EMV 3-D Secure
EMV 3-D Secure is a messaging protocol that lets an online merchant and the card issuer exchange information to help confirm that a shopper is the legitimate cardholder during a card-not-present purchase, such as an e-commerce checkout. It is intended to help reduce card-not-present fraud and add security to online payments, and it is often branded by card networks under names such as Visa Secure. It is designed to improve on the earlier 3-D Secure 1 protocol by supporting a smoother checkout experience.
EMV 3-D Secure is a card-not-present authentication protocol maintained by EMVCo that enