VBV stands for Verified by Visa. It was Visa’s original online authentication program for e-commerce payments. The Verified by Visa name is no longer used; Visa’s current program is called Visa Secure and uses the EMV 3-D Secure (3DS) protocol. During an online purchase, 3DS lets the merchant and card issuer exchange transaction data so the issuer can assess risk and, when needed, ask the cardholder to verify their identity using an OTP, banking-app approval, biometrics, or another supported method.

What Is VBV?

VBV stands for Verified by Visa, a name that many cardholders and merchants still recognize from earlier generations of online payment authentication. Verified by Visa was created to add an extra identity-verification step to certain Visa e-commerce transactions before the payment was sent for authorization.

The basic goal was straightforward: if someone entered Visa card details on a website, the issuing bank could ask for additional proof that the person making the purchase was the legitimate cardholder. Depending on the issuer and the period, that verification could involve a password, one-time passcode, security question, or another authentication step.

The important 2026 clarification is that “Verified by Visa” is now legacy terminology. Visa’s current program is called Visa Secure. Visa itself describes Visa Secure as the successor to Verified by Visa and as its program for transactions that use the 3-D Secure standard.

What Does VBV Stand For?

VBV stands for Verified by Visa. The phrase became common enough that people still search for terms such as “VBV meaning,” “what is VBV,” “VBV card,” and “Verified by Visa.”

However, VBV does not describe a special category of Visa card. A card is not permanently “VBV” or “non-VBV” in the same way it might be debit, credit, prepaid, or commercial. Instead, Verified by Visa referred to an authentication program used for eligible online transactions. Whether a cardholder sees an authentication step depends on factors such as the issuer, merchant, payment flow, transaction risk, supported 3DS version, and applicable regulatory requirements.

Is Verified by Visa Still Used in 2026?

The Verified by Visa brand name is no longer the main consumer-facing name. Visa now uses Visa Secure for its online authentication program. Visa’s current consumer guidance states that the old Verified by Visa name is no longer in use, while the underlying purpose of helping protect online purchases continues through the enhanced Visa Secure service.

You may still encounter “VBV” on older websites, archived payment documentation, merchant dashboards, forums, or search results. Treat it as a legacy term that usually points to Visa’s 3-D Secure authentication ecosystem rather than as a current standalone technology.

What Is Visa Secure?

Visa Secure is Visa’s current program for authenticating eligible e-commerce transactions using EMV 3-D Secure. It helps the merchant, Visa ecosystem, and issuing bank exchange information so the issuer can evaluate whether the person attempting the payment is likely to be the legitimate cardholder.

Visa Secure is designed to balance security with checkout usability. Instead of forcing every shopper through the same password or OTP screen, modern 3DS can support risk-based authentication. Low-risk transactions may complete without any visible interruption, while higher-risk transactions can trigger a step-up challenge.

What Is 3D Secure?

3-D Secure, often shortened to 3DS, is an authentication protocol used for online card payments. It is designed to provide an additional layer of protection for card-not-present transactions by enabling information to move between the merchant side, the cardholder’s issuer, and the payment-network authentication ecosystem.

Promotional banner

The modern standard is maintained by EMVCo and is known as EMV 3-D Secure. EMVCo documentation describes two primary user experiences: the frictionless flow and the challenge flow. In 2026, EMVCo’s public documentation lists 3DS 2.3.1 as a current specification family and also shows draft work toward 2.4.0, illustrating that the protocol continues to evolve.

Why Is It Called “3-D Secure”?

The “3-D” refers to three domains that participate in the authentication model: the merchant/acquirer side, the issuer side, and the interoperability domain that connects the ecosystem. It does not mean three passwords, three security questions, or three separate payment steps.

Promotional banner

Verified by Visa was Visa’s branded implementation of the original 3-D Secure concept. Visa Secure is the modern program name, and it uses EMV 3-D Secure standards. This is why the terms are often mixed together in older articles and user discussions.

