Back to the library
Payment Processing
2026-07-29 9 min read

What Is 3D Secure (3DS) and Does Your Business Need It?

3D Secure shifts fraud liability from merchant to issuer when used correctly. Here is how it works, and when the checkout friction is worth it.

GM

By Gray Merchants Team

3D Secure3DS2EMV 3-D Secureliability shiftstrong customer authentication
What Is 3D Secure (3DS) and Does Your Business Need It?
Key takeaways
  • 3D Secure verifies a cardholder's identity with their issuing bank before authorization; used correctly, it shifts fraud liability from the merchant to the issuer, though only for fraud-related disputes.
  • EMV 3DS2 runs a frictionless flow for most transactions and a challenge flow only when the issuer needs direct cardholder confirmation, a major improvement over the all-redirect 3DS1.
  • The EU legally mandates Strong Customer Authentication under PSD2, in force since September 2019. The US has no equivalent regulation, making 3DS a merchant risk decision rather than a legal requirement.
  • The liability shift disappears if a merchant uses an SCA exemption to skip authentication, so skipping the friction also means keeping the fraud risk.
  • 3DS matters most for businesses with elevated dispute exposure or large average ticket sizes, and works best paired with a broader fraud-prevention strategy rather than as a standalone fix.

So what is 3D Secure? It's an authentication step for card-not-present transactions that verifies a cardholder's identity with their bank before a payment goes through. Visa brands its own implementation Visa Secure, built on the current EMV 3-D Secure (3DS2) standard (Visa), and its biggest practical benefit for a merchant is a liability shift: use it correctly, and fraud liability on a disputed transaction generally moves from the merchant to the card-issuing bank instead.

How 3D Secure Actually Works

When a customer checks out, the merchant's system sends transaction data to the card-issuing bank through the 3DS network. EMVCo, the organization that owns the 3-D Secure specification, defines two possible outcomes (EMVCo):

  • Frictionless flow: the issuing bank reviews risk data in real time and approves the transaction silently, with no extra step for the customer.
  • Challenge flow: the issuer decides it needs direct confirmation from the cardholder, a one-time passcode, biometric verification, knowledge-based questions, or another method, before authorizing the sale.

That second flow is the friction merchants worry about. It's also the mechanism that makes the liability shift work: real cardholder confirmation is what gives the issuer confidence to accept fraud risk on that transaction.

Why the Liability Shift Is the Real Reason to Care

Here's the mechanism in plain terms. When a transaction is successfully authenticated through 3DS and the issuer returns a valid authentication result, fraud liability on that specific transaction generally shifts from the merchant to the card-issuing bank. If the cardholder later disputes it as unauthorized, the issuer absorbs that loss instead of the merchant eating a chargeback.

That protection is narrower than it sounds, though, and it's worth being precise about the limits. The liability shift only applies to fraud-related disputes, not to other reasons a customer might file a chargeback, like a product never arriving or not matching its description. It also doesn't apply if the merchant uses an exemption to skip full authentication instead of running it. Skip the authentication step to reduce friction, and the liability stays with the merchant, exactly where it would sit without 3DS at all.

3DS1 vs. 3DS2: Why the Newer Version Matters

The original 3D Secure protocol (3DS1) redirected every customer to a separate verification page, no exceptions, which created real cart abandonment risk on every single transaction. EMV 3-D Secure (3DS2) fixed the core problem by adding the frictionless flow described above, exchanging far more risk data behind the scenes so most legitimate transactions never see a challenge screen at all. The challenge flow still exists for genuinely risky transactions, but it's the exception now, not the default.

Europe Mandates This. The US Doesn't.

This is the single biggest difference in how 3DS gets used depending on where a business operates. In the European Union, PSD2's Strong Customer Authentication requirement came into force on September 14, 2019, requiring two-factor verification (from something the customer knows, has, or is) on most electronic payments, including e-commerce card transactions (European Commission, 2019). That's a legal requirement enforced by national regulators, not a merchant's choice.

The US has no equivalent regulation. Whether a US merchant uses 3DS at all, and on which transactions, comes down entirely to card network program rules and the merchant's own risk tradeoff, not a legal mandate. That's exactly why the decision deserves real thought instead of a default answer.

