Skip to main content
Category: 3-D Secure

Electronic Commerce Indicator

Also known as: ECI, ECI code, ECI value, e-commerce indicator
Simply put

An Electronic Commerce Indicator (ECI) is a short code attached to an online card transaction that signals how, or whether, the payment was authenticated during the checkout process. It helps the merchant and the card issuer understand the security context of the transaction and decide what to do next, such as proceeding with or declining a payment. The code is also used to communicate who may carry responsibility if the transaction turns out to be fraudulent.

Formal definition

The Electronic Commerce Indicator (ECI) is a two-digit response value used in 3-D Secure processing, including EMV 3-D Secure, that conveys the level of payer authentication achieved for a card-not-present transaction. It is returned during the authentication flow and passed into authorization to indicate to the issuer how the transaction was authenticated and to inform fraud-liability handling; merchants use the ECI value to determine subsequent processing decisions. The specific ECI values, their meanings, and any associated liability shift are defined by individual card brand and network rules, which vary by region and change over time, so exact mappings should be confirmed against the current rules of the applicable network. ECI is a signal about authentication context only and does not by itself authenticate a cardholder or eliminate fraud.

Why it matters

The Electronic Commerce Indicator sits at the intersection of authentication and fraud liability for card-not-present transactions, which makes it a practical decision input rather than just a technical artifact. When a 3-D Secure authentication flow completes, the ECI value communicates to the issuer how the transaction was authenticated and, under the applicable card brand and network rules, can inform who carries responsibility if the transaction is later disputed as fraudulent. Merchants and processors rely on this signal to decide whether to proceed with authorization, apply additional scrutiny, or decline.

Because the meanings of specific ECI values and any associated liability shift are defined by individual card brands and networks, and because those rules vary by region and change over time, misreading or hard-coding ECI mappings can lead to incorrect processing decisions and unexpected chargeback outcomes. A merchant that assumes a given ECI value always transfers fraud liability may find that assumption does not hold across all networks or regions. Confirming values against the current published rules of the applicable network is important for accurate handling.

It is equally important to understand what the ECI does not do. The ECI is a signal about authentication context only; it does not itself authenticate a cardholder and does not eliminate fraud. Treating a favorable ECI value as a guarantee of a legitimate transaction can create a false sense of security, since fraud such as account takeover or first-party disputes can still occur within transactions that carry any given authentication outcome. The ECI should be used as one input alongside broader fraud-detection and risk controls, not as a standalone control.

Who it's relevant to

Merchants and e-commerce teams
Merchants use the returned ECI value to decide what to do next in a 3-D Secure transaction, such as whether to proceed with authorization or reject the payment. Teams building checkout logic should map ECI values against the current rules of each applicable network rather than assuming a single interpretation, and should treat the ECI as one input among broader fraud controls rather than a guarantee against fraud.
Payment processors and gateways
Processors and gateways carry the ECI value from the authentication flow into the authorization message and expose it to merchants. Because value meanings and liability treatment vary by card brand, network, and region and change over time, processors need to keep their handling and documentation aligned with current network rules to avoid propagating outdated or incorrect mappings.
Issuers and issuing risk teams
Issuers receive the ECI as a signal of how a card-not-present transaction was authenticated, which can inform authorization decisions and fraud-liability handling under the applicable network rules. Issuers should treat the ECI as authentication context rather than definitive proof of a legitimate cardholder, since it does not by itself authenticate the payer or eliminate fraud.
Fraud analysts and chargeback teams
Analysts investigating disputes use the ECI to understand the authentication context of a transaction and how it may relate to fraud-liability outcomes governed by card brand and network rules. Because liability shift and chargeback rules vary by region and change, teams should confirm the relevant rules for the specific network involved and should not treat any single ECI value as eliminating dispute or fraud risk.

Inside ECI

ECI Value
A numeric indicator returned during or after a 3-D Secure authentication attempt that signals the authentication outcome and the degree of authentication achieved for a card-not-present transaction. The specific values and their meanings vary by card brand, so the same numeral can carry different meaning across networks.
Authentication Outcome Signaling
The ECI communicates whether cardholder authentication was fully completed, attempted but not fully completed, or not performed. This context is passed into authorization so the issuer and acquirer can interpret the authentication status of the transaction.
Relationship to 3-D Secure
The ECI is produced in connection with the 3-D Secure protocol and is distinct from the CAVV/AAV cryptographic value that accompanies it. The ECI describes the outcome; the cryptographic value is intended to provide verifiable proof of that outcome.
Card Brand Dependence
ECI values, their numbering, and their interpretation are defined by individual card brand and network rules rather than by PCI DSS or any single unified specification, and these rules vary by brand and may change over time.
Liability Context
The ECI is one input that networks and issuers may consider when applying liability shift rules for card-not-present transactions. Whether and how liability shifts is governed by card brand and network rules, which vary by region and change over time.

Common questions

Answers to the questions practitioners most commonly ask about ECI.

Does a favorable ECI value mean the merchant is protected from all chargebacks on the transaction?
No. An ECI value reflects the authentication outcome or attempt status reported through 3-D Secure at authorization time, and it may influence liability shift under the applicable card brand and network rules. It does not by itself guarantee protection from chargebacks. Liability shift and chargeback rights are governed by card brand and network rules, which change and vary by region, and other dispute reason codes, such as those tied to friendly or first-party fraud, may still apply. Confirm the specific outcome against the current network rules rather than assuming any ECI value eliminates chargeback exposure.
Is the ECI the same thing as a proof that strong customer authentication was successfully completed?
Not necessarily. The ECI is an indicator that summarizes the authentication state associated with a transaction, but the exact meaning of a given value depends on the card brand and the 3-D Secure flow, and some values indicate an attempted rather than a fully completed authentication. Strong customer authentication is a separate regulatory concept, and 3-D Secure is one mechanism that may support it. An ECI value should be interpreted against the specific brand's definitions rather than read as a universal confirmation that authentication was completed.
Where in the transaction flow is the ECI value set and passed?
The ECI is typically produced as part of the 3-D Secure authentication exchange and then carried into the authorization request so the issuer and acquirer can factor it into their decisioning. Because the exact fields, positions, and permitted values differ by card brand and by integration, teams should follow the specifications provided by their acquirer, gateway, and the relevant card brand rather than assuming a single universal format.
How should a merchant handle a transaction where the ECI indicates an attempted but not fully completed authentication?
Treat it according to the card brand's definitions and your acquirer's guidance, since an attempted status can carry different liability and risk implications than a fully authenticated status. Because the interpretation depends on brand and network rules that vary by region and change over time, merchants often combine the ECI with their own fraud screening rather than relying on it alone. Document the decisioning logic and confirm the handling against current network rules.
Do different card brands use the same ECI values to mean the same thing?
Not consistently. The set of permitted ECI values and their meanings can differ between card brands, so the same numeric value may correspond to different authentication states depending on the brand. Implementations should map ECI values per brand using the current specifications from the relevant card brand and acquirer, and avoid hardcoding a single cross-brand interpretation.
Is the ECI value considered cardholder data or sensitive authentication data for storage purposes?
The ECI is an authentication result indicator rather than an element of the primary account number or the sensitive authentication data set such as full track data, CAV2/CVC2/CVV2/CID, or PINs. Storing or logging an ECI does not remove the separate obligation to protect any cardholder data and to not retain sensitive authentication data after authorization. Handle any accompanying account data under the applicable controls, and confirm storage practices against the current published PCI DSS requirements rather than assuming the ECI changes those obligations.

Common misconceptions

The ECI is cardholder data or sensitive authentication data governed by PCI DSS storage rules.
The ECI is an indicator describing the outcome of a 3-D Secure authentication attempt, not a data element such as PAN or a CVV2/CVC2/CID. It is distinct from sensitive authentication data, which must not be stored after authorization. How you handle the ECI does not by itself change your obligations for actual cardholder data or sensitive authentication data.
A favorable ECI value guarantees a legitimate transaction or prevents fraud and chargebacks.
The ECI only signals the authentication status reported through 3-D Secure. It is intended to help inform authorization and may affect liability under card brand rules, but it does not confirm the cardholder's identity beyond what the protocol established and does not prevent card-not-present fraud, friendly or first-party fraud, or chargebacks. Liability shift outcomes depend on network rules that vary by region and change over time.
ECI values mean the same thing across all card brands.
ECI values and their meanings are defined by individual card brand and network rules, so the same numeral can indicate different authentication outcomes depending on the brand. Practitioners should map ECI values against each brand's current published rules rather than assuming a universal interpretation.

Best practices

Map each ECI value to its meaning per the specific card brand's current rules, and confirm interpretations against the applicable network documentation rather than assuming values are uniform across brands.
Treat the ECI as one input alongside the accompanying cryptographic value (CAVV/AAV) and other risk signals, rather than relying on the ECI alone to judge authentication status.
Pass the ECI accurately from the 3-D Secure result into the authorization message so issuers can correctly interpret the authentication context and apply applicable liability rules.
Verify current liability shift rules with your acquirer and the relevant card brands, and account for regional variation and periodic rule changes when relying on ECI-based liability outcomes.
Do not treat the ECI as a substitute for a layered fraud strategy; combine it with fraud screening and monitoring, and account for false-positive and false-negative trade-offs in any detection logic.
Keep ECI handling logic under change control and review it when card brands update their value definitions or 3-D Secure protocol behavior.