Introduction

VBV stands for Verified by Visa, the former name of Visa's online cardholder-authentication program based on the 3-D Secure standard. Visa later renamed the program Visa Secure, and modern Visa Secure uses EMV 3-D Secure technology.

Visa's own developer documentation describes Visa Secure as previously known as Verified by Visa, while current Visa materials describe Visa Secure as its EMV 3-D Secure program for making online authentication simpler, reducing customer friction, and helping prevent card-not-present fraud.

The name changed, but the basic security goal remained: help the card issuer determine whether an online buyer is genuinely authorized to use the Visa card being presented.

Modern Visa Secure is significantly different from the old Verified by Visa experience many customers remember. Legacy implementations were often associated with password pages and browser redirects, while current EMV 3DS supports risk-based authentication, frictionless transactions, mobile apps, and stronger challenge methods.

This guide explains VBV, Visa Secure, and 3-D Secure from a defensive payment-security perspective. It does not provide instructions for bypassing authentication or identifying merchants with weaker controls.

Quick Answer: What Does VBV Mean?

VBV means Verified by Visa.

Verified by Visa was Visa's older brand name for its 3-D Secure online-authentication program.

Visa later renamed the program Visa Secure. Visa's 2019 developer release notes explicitly state that Visa Secure was previously known as Verified by Visa.

Today, Visa Secure is based on EMV 3-D Secure and is designed to help issuers authenticate customers during online card payments while reducing card-not-present fraud.

So the simplest relationship is: VBV = old name; Visa Secure = current Visa program; EMV 3DS = the modern authentication technology underneath the program.

VBV, Visa Secure and 3D Secure: The Relationship

The three terms are connected but do not mean exactly the same thing.

Verified by Visa was Visa's branded authentication program.

Visa Secure is the current name of that Visa program.

3-D Secure is the authentication protocol family used to support online cardholder authentication.

EMV 3-D Secure is the modern specification maintained by EMVCo and used by payment networks around the world.

A useful way to think about the relationship is: EMV 3DS is the technology framework, while Visa Secure is Visa's branded program built on that framework.

Why Was It Called Verified by Visa?

The name reflected the program's original objective: provide an additional issuer-controlled verification step during an online Visa card transaction.

When the system determined that more authentication was required, the cardholder could be asked to verify themselves through an issuer-controlled process.

Older versions became strongly associated with passwords, security questions, or one-time codes displayed through a separate bank authentication page.

That experience helped establish online authentication but also contributed to the perception that 3-D Secure always means a visible password or OTP screen.

Why Did Verified by Visa Become Visa Secure?

Visa modernized both the technology and branding surrounding its online authentication program.

Visa's developer release notes state that Visa Secure was previously known as Verified by Visa. Current Visa materials describe Visa Secure as its global EMV 3-D Secure program.

The newer name also better reflects how modern authentication works. EMV 3DS is no longer simply about presenting a visible 'verification' page to every shopper. Many transactions can now be authenticated through a frictionless, data-driven process without requiring additional customer interaction.

The transition therefore reflects both a branding update and a major technological evolution in 3-D Secure.

Is Verified by Visa Still Used?

The Verified by Visa name is now primarily legacy terminology.

Consumers may still encounter the abbreviation VBV in older articles, merchant discussions, payment-system documentation, forums, or historical descriptions of 3-D Secure.

Visa's current consumer and merchant materials use Visa Secure and EMV 3-D Secure terminology.

If someone refers to a 'VBV transaction' today, they are usually talking about Visa's 3-D Secure authentication concept rather than a separate modern payment technology called VBV.

What Is Visa Secure?

Visa Secure is Visa's current EMV 3-D Secure authentication program.

Visa says Visa Secure helps make authentication simple, reduce customer friction, and prevent card-not-present fraud.

It allows Visa issuers and participating merchants to exchange authentication information during e-commerce transactions so the issuer can assess whether additional customer verification is necessary.

Promotional banner

Visa Secure does not replace the normal payment authorization process. Authentication happens as one part of the broader payment journey.

What Is 3-D Secure?

3-D Secure, or 3DS, is an authentication protocol designed to strengthen online card payments.

EMVCo maintains the modern EMV 3-D Secure specifications. EMVCo says EMV 3DS helps issuers and merchants prevent card-not-present fraud and increase the security of e-commerce payments.

Visa Secure is one payment-network implementation of EMV 3DS. Mastercard uses its own branded EMV 3DS program, Mastercard Identity Check.

