Introduction

3-D Secure has changed dramatically since the first generation of the protocol appeared in online checkout. What many shoppers remember as a separate bank page, static password, or repeated one-time-code prompt is associated with the older 3-D Secure 1.x experience. Modern EMV 3-D Secure, often informally called 3DS2, was redesigned for mobile commerce, richer risk information, app-based payments, frictionless authentication, and more flexible challenge methods.

EMVCo published the next generation EMV 3-D Secure specification in 2016 to support consumer authentication for e-commerce and remote purchases without adding unnecessary checkout friction. Visa later discontinued support for its legacy 3-D Secure 1.0.2 program on October 15, 2022.

The biggest difference is not simply a new version number. 3DS2 changed how merchants and issuers exchange authentication data, how issuers assess transaction risk, how mobile and in-app payments are supported, and how frequently legitimate customers need to complete a visible challenge.

This article compares 3DS1 and modern EMV 3DS from a defensive payment-security perspective. It does not provide instructions for bypassing authentication or defeating issuer controls.

Quick Answer: 3DS1 vs 3DS2

3DS1 was the original browser-focused authentication model. It often relied on redirects and a visible customer challenge, which created checkout friction and was poorly suited to modern mobile and app experiences.

3DS2, more accurately called EMV 3-D Secure, introduced richer transaction and device data, browser and app support, frictionless authentication, risk-based challenges, better user-interface options, and more flexible authentication methods.

In simple terms: 3DS1 emphasized an extra authentication step; modern EMV 3DS emphasizes intelligent authentication, where low-risk customers can often be authenticated silently and higher-risk transactions receive additional verification.

What Was 3-D Secure 1?

3-D Secure 1.x was the first generation of the online cardholder-authentication protocol.

It was designed during an era when e-commerce was heavily browser-based and smartphones had not yet become the dominant shopping device.

Legacy implementations often redirected customers away from the merchant checkout to an issuer-controlled authentication page. Depending on the issuer, customers could be asked for a static password, one-time code, or another credential.

The protocol added useful authentication to online card payments, but its user experience became a major weakness as digital commerce evolved.

Why 3DS1 Became Frustrating for Shoppers

Older 3DS experiences often interrupted checkout with a separate authentication page.

This could create problems such as extra redirects, unfamiliar bank screens, forgotten passwords, poor mobile formatting, interrupted sessions, and customer abandonment.

The problem was not that authentication itself was unnecessary. The problem was that almost every transaction could feel like it required the same disruptive process, regardless of actual risk.

Modern 3DS was designed specifically to reduce that unnecessary friction.

What Is 3-D Secure 2?

3-D Secure 2 is the common industry shorthand for the modern EMV 3-D Secure generation maintained by EMVCo.

It is not one permanently fixed protocol version. EMVCo has released multiple 2.x specifications, including 2.1, 2.2, 2.3, and the 2.3.1 specification family.

Modern EMV 3DS supports browser and app-based commerce, richer data exchange, frictionless authentication, challenge flows, out-of-band authentication, and additional modern payment use cases.

As a result, '3DS2' is best understood as the modern generation rather than one single version number.

The Biggest Change: From Challenge-First to Risk-Based Authentication

One of the most important changes was the move toward risk-based authentication.

Under modern EMV 3DS, the merchant can send significantly richer transaction context to the issuer. The issuer can use that information alongside its own fraud intelligence to decide whether an additional customer challenge is needed.

A normal, low-risk purchase may therefore be authenticated through a frictionless flow with no visible interruption.

A higher-risk transaction can trigger a challenge for stronger verification.

This is fundamentally different from treating every customer as though the same additional authentication step is always necessary.

What Is a Frictionless Flow?

A frictionless flow is an EMV 3DS authentication in which the issuer can authenticate the transaction without requesting additional visible interaction from the customer.

The customer may click the payment button and continue directly to the normal transaction outcome without seeing an OTP page or bank challenge.

EMVCo says the purpose is to help issuers identify and prevent fraudulent transactions without unnecessary payment friction that can lead to abandoned purchases.

Frictionless does not mean unauthenticated. It means the issuer had enough risk information to make the authentication decision without step-up verification.

What Is a Challenge Flow?

A challenge flow occurs when the issuer wants additional proof that the person making the purchase is the legitimate cardholder.

Modern EMV 3DS supports several challenge methods depending on the issuer and market. These can include one-time codes, banking-app confirmation, biometrics, out-of-band authentication, or other approved methods.

The challenge is therefore no longer tied to one universal password or OTP experience.

Promotional banner

The issuer can choose an authentication method appropriate to its technology, customer, regulation, and assessed transaction risk.

3DS1 vs 3DS2: User Experience

The user-experience difference is one of the most visible changes.

3DS1 commonly involved redirecting the customer to a separate issuer page. Modern EMV 3DS supports authentication that can be embedded more naturally into browser and mobile experiences.

EMVCo has also published user-interface and user-experience guidance specifically aimed at improving challenge flows across devices.

The objective is to maintain strong security while making authentication feel like part of checkout instead of a completely separate website.

3DS1 vs 3DS2: Mobile Support

3DS1 was created before mobile commerce became central to online shopping.

As a result, legacy authentication pages could be difficult to use on small screens and were not designed around native mobile apps.

Modern EMV 3DS includes an SDK architecture for app-based authentication and supports device information useful for issuer risk assessment.

This makes it much better suited to smartphones, tablets, banking apps, and in-app purchases.

3DS1 vs 3DS2: Amount of Risk Data

Modern EMV 3DS supports much richer information exchange between the merchant side and issuer than legacy 3DS.

EMVCo explains that EMV 3DS messages can include information about the transaction, payment method, and device.

Additional contextual information can help the issuer distinguish a normal customer purchase from unusual or suspicious activity.

The goal is not simply to collect more data. It is to make authentication decisions more accurate so legitimate shoppers face fewer unnecessary challenges.

3DS1 vs 3DS2: Static Passwords

Some early 3DS1 programs relied on cardholders registering a reusable password.

Reusable authentication secrets create usability problems because customers forget them and security problems because static secrets can be phished or reused.

Modern EMV 3DS does not depend on one fixed password model. Issuers can use risk-based authentication, OTPs, banking apps, biometrics, passkey-related approaches, or other approved methods.

This gives issuers more flexibility to move toward stronger and more convenient authentication.

3DS1 vs 3DS2: Browser Redirects

Legacy 3DS commonly moved customers to a separate issuer-controlled browser page.

Modern 3DS provides more flexible browser authentication and can integrate the challenge experience more naturally into merchant checkout.

This helps reduce the sense that the shopper has unexpectedly left the merchant's website.

Promotional banner

It can also improve compatibility with modern responsive checkout designs.

3DS1 vs 3DS2: App-Based Commerce

Native mobile apps were not a core design assumption of early 3DS1.

Modern EMV 3DS specifically includes support for app-based authentication through a 3DS SDK.

This allows authentication to work within a merchant application while giving the issuer device and transaction context needed for risk decisions.

Supporting apps natively is one of the clearest examples of why the protocol had to be redesigned rather than simply adding cosmetic changes to 3DS1.

3DS1 vs 3DS2: Authentication Methods

3DS1 experiences were often associated with passwords and SMS codes.

Modern EMV 3DS supports a broader range of authentication options.

Newer specification versions have improved support for out-of-band authentication, Secure Payment Confirmation, richer challenge flows, and modern authentication technologies.

This means the protocol can evolve as issuers adopt stronger technologies rather than being permanently tied to SMS or static passwords.

What Is Out-of-Band Authentication?

Out-of-band authentication allows customers to verify themselves through another trusted channel, such as their banking application.

For example, the issuer may ask the customer to approve the transaction inside its official app instead of typing a code into the merchant checkout.

EMV 3DS 2.3.1 added data and enhancements intended to improve out-of-band authentication and user experience.

This provides issuers with another way to deliver secure step-up authentication without relying exclusively on SMS.

What Is Secure Payment Confirmation?

Secure Payment Confirmation, or SPC, is a web authentication capability designed to support strong and user-friendly payment authentication.

EMVCo added data elements supporting SPC in EMV 3DS 2.3.1.

This reflects the continuing evolution of 3DS toward stronger cryptographic and device-based authentication rather than dependence on reusable secrets.

The exact availability of SPC depends on ecosystem and browser support, issuer implementation, and payment-provider capabilities.

3DS1 vs 3DS2: Authentication and Authorization

Neither 3DS1 nor 3DS2 is the actual payment authorization system.

3DS authenticates the customer or account relationship. The issuer then separately evaluates the payment authorization.

A transaction can therefore pass 3DS authentication and still be declined because of account status, available funds or credit, fraud controls, merchant restrictions, or other issuer rules.

This distinction did not disappear with 3DS2, but modern authentication provides richer information that can also support better downstream risk decisions.

3DS1 vs 3DS2: Fraud Prevention

Both generations were intended to reduce card-not-present fraud.

The difference is that modern EMV 3DS gives issuers more context and flexibility.

Instead of relying heavily on one visible challenge, 3DS2 allows authentication decisions to use transaction and device information, issuer fraud models, merchant data, and step-up authentication when needed.

That can improve fraud detection while reducing unnecessary authentication friction for legitimate customers.

3DS1 vs 3DS2: False Declines

A false decline occurs when a legitimate transaction is rejected because it appears suspicious.

Richer EMV 3DS data can help issuers recognize legitimate unusual activity instead of simply declining it.

Promotional banner

If additional assurance is required, the issuer can challenge the customer rather than immediately rejecting the transaction.

This means modern 3DS can support both fraud reduction and higher legitimate approval rates when implemented effectively.

3DS1 vs 3DS2: Liability Shift

Both generations of 3DS have been associated with payment-network liability-shift rules for qualifying fraud transactions.

Modern programs such as Visa Secure and Mastercard Identity Check continue to provide potential liability benefits when network conditions are met.

However, liability shift is governed by payment-network rules, region, authentication outcome, transaction type, and other conditions.

3DS2 does not mean every chargeback becomes the issuer's responsibility, and merchants should rely on current processor and network guidance.

Why Visa Ended Support for 3DS1

Visa announced that support for 3-D Secure 1.0.2 would end on October 15, 2022.

The sunset reflected the industry's transition to the newer EMV 3DS generation, which was built to support current e-commerce security and user-experience requirements.

Merchants still relying on legacy 3DS infrastructure therefore needed to migrate to modern authentication platforms.

The date is also useful historically because it marks the point by which one of the world's largest card networks had formally moved away from the original protocol generation.

Is 3DS1 Still Relevant Today?

Primarily as historical context.

Major payment ecosystems have migrated toward EMV 3DS, and legacy 3DS1 support has been sunset by major networks.

Merchants evaluating modern payment integrations should focus on current EMV 3DS capabilities rather than designing around the old 1.x user experience.

Understanding 3DS1 is still useful because many misconceptions about '3D Secure' come from customers remembering the friction of those older authentication pages.

Is 3DS2 Still Being Updated?

Yes.

EMVCo continues to evolve the EMV 3DS specifications.

Version 2.3.1 was released in 2022 with enhancements for Secure Payment Confirmation, out-of-band authentication, challenge flows, and user-interface improvements. EMVCo followed with 2.3.1.1 updates in 2023.

EMVCo's Q1 2026 update also states that work continues to enhance the EMV 3DS specifications and simplify solution development, deployment, and testing.

Therefore, 3DS2 should be seen as an evolving family of modern specifications rather than a completed one-time upgrade.

3DS2 and Strong Customer Authentication

Modern EMV 3DS was designed in part to support stronger authentication requirements in regulated markets.

Version 2.2 added capabilities that helped the ecosystem support European PSD2 and Strong Customer Authentication requirements.

3DS can support risk analysis, two-factor authentication, exemptions, and issuer challenge decisions depending on the regulatory and transaction context.

Regulatory requirements vary by region, so merchants should use their processor's current compliance guidance.

3DS2 and Passkeys

Payment authentication is increasingly moving toward phishing-resistant technologies such as passkeys and FIDO authentication.

EMVCo introduced the ability to use FIDO authentication data in EMV 3DS messages beginning with version 2.1.0 and has continued collaborating with the wider authentication ecosystem.

This demonstrates another important advantage of the modern architecture: it can evolve to incorporate new authentication technologies rather than remaining tied to static passwords.

3DS1 vs 3DS2 Comparison Table

Protocol generation: 3DS1 was the original generation; 3DS2 is the modern EMV 3DS generation.

Primary design era: 3DS1 was browser-centric; 3DS2 is designed for modern browser, mobile, and app commerce.

Customer experience: 3DS1 frequently used visible redirects and challenges; 3DS2 supports frictionless authentication and improved embedded challenges.

Risk data: 3DS1 exchanged relatively limited context; 3DS2 supports richer transaction, payment, and device information.

Authentication methods: 3DS1 commonly relied on passwords or OTPs; 3DS2 supports a broader range of step-up methods, including app and out-of-band authentication.

Mobile support: 3DS1 was limited; 3DS2 includes dedicated SDK support.