The Honest Tradeoff: Fraud Protection vs. Checkout Friction

A challenge flow adds a real step to checkout, and that step can cost a business a sale if a legitimate customer abandons rather than completes it. Vendor claims about exactly how much conversion this costs vary wildly and rarely cite real methodology, so treat any specific percentage you see quoted with real skepticism. What's true directionally, without needing an invented number to prove it: more challenge flows generally means more friction, and frictionless-flow-eligible transactions get the liability-shift benefit with essentially none of the downside.

On the fraud-reduction side, the most concrete figure available comes from Visa itself, though it's dated: in 2021, Visa reported EMV 3DS transactions in the US carried 35% lower fraud rates than non-3DS transactions (PYMNTS, 2021, reporting Visa data). That's a real, network-sourced number, even if it's a few years old now, and it's consistent with the underlying logic: authenticated transactions carry less fraud risk than unauthenticated ones by design.

When 3DS Genuinely Makes Sense for a High-Risk Merchant

A business with elevated dispute exposure, large average ticket sizes, or a history of friendly fraud is exactly the profile where the liability shift matters most, since those are the businesses losing the most to chargebacks in the first place. Pairing 3DS with a broader fraud prevention strategy rather than treating it as a standalone fix gets the most value out of it: 3DS handles authentication-eligible fraud risk, while other tools cover what 3DS structurally can't touch, like non-fraud disputes and delivery issues.

A business running mostly low-risk, low-ticket transactions with a clean dispute history may reasonably decide the friction isn't worth it for every sale. This isn't an all-or-nothing decision either. Many merchants apply 3DS selectively, on higher-risk transactions specifically, rather than across the board.

Frequently Asked Questions

Does 3D Secure guarantee I'll never face a fraud chargeback?

No. It shifts liability for successfully authenticated fraud disputes to the issuer, but it doesn't prevent every dispute, and it doesn't cover non-fraud reason codes at all.

Will 3D Secure slow down my checkout for every customer?

Not necessarily. Most transactions under EMV 3DS2 go through the frictionless flow with no visible step for the customer. The challenge flow only triggers when the issuer flags a transaction as needing direct confirmation.

Is 3D Secure required in the US?

No. Unlike the EU's PSD2 mandate, the US has no regulatory requirement for 3DS. It's driven by card network program rules and each merchant's own risk decision.

Can I apply 3D Secure only to some transactions?

Yes. Many merchants use it selectively on higher-risk transactions, like unusually large orders or first-time customers, rather than applying it to every single sale.

Does using a 3DS exemption still protect me from fraud liability?

No. If a merchant or payment provider uses an exemption to skip full authentication, the liability shift doesn't apply, and fraud risk on that transaction stays with the merchant.

What's the difference between 3DS1 and 3DS2?

3DS1 redirected every customer to a verification page with no frictionless option. 3DS2 added a frictionless flow that approves most legitimate transactions silently using richer risk data, reserving the challenge step for genuinely higher-risk transactions.

Weighing whether 3DS fits your specific risk profile? Apply free for a 24 to 48 hour decision, or talk to a specialist about fraud tools that actually fit your dispute history.

GM

Gray Merchants Team

Gray Merchants is a payment ISO that places merchant accounts across every risk level, from low-risk retail and e-commerce to 67+ high-risk verticals. The editorial team writes on high-risk merchant accounts, chargeback defense, MATCH/TMF remediation, and ACH processing, whether you are new, scaling, switching processors, or rebuilding after a decline.

Talk to a specialist

Tell us about your business

Share a few details and a specialist reviews your industry, volume, and processing history, then comes back with the right path. No obligation.

  • Underwriting decision in 24 to 48 hours
  • $0 setup fee, dedicated MID
  • Specialist replies within 4 business hours
  • Every term disclosed in writing before you sign

Request a call from a specialist

Are you currently processing?

No obligation. A specialist replies within 4 business hours, Mon to Fri, 9:00 to 18:00 EST.

What Is 3D Secure (3DS) and Does Your Business Need It? | Gray Merchants