Term

What it means

Current status

VBV

Short form for Verified by Visa

Legacy/common search term

Verified by Visa

Visa’s earlier branded online authentication program

Brand name retired

Visa Secure

Visa’s current EMV 3-D Secure program

Current Visa program

3-D Secure / 3DS

The authentication protocol used for e-commerce cardholder verification

Current industry technology

EMV 3-D Secure

Modern 3DS specifications maintained by EMVCo

Current standards framework

How Does a 3D Secure Payment Work?

A simplified modern 3DS transaction can be understood in five stages:

  1. The shopper enters card details or uses a stored-card checkout at a participating merchant.
  2. The merchant or payment provider initiates a 3DS authentication request and sends relevant transaction information through the authentication ecosystem.
  3. The issuing bank evaluates available data, which can include transaction details, device information, merchant information, prior behavior, and other risk signals.
  4. If the issuer is sufficiently confident, the transaction may use a frictionless authentication flow. If more proof is needed, the issuer can present a challenge.
  5. After authentication, the payment continues to authorization, where the issuer still decides whether to approve or decline the financial transaction.

Authentication and authorization are related but different. Passing a 3DS authentication step does not guarantee the payment will be approved. A card can still be declined for reasons such as insufficient funds, account restrictions, suspected fraud, expired credentials, or issuer policy.

Frictionless Authentication vs Challenge Authentication

Feature

Frictionless flow

Challenge flow

What the shopper sees

Usually no additional verification screen

An additional identity-verification step

When it is used

When issuer risk assessment indicates sufficient confidence

When issuer wants stronger proof of identity

Typical experience

Checkout continues in the background

OTP, app approval, biometrics, or another supported method

Security model

Risk-based data analysis

Step-up cardholder authentication

Goal

Reduce unnecessary checkout friction

Add stronger verification when risk is higher

This difference explains why a Visa Secure transaction does not always display an OTP or a “Verified by Visa” screen. Modern 3DS is designed to authenticate many transactions silently when the issuer has enough information to make a confident decision.

What Authentication Methods Can Visa Secure Use?

The exact challenge method is selected by the issuing bank and can vary by country, bank, device, and transaction. Common methods include:

  • One-time passcodes sent through an issuer-supported channel.
  • Approval inside a mobile banking application.
  • Biometric authentication such as fingerprint or facial recognition when supported by the issuer and device.
  • Out-of-band authentication, where verification happens in a separate trusted banking channel.
  • Knowledge-based or issuer-specific verification in some environments.

A merchant should not assume that every 3DS challenge will look the same. The authentication experience is primarily controlled by the issuer within the applicable 3DS program rules.

Does VBV Mean a Payment Must Use an OTP?

No. This is one of the most common misunderstandings. Older Verified by Visa implementations were often associated with a visible password or OTP prompt, so many users came to think “VBV” meant “an OTP screen.” Modern Visa Secure with EMV 3DS is more flexible.

A transaction may be authenticated through a frictionless flow with no visible challenge. If a challenge is required, an OTP is only one possible method. The issuer may instead use an app notification, biometrics, or another supported authentication mechanism.

Why Do Some Visa Payments Not Show 3D Secure?

There are several legitimate reasons an online Visa purchase may complete without a visible 3DS challenge:

  • The transaction completed through a frictionless 3DS flow.
  • The merchant or payment flow did not invoke 3DS for that transaction.
  • The issuer assessed the transaction as low risk and did not require step-up verification.
  • The transaction type, region, or regulatory context did not require a visible challenge.
  • The payment was handled through a wallet or stored-credential flow with other authentication and risk controls.
  • The transaction may have been outside the scope of a particular 3DS program or exemption framework.

The absence of an OTP alone does not prove that a transaction is unsafe, “non-VBV,” or unauthenticated. Modern payment security uses multiple layers, many of which are invisible to the cardholder.

How Does 3D Secure Help Reduce Card-Not-Present Fraud?

Card-not-present fraud is difficult because a merchant cannot physically inspect the card or cardholder. 3DS helps by allowing the issuer to evaluate additional context and, when necessary, verify the cardholder before authorization.

