3D Secure, usually shortened to 3DS, is an online card-authentication protocol designed to help merchants and card issuers reduce card-not-present fraud while keeping ecommerce checkout as smooth as possible.

The current industry standard is EMV 3-D Secure (EMV 3DS), maintained by EMVCo. Instead of relying only on a visible password or one-time code, modern 3DS can exchange transaction, payment-method and device information between the merchant and the card issuer so the issuer can assess risk in real time.

For many legitimate purchases, authentication can happen in the background with no extra action from the customer. When the issuer needs more confidence, it can require an additional challenge such as a banking-app approval, biometric verification or one-time passcode.

Quick answer: 3D Secure is an ecommerce authentication system that helps the card issuer verify the person making an online purchase. Modern EMV 3DS uses risk-based authentication: low-risk transactions can be frictionless, while higher-risk transactions can trigger a challenge.

What Does 3D Secure Mean?

3D Secure is a protocol that adds issuer-led authentication to online card payments. EMVCo describes EMV 3DS as a card-not-present fraud-prevention protocol that enables data exchange between the merchant and issuer to authenticate the consumer.

The name '3-D Secure' comes from the three-domain model used to connect the merchant/acquirer side, issuer side and the interoperability infrastructure between them.

What Is EMV 3-D Secure?

EMV 3-D Secure is the modern specification family maintained by EMVCo. It was designed to improve both fraud prevention and customer experience compared with older 3DS implementations.

The protocol lets the merchant send richer information about the transaction, payment method and device to the issuer. The issuer can then make a more informed authentication decision before or alongside payment authorization.

3D Secure vs 3DS2

The term 3DS2 is commonly used for the newer generation of 3-D Secure based on EMVCo specifications. In everyday merchant and consumer discussions, 'modern 3D Secure,' 'EMV 3DS' and '3DS2' often refer to the same modern risk-based authentication family.

The important improvement is not simply a version number. Modern 3DS supports richer data exchange, mobile experiences, app-based authentication and frictionless flows that were not central to older password-oriented 3DS experiences.

How Does 3D Secure Work?

1. The customer starts an online purchase.

The shopper enters or selects an eligible card through a legitimate merchant checkout.

2. The merchant initiates 3DS authentication.

The merchant or payment provider sends authentication data into the 3DS ecosystem.

Promotional banner

3. Transaction and device information reaches the issuer.

Information can include transaction details, payment-method context and device information.

4. The issuer evaluates risk.

The issuer's Access Control Server assesses whether the transaction appears consistent with legitimate cardholder behavior.

5. The issuer chooses a frictionless or challenge flow.

Low-risk transactions can authenticate in the background. Higher-risk transactions can require additional verification.

6. Authentication is completed and the payment proceeds to authorization.

Authentication supports the payment decision, but the issuer's authorization decision remains a separate step.

The Three Main Parts of a 3DS Transaction

Participant

Role

What it does

Merchant / 3DS Requestor

Starts authentication

Provides transaction and checkout context.

3DS infrastructure / card-network program

Connects participants

Supports secure message exchange and program rules.

Issuer / Access Control Server (ACS)

Authenticates cardholder

Assesses risk and chooses frictionless or challenge authentication.

What Is a Frictionless 3DS Flow?

A frictionless flow occurs when the issuer has enough information to authenticate the transaction without asking the shopper for an additional step.

Promotional banner

EMVCo states that in the frictionless flow, the cardholder's identity can be verified automatically through real-time risk assessment. Visa similarly explains that low-risk transactions can be authenticated in the background.

  • No OTP or extra prompt may appear.
  • The customer can often continue checkout normally.
  • The issuer still evaluates transaction risk.
  • A frictionless experience does not mean authentication was skipped.

What Is a 3DS Challenge Flow?

A challenge flow occurs when the issuer needs more confidence before authenticating the transaction or when applicable rules require stronger verification.

The challenge is completed directly with the issuer's authentication system rather than by giving credentials to the merchant.