Fraud strategy: 3DS1 was more challenge-centric; 3DS2 is risk-based and data-driven.

Protocol status: 3DS1 is legacy and has been sunset by major networks; EMV 3DS continues to evolve.

Does 3DS2 Always Mean a Better Customer Experience?

Usually it provides the tools for a better experience, but implementation still matters.

A merchant or issuer can configure authentication poorly and challenge too many legitimate transactions.

Promotional banner

Network rules, regulatory requirements, issuer risk models, and payment-provider configuration all affect the final user experience.

The technology makes frictionless and intelligent authentication possible; it does not automatically guarantee perfect checkout design.

Can Merchants Force Every Transaction to Be Frictionless?

No.

The issuer ultimately determines whether additional authentication is required under the relevant 3DS flow and payment-network rules.

Merchants can provide accurate information and request certain preferences where supported, but they should not attempt to weaken authentication simply to avoid customer challenges.

The security value of modern 3DS depends on allowing riskier transactions to receive stronger verification when appropriate.

Does 3DS2 Replace CVV and AVS?

No.

CVV validation, AVS, 3DS, tokenization, and fraud analytics provide different types of information.

CVV checks a card-verification value. AVS checks billing-address consistency. 3DS authenticates the remote customer. Tokenization reduces exposure of the underlying payment credential.

A merchant can combine these controls as part of layered fraud prevention rather than treating them as interchangeable.

Does 3DS2 Replace PCI DSS?

No.

PCI DSS protects the environment in which payment-account data is stored, processed, or transmitted.

3DS authenticates online card transactions.

A merchant can use modern 3DS and still have obligations to protect payment data and maintain secure checkout infrastructure.

Strong payment security requires both secure data handling and secure customer authentication.

What Consumers Should Know

If an online purchase does not show an OTP, that does not mean 3DS was absent.

The transaction may have been authenticated through a frictionless EMV 3DS flow.

If a challenge appears, read it carefully and verify that the merchant and transaction amount correspond with the purchase you are making.

Never share authentication codes, banking passwords, or app approvals with someone who contacts you unexpectedly.

If you receive an authentication request for a purchase you did not initiate, reject it and contact your card issuer through an official channel.

What Merchants Should Know

Use a reputable payment provider that supports current EMV 3DS versions and payment-network programs.

Send accurate transaction information so issuers can make higher-quality authentication decisions.

Monitor frictionless rates, challenge rates, authentication success, authorization outcomes, false declines, fraud, and checkout conversion.

Avoid treating every transaction as high risk and forcing unnecessary challenges.

At the same time, do not try to suppress legitimate issuer challenges simply to improve conversion.

Follow current Visa, Mastercard, regional, and processor rules rather than relying on assumptions developed during the 3DS1 era.

Common Myths

Myth: 3DS2 is simply 3DS1 with a new visual design. Reality: the protocol architecture, data exchange, mobile support, authentication flows, and risk decisioning changed substantially.

Myth: 3DS2 always sends an OTP. Reality: many transactions use frictionless authentication, and challenge methods vary.

Myth: Frictionless means the transaction was not authenticated. Reality: it means the issuer authenticated without requiring additional customer interaction.

Myth: Passing 3DS2 guarantees payment approval. Reality: authentication and authorization are separate.

Myth: 3DS2 removes all chargebacks. Reality: liability benefits apply only under qualifying payment-network rules and do not cover every dispute.

Myth: 3DS1 and 3DS2 are both equally current. Reality: major networks sunset legacy 3DS1 while modern EMV 3DS continues evolving.

Myth: 3DS2 replaces all other payment-security tools. Reality: it should be combined with PCI DSS, tokenization, secure accounts, fraud analytics, and other appropriate controls.

Conclusion

The move from 3-D Secure 1 to modern EMV 3-D Secure was much more than a version upgrade.

3DS1 proved the value of adding issuer-controlled authentication to e-commerce, but its browser redirects and frequently disruptive challenges became poorly suited to mobile-first digital commerce.

3DS2 changed that model by introducing richer transaction information, mobile and app support, frictionless authentication, risk-based challenges, stronger authentication options, and a protocol architecture that can continue evolving alongside the payment ecosystem.

For consumers, that means secure authentication may happen without an obvious extra step. For merchants, it means stronger fraud prevention does not have to require challenging every legitimate customer.

The central lesson is simple: 3DS1 added authentication to online payments; modern EMV 3DS made that authentication smarter, more contextual, more mobile-friendly, and less disruptive.