vs PayFac
Need help mapping your payment stack?
Accept major card networks with routing, 3DS, and settlement built for cross-border sales.
Contact Us