  • One-time passcode
  • Approval in a banking app
  • Biometric authentication
  • Other issuer-supported authentication methods

Frictionless vs Challenge Flow

Feature

Frictionless flow

Challenge flow

Customer interaction

Usually none beyond normal checkout

Additional authentication required

Typical risk context

Issuer has enough confidence

Issuer needs more confidence or rules require challenge

Example experience

Payment continues in background

App approval, biometric or OTP

Goal

Authenticate with minimal friction

Add stronger verification for uncertain/higher-risk payment

What Information Does 3DS Use?

One of the major advantages of modern EMV 3DS is richer authentication data.

  • Transaction amount and currency
  • Merchant information
  • Payment-method context
  • Device type and browser/app information
  • IP address or location context where available
  • Cardholder transaction history
  • Relationship between the cardholder and merchant
  • Whether the payment is recurring or non-recurring

The exact information available varies by implementation, issuer and 3DS program. The purpose is to help the issuer distinguish normal customer behavior from unusual transaction context.

How Does 3D Secure Help Prevent Card-Not-Present Fraud?

Card-not-present fraud is difficult because the merchant cannot physically inspect the card. 3DS adds an issuer-controlled authentication layer before the merchant relies solely on payment credentials.

  • The issuer can evaluate the device and transaction context.
  • Higher-risk purchases can receive stronger authentication.
  • A copied card number alone may not be enough when a challenge is required.
  • Low-risk legitimate customers can avoid unnecessary checkout friction.
  • Authentication data can improve the wider fraud-risk picture.

3D Secure Does Not Replace Authorization

Authentication and authorization answer different questions.

Process

Main question

Typical outcome

3DS authentication

Is the transaction sufficiently associated with the legitimate cardholder?

Frictionless authentication, challenge or authentication failure.

Payment authorization

Should the issuer approve the requested payment?

Approved or declined.

A transaction can authenticate successfully and still be declined during authorization because of account status, issuer risk controls or other payment reasons.

3D Secure and Strong Customer Authentication (SCA)

In regions where Strong Customer Authentication rules apply, EMV 3DS can support the authentication needed for ecommerce card payments.

A challenge can allow the issuer to authenticate the customer with qualifying factors such as something the customer knows, possesses or is. Some transactions can also qualify for exemptions or fall outside a particular SCA requirement depending on the transaction type and regulation.

3D Secure and Merchant-Initiated Transactions

Merchant-initiated and recurring payment flows need careful classification. The initial customer setup or consent can require authentication, while later qualifying merchant-initiated payments can follow different SCA treatment depending on the regulatory framework.

Merchants should use their payment provider's supported stored-credential and 3DS workflows rather than trying to infer SCA requirements from whether a challenge appeared.

3D Secure vs CVV/CVC

CVV/CVC checks a card security value. 3DS authenticates the customer or transaction context through the issuer.

  • CVV/CVC is a verification signal tied to card details.
  • 3DS is an authentication protocol.
  • A CVV match does not replace 3DS authentication.
  • A strong fraud strategy can use both controls together.

3D Secure vs AVS

AVS compares billing-address information with issuer records where supported. 3DS focuses on cardholder authentication and transaction risk.

Promotional banner

AVS can contribute useful context, but it does not provide the issuer-led authentication that EMV 3DS is designed to support.

3D Secure and Tokenization

Tokenization protects the payment credential by replacing the underlying PAN with a token. 3DS protects the transaction by adding authentication.

EMVCo has published guidance on using payment-token data within 3DS because richer token information can further improve issuer risk analysis in supported payment flows.

Visa Secure and Other 3DS Programs

Card networks operate their own programs based on EMV 3DS specifications. Visa's program is called Visa Secure. Other networks use their own consumer-facing program names while relying on the broader EMV 3DS framework.

Consumers therefore may see different branding depending on the card network even though the underlying authentication model is based on the same industry standard.

Is Verified by Visa the Same as 3D Secure?

Verified by Visa was Visa's older branding for its earlier 3-D Secure service. Visa Secure is the modern Visa program based on EMV 3-D Secure.