The existence of multiple network brands is one reason it is useful to distinguish the underlying EMV 3DS technology from individual network program names.

What Does EMV 3DS Do?

EMV 3DS allows transaction and authentication information to move between the merchant side of the payment ecosystem and the issuer.

The issuer can evaluate the transaction and decide whether the customer can be authenticated without additional interaction or whether stronger verification is needed.

Modern EMV 3DS supports both browser and application-based authentication and is designed to improve fraud prevention without unnecessarily disrupting legitimate shoppers.

This is the technology behind the modern Visa Secure experience.

How Did Old VBV Usually Work?

Older Verified by Visa experiences were commonly associated with legacy 3-D Secure implementations.

A shopper might enter card information at checkout and then be redirected to an issuer authentication page.

Depending on the bank, the customer might have been asked for a registered password, one-time code, or another verification credential.

The authentication result would then be returned so the payment process could continue.

This provided additional online security but could also introduce friction, particularly on mobile devices or when customers forgot credentials.

How Does Modern Visa Secure Work?

Modern Visa Secure uses EMV 3DS to support risk-based authentication.

The merchant and payment provider can send relevant transaction context through the 3DS authentication flow. The issuer evaluates that information along with its own risk intelligence.

A lower-risk transaction may be authenticated through a frictionless flow.

A transaction that requires more confidence can trigger a customer challenge.

This means the authentication experience can adapt to risk instead of forcing every customer through the same visible verification step.

What Is a Frictionless Visa Secure Transaction?

A frictionless transaction is one in which the issuer can authenticate the customer without asking for an additional visible action.

The customer may complete checkout without seeing a Visa Secure screen, OTP prompt, or banking-app approval request.

EMVCo explains that modern EMV 3DS is designed to support frictionless authentication so issuers can prevent fraud without unnecessarily interrupting the purchase process.

A transaction can therefore be protected by Visa Secure even when the shopper sees no obvious authentication page.

What Is a Visa Secure Challenge?

A challenge occurs when the issuer requires additional evidence that the customer is authorized to use the card.

The precise challenge method is determined by the issuer and supported technology.

It may involve a banking application, biometric verification, one-time code, out-of-band authentication, or another issuer-approved method.

Visa publishes specific user-experience guidance for EMV 3DS challenge experiences across desktop and mobile devices.

Promotional banner

The challenge is therefore part of the issuer authentication process rather than a universal fixed Visa password screen.

Does Visa Secure Always Require an OTP?

No.

Modern Visa Secure can authenticate transactions frictionlessly when the issuer has sufficient confidence.

When additional verification is necessary, an OTP is only one possible challenge method.

Visa's current EMV 3DS guidance includes both OTP and out-of-band authentication experiences, showing that modern Visa Secure is broader than the old 'enter the code' model.

Therefore, describing Visa Secure as simply an OTP system is inaccurate.

Does Visa Secure Require Registration?

For modern Visa Secure, consumers generally do not need to separately register for a special 3DS service.

Visa's current consumer support guidance states that issuers handle the authentication provided by 3-D Secure and that consumers do not need to register for it themselves.

The exact experience depends on the card issuer. Customers should keep their bank's contact information and authentication methods current so they can complete legitimate challenges when required.

This is another difference from some older Verified by Visa implementations that involved explicit cardholder enrollment or registered passwords.

VBV vs Visa Secure

VBV and Visa Secure describe different eras of Visa's online authentication program.

VBV is the abbreviation for Verified by Visa, the legacy program name.

Visa Secure is the current program name.

Modern Visa Secure is based on EMV 3-D Secure and supports features that did not define the early Verified by Visa experience, including richer risk data, frictionless authentication, mobile integration, and newer challenge methods.

In everyday conversation, people sometimes use VBV as a generic label for Visa 3DS, but technically Visa Secure is the current terminology.

VBV vs 3-D Secure

VBV was a Visa brand. 3-D Secure is the underlying authentication protocol family.

This distinction is similar to the difference between a technology standard and a network-branded implementation of that standard.

Verified by Visa used 3-D Secure. Visa Secure now uses modern EMV 3-D Secure.

Therefore, not every 3DS transaction is a Visa transaction. Mastercard and other payment networks can use EMV 3DS through their own programs.

Visa Secure vs Mastercard Identity Check

Visa Secure and Mastercard Identity Check are different payment-network programs built around the same broad EMV 3-D Secure framework.

Visa Secure applies to participating Visa card transactions.

Mastercard Identity Check applies within Mastercard's authentication ecosystem.

Mastercard describes Identity Check as its EMV 3-D Secure solution.