Visa says Visa Secure is intended to help prevent card-not-present fraud while reducing unnecessary friction. Visa has also published data indicating materially lower fraud rates for authenticated e-commerce transactions compared with non-authenticated transactions. Those figures are network-specific and should not be treated as a guarantee for every merchant, but they illustrate why authentication is an important layer in online payment security.

Promotional banner

Does 3D Secure Guarantee That a Transaction Is Fraud-Free?

No. No single payment-security control can guarantee that fraud will never occur. 3DS reduces risk by strengthening authentication, but merchants and issuers still need additional controls such as fraud scoring, tokenization, account monitoring, velocity rules, device intelligence, AVS, CVV/CVC checks, behavioral signals, and post-transaction monitoring.

VBV, 3D Secure, AVS and CVV: What Is the Difference?

Security control

Primary purpose

What it checks

Visa Secure / 3DS

Cardholder authentication

Whether the payer is likely to be the legitimate cardholder

AVS

Billing-address verification

Whether submitted address data corresponds with issuer records

CVV/CVC

Card security-code verification

Whether the supplied security code matches issuer/network expectations

Tokenization

Protect stored or transmitted card data

Replaces the primary account number with a token for supported use cases

Fraud scoring

Transaction risk assessment

Combines multiple signals to estimate fraud risk

These controls are complementary. A strong merchant security stack does not rely on only one of them.

What Does “VBV Card” Mean?

People sometimes say “VBV card” to describe a Visa card that can participate in Verified by Visa or Visa Secure authentication. The phrase is informal. It is more accurate to say that a Visa card or issuer supports Visa Secure / EMV 3DS for eligible transactions.

Similarly, labels such as “non-VBV card” can be misleading because authentication behavior depends on the transaction context. A card that completes one purchase without a visible challenge may still be eligible for 3DS on another purchase.

3D Secure and Payment Liability

3DS can affect fraud-liability treatment for certain authenticated e-commerce transactions, but the exact result depends on the card network, transaction category, authentication outcome, merchant configuration, region, and network rules. Merchants should not assume that simply attempting 3DS automatically transfers all fraud liability.

The practical takeaway is to treat liability protection as a network-rule issue that must be validated with the merchant’s acquirer or payment service provider. Authentication should primarily be viewed as a fraud-reduction and identity-verification layer, not as a universal chargeback shield.

Common Visa Secure and 3DS Problems

1. The OTP never arrives

Possible causes include outdated issuer contact details, telecom delays, roaming issues, blocked messages, or issuer-side service problems. Cardholders should use the issuer’s official support channel rather than repeatedly entering credentials on an unfamiliar page.

2. The challenge page keeps failing

Browser restrictions, blocked cookies, network instability, outdated app components, merchant integration problems, or issuer-side errors can interrupt a 3DS challenge. Trying the purchase again through the merchant’s official site or app may help, but repeated failures should be escalated to the issuer or merchant.

3. Authentication succeeds but the payment is declined

This can happen because authentication and authorization are separate. The issuer may authenticate the cardholder successfully but still decline the purchase for account or risk reasons.

4. A page says “Verified by Visa” but looks suspicious

Treat unexpected branding carefully. Verified by Visa is a legacy name, and phishing pages can imitate payment-security screens. Cardholders should avoid entering banking credentials into pages reached from unsolicited messages and should confirm transactions through the merchant and bank’s official channels.

How Cardholders Can Use Visa Secure Safely

  • Keep your phone number and contact details updated with your card issuer.
  • Use the official banking app when your issuer offers app-based authentication.
  • Never share an OTP with someone who calls or messages you claiming to be from a bank, merchant, or delivery service.
  • Read the transaction amount and merchant information shown in the authentication prompt before approving it.
  • Do not approve a banking-app authentication request for a purchase you did not initiate.
  • Access merchants through their official website or app rather than links in suspicious messages.
  • Enable transaction alerts so unauthorized purchases are detected quickly.
  • Contact the issuer immediately if an unexpected authentication request appears.

Best Practices for Merchants

  • Use a reputable payment service provider or 3DS provider that supports current EMV 3DS versions.
  • Send accurate transaction and device data so issuers can make better risk decisions.
  • Measure challenge rates, authentication success, authorization conversion, false declines, and fraud outcomes together.
  • Do not treat 3DS as a substitute for fraud scoring, tokenization, AVS, CVV/CVC, and account-security controls.
  • Design challenge handoffs carefully on mobile and desktop to minimize checkout abandonment.
  • Keep 3DS integrations and SDKs updated and follow provider and scheme migration guidance.
  • Explain security prompts clearly so customers know when additional bank verification may appear.
  • Review regional SCA and authentication requirements with qualified compliance and payment specialists.

Verified by Visa vs Visa Secure: Quick Comparison

Topic

Verified by Visa (legacy)

Visa Secure (current)

Brand name

Verified by Visa / VBV

Visa Secure

Technology era

Associated with earlier 3DS implementations

Uses modern EMV 3-D Secure

Typical user perception

Password/OTP-style challenge screens

Risk-based frictionless or challenge authentication

Device experience

Primarily traditional web checkout

Designed for modern web and mobile commerce

Current relevance

Useful legacy/search term

Current Visa authentication program

Frequently Asked Questions

What is VBV?

VBV stands for Verified by Visa, the former name of Visa’s online cardholder-authentication program. The current program is Visa Secure.

Promotional banner

What does Verified by Visa mean?

It refers to Visa’s earlier 3-D Secure authentication program for eligible online transactions. It added an issuer-controlled identity-verification layer before authorization.

Is Verified by Visa still active?

The old Verified by Visa brand name is no longer the primary name. Visa now uses Visa Secure with EMV 3-D Secure.

Is VBV the same as 3D Secure?

Not exactly. Verified by Visa was Visa’s branded 3-D Secure program. 3-D Secure is the underlying authentication protocol used across card-payment ecosystems.

What is Visa Secure?

Visa Secure is Visa’s current program for online card authentication using EMV 3-D Secure.

Does every Visa Secure payment require an OTP?

No. Modern 3DS can authenticate transactions through a frictionless flow. If a challenge is required, the issuer may use an OTP, banking-app approval, biometrics, or another method.

What is a 3D Secure challenge?

A challenge is an additional verification step requested by the card issuer when more evidence is needed to confirm the cardholder’s identity.

Why did my Visa payment go through without Verified by Visa?

The transaction may have used frictionless 3DS, another supported risk process, or a payment flow that did not require a visible authentication challenge.

Does 3D Secure prevent all online card fraud?

No. It reduces risk but should be combined with other controls such as tokenization, AVS, CVV/CVC checks, fraud scoring, and account monitoring.

Is a “VBV card” a special type of Visa card?

No. The phrase is informal and usually refers to a card or issuer that participates in Visa Secure / 3DS for eligible transactions.

Conclusion

VBV means Verified by Visa, but the name belongs to an earlier generation of Visa’s e-commerce authentication program. Today, the correct current term is Visa Secure, which uses EMV 3-D Secure to help issuers verify online cardholders and reduce card-not-present fraud.

The biggest change from the old VBV experience is that modern 3DS does not always interrupt checkout with a password or OTP. Risk-based authentication can allow low-risk purchases to proceed frictionlessly while higher-risk transactions receive stronger verification. For cardholders, that means fewer unnecessary prompts and stronger protection when extra proof is needed. For merchants, it means authentication can become part of a layered fraud-prevention strategy rather than a one-size-fits-all checkout barrier.

Authoritative Sources for Editorial Verification

  • Visa Developer — Visa 3D Secure UX Guidelines: Visa Secure was previously known as Verified by Visa and uses the 3-D Secure standard.
  • Visa — Visa Secure with EMV 3-D Secure: current Visa authentication program and card-not-present fraud guidance.
  • Visa Consumer Security — Safe Online Shopping: confirms the Verified by Visa name is no longer in use.
  • EMVCo — EMV 3-D Secure: current 3DS framework and specification information.
  • EMVCo — EMV 3-D Secure White Paper: frictionless and challenge flows and their security purpose.