Older terms such as VBV and 'non-VBV' can be misleading because modern 3DS can authenticate a transaction without displaying the kind of visible password prompt associated with earlier systems.

Why You May Not See an OTP During 3DS

Modern 3DS is intentionally designed so most low-risk legitimate payments do not require an extra challenge.

Visa explains that for many purchases, the shopper may not notice Visa Secure working because authentication happens in the background. An OTP or biometric prompt appears only when additional verification is needed.

What Should a Legitimate 3DS Challenge Look Like?

  • It should be connected to the purchase you just initiated.
  • The verification should be controlled by or clearly associated with your card issuer.
  • You may be asked to approve inside your banking app or complete another issuer-supported authentication step.
  • You should not be asked to send a banking password or one-time code to a person by email, chat or phone.

Warning Signs of Fake 3DS Verification

  • An unexpected email or text asks you to 'complete 3D Secure' for a purchase you did not start.
  • A caller asks you to read a one-time code aloud.
  • The page asks for unrelated online-banking credentials.
  • The verification page appears on a suspicious or misspelled domain.
  • You are told to install remote-access software to approve a transaction.
  • The message threatens account closure unless you verify immediately.

What Merchants Gain From 3DS

  • Stronger issuer-led authentication for ecommerce payments
  • Better fraud-risk information
  • Reduced CNP fraud exposure
  • Potential reduction in fraud-related chargebacks under applicable network rules
  • Support for SCA obligations where required
  • Lower checkout friction when low-risk transactions can remain frictionless

What Consumers Gain From 3DS

  • Additional protection for online card payments
  • Issuer-controlled authentication when a transaction appears unusual
  • Fewer unnecessary challenges when risk is low
  • Support for app-based and biometric authentication
  • More confidence that payment security adapts to transaction risk

Frequently Asked Questions

What is 3D Secure?

3D Secure is an online card-authentication protocol used to help issuers and merchants reduce card-not-present fraud.

What is EMV 3-D Secure?

EMV 3DS is the modern industry-standard 3-D Secure framework maintained by EMVCo.

What is 3DS2?

3DS2 is a common name for the newer generation of 3-D Secure based on EMVCo specifications and richer risk-based authentication.

Promotional banner

Does 3D Secure always require an OTP?

No. Modern 3DS supports frictionless authentication, so many low-risk transactions do not show an OTP or other challenge.

What is a frictionless 3DS flow?

It is a flow where the issuer authenticates the transaction in the background using available risk information without extra customer interaction.

What is a 3DS challenge?

It is an additional issuer-controlled authentication step, such as banking-app approval, biometric verification or a one-time code.

Does 3D Secure guarantee payment approval?

No. Authentication and authorization are separate processes, and the issuer can still decline an authenticated payment.

Does 3D Secure prevent all online card fraud?

No. It is one important layer and works best alongside authorization, tokenization, AVS/CVV where relevant, device signals and broader fraud monitoring.

Is Visa Secure the same as 3D Secure?

Visa Secure is Visa's program based on the EMV 3-D Secure framework.

Is Verified by Visa still used?

Verified by Visa is legacy branding. Visa now uses Visa Secure for its modern EMV 3-D Secure program.

Final Thoughts

3D Secure is one of the core authentication technologies behind modern ecommerce card payments.

EMV 3DS helps merchants and issuers exchange richer transaction and device information so the issuer can authenticate low-risk purchases silently and challenge higher-risk transactions when additional confidence is needed.

The most important concept is that 3DS is risk-based. No visible OTP does not mean authentication was absent, and a visible challenge does not by itself determine whether the final payment will be approved.

Used alongside authorization, tokenization, AVS/CVV where relevant and wider fraud monitoring, 3D Secure gives merchants and consumers a stronger layer of protection against card-not-present fraud.

Authoritative References

Editorial note: This article is educational and focused on payment-security awareness. It explains legitimate authentication and fraud-prevention concepts and does not provide methods for bypassing issuer or merchant security.