The branding differs, but both programs aim to strengthen authentication for remote card payments.

What Happened to Verified by Visa Passwords?

Legacy Verified by Visa experiences sometimes involved reusable passwords registered by cardholders.

Modern payment authentication has moved away from relying on one reusable password model.

EMV 3DS allows issuers to use richer risk assessment and multiple authentication methods, including app confirmation, biometrics, out-of-band flows, and other modern approaches.

This shift improves both security and usability because reusable secrets can be forgotten, phished, or reused across services.

Why Modern 3DS Is Better for Mobile Shopping

Older 3DS experiences were created in a browser-first era.

Modern EMV 3DS was designed to support smartphones, tablets, browsers, and native applications.

Promotional banner

Visa provides EMV 3DS user-experience guidance covering both desktop and mobile challenge flows.

This allows authentication to be integrated more naturally into the devices people actually use for online shopping today.

Visa Secure Authentication vs Payment Authorization

Authentication and authorization are separate.

Visa Secure helps authenticate the cardholder or account relationship.

After authentication, the issuer still makes a separate authorization decision about whether the payment should be approved.

Authorization may depend on account status, available funds or credit, transaction risk, merchant information, and other issuer rules.

A transaction can therefore authenticate successfully through Visa Secure and still be declined afterward.

Does Visa Secure Guarantee Payment Approval?

No.

A successful authentication result is an important security signal, but it is not a promise that the payment will be authorized.

The issuer retains the ability to decline the transaction for legitimate account, credit, fraud, regulatory, or processing reasons.

The reverse misconception is also important: not seeing a Visa Secure challenge does not mean the payment skipped authentication, because frictionless authentication may have occurred.

Visa Secure vs CVV

CVV and Visa Secure address different parts of online payment security.

CVV validates a card-verification value associated with the payment card.

Visa Secure uses EMV 3DS to authenticate the remote customer or account.

A merchant can use CVV validation together with Visa Secure authentication and other fraud controls.

A correct CVV alone does not establish cardholder identity.

Visa Secure vs AVS

AVS compares billing-address information with issuer records.

Visa Secure focuses on authentication.

These controls are complementary.

A merchant might consider address verification and card-verification results as transaction-risk signals while using 3DS to obtain stronger issuer-controlled customer authentication.

No single one of these controls should be treated as complete fraud prevention.

Visa Secure vs PCI DSS

Visa Secure and PCI DSS solve different security problems.

Visa Secure helps authenticate online customers.

PCI DSS establishes technical and operational requirements for protecting payment-account data where it is stored, processed, or transmitted.

A merchant using Visa Secure still needs secure payment infrastructure and appropriate PCI DSS controls.

Authentication cannot compensate for poor protection of cardholder data.

Does Visa Secure Stop All Card-Not-Present Fraud?

No.

EMV 3DS is designed to reduce card-not-present fraud, but online fraud can also involve phishing, account takeover, malware, social engineering, merchant compromise, and first-party misuse.

Visa Secure should therefore be combined with tokenization, fraud analytics, secure checkout infrastructure, account protection, PCI DSS, and transaction monitoring.

No legitimate payment-security program should promise that one authentication technology eliminates every possible fraud scenario.

Can an Authenticated Visa Secure Transaction Still Be Disputed?

Yes.

Authentication can reduce certain forms of third-party stolen-card fraud, but transactions can still be disputed for other reasons.

Examples can include merchandise disputes, refunds, duplicate processing, service complaints, first-party misuse, or transactions that do not meet applicable network conditions.

Visa Secure may provide liability-shift benefits for qualifying authenticated or attempted transactions, but those rules do not make merchants immune from every chargeback category.

Merchants should follow current Visa and processor dispute guidance.

What Is Liability Shift in Visa Secure?

Liability shift is a payment-network rule under which responsibility for certain fraud-related disputes can shift away from the merchant when applicable authentication conditions are satisfied.

Visa's current 3-D Secure guidance states that Visa Secure can provide liability shift for authenticated or attempted transactions, subject to program and regional rules.

This can be an important benefit for merchants, but it is not universal.

Promotional banner

Eligibility depends on factors such as transaction type, market, authentication result, Visa rules, and processor implementation.

Merchants should not assume that displaying a Visa Secure badge or initiating 3DS automatically protects every transaction from every dispute.

What Does 'Non-VBV' Mean?

The phrase 'non-VBV' is informal legacy terminology sometimes used online to describe a transaction or merchant that does not appear to present the old Verified by Visa authentication experience.

That label is unreliable in modern payments.

A transaction can use Visa Secure through a frictionless EMV 3DS flow without showing the customer an authentication screen.

A merchant may also use different authentication, exemption, routing, or risk rules depending on issuer, country, transaction, and regulatory context.

Therefore, visible absence of an OTP or Verified by Visa screen does not establish that a payment lacks 3DS protection.

For security analysis, merchants should use actual processor authentication results rather than informal labels such as 'VBV' and 'non-VBV.'

Why 'VBV Site' Is an Outdated Concept

Older online discussions sometimes divided merchants into 'VBV' and 'non-VBV' sites.

Modern EMV 3DS makes that classification misleading.

Authentication decisions can be transaction-specific. The same merchant may have one transaction authenticated frictionlessly and another challenged depending on issuer risk assessment, market requirements, payment method, and transaction context.

The correct modern question is not 'Is this website VBV?' but 'What authentication result and payment-security controls applied to this particular transaction?'

This transaction-specific approach is both more technically accurate and more useful for fraud prevention.

How Consumers Can Recognize Legitimate Visa Secure Authentication

A legitimate Visa Secure challenge is delivered through the card issuer and payment authentication flow.

The customer may be asked to verify through an issuer page, banking app, biometric method, or another supported mechanism.

Consumers should carefully read the merchant name, amount, and authentication prompt before approving.

A bank or merchant should not ask a customer to send a one-time code or banking password through email, social media, or ordinary chat.

If a Visa Secure request appears for a purchase the customer did not initiate, it should be rejected and reported to the issuer through an official channel.

What Consumers Should Do If Visa Secure Is Not Working

Customers should first confirm that their contact information and banking-app access with the card issuer are current.

They should avoid repeatedly sharing or entering authentication credentials into unfamiliar pages.

Visa's consumer support guidance notes that issuers manage 3-D Secure authentication, so persistent authentication issues generally need to be addressed with the card-issuing financial institution.

Customers should contact the issuer using the official app, the number printed on the card, or another trusted issuer channel.

How Merchants Should Use Visa Secure

Merchants should integrate Visa Secure through a reputable payment gateway, acquirer, processor, or 3DS provider that supports current EMV 3DS requirements.

They should provide accurate transaction information so issuers can make better authentication decisions.

Merchants should monitor frictionless rates, challenge rates, authentication success, authorization rates, fraud, false declines, and checkout conversion.

Visa Secure should be one part of a wider fraud strategy that includes tokenization, secure payment pages, account security, transaction monitoring, and appropriate CVV or AVS use.

Merchants should also follow current Visa rules regarding authentication, liability shift, regional requirements, recurring payments, and stored credentials.

Common Myths About VBV and Visa Secure

Myth: VBV and Visa Secure are completely different security technologies. Reality: VBV was the old name for Visa's 3-D Secure program; Visa Secure is the current program built on modern EMV 3DS.

Myth: Visa Secure always means an OTP screen. Reality: many transactions can authenticate frictionlessly, and challenge methods vary.

Myth: If no Visa Secure page appears, the transaction is 'non-VBV.' Reality: modern 3DS can authenticate without visible customer interaction.

Myth: Passing Visa Secure guarantees payment approval. Reality: authentication and authorization are separate.

Myth: Visa Secure stops every form of online fraud. Reality: it reduces authentication risk but should be combined with broader payment-security controls.

Myth: A merchant using Visa Secure no longer needs PCI DSS. Reality: Visa Secure authenticates customers; PCI DSS protects payment-account data.

Myth: Verified by Visa still requires consumers to register a special password. Reality: current Visa guidance says consumers do not need to register separately for 3-D Secure; issuers manage authentication.

Conclusion

VBV is an important historical term in online payment security, but it belongs primarily to an earlier generation of Visa authentication.

Verified by Visa evolved into Visa Secure, and the underlying technology evolved from legacy 3-D Secure toward modern EMV 3DS.

That evolution changed the customer experience dramatically. Authentication no longer needs to mean a password page or OTP challenge on every purchase. Modern Visa Secure can authenticate low-risk transactions frictionlessly while requesting stronger verification when issuer risk systems determine that it is needed.

For consumers, the result is a smoother and more adaptive online payment experience. For merchants, Visa Secure provides stronger authentication information and can support fraud reduction and qualifying liability-shift protections.

The clearest summary is simple: VBV was the old name, Visa Secure is the current Visa program, and EMV 3-D Secure is the modern authentication technology that helps protect Visa e-commerce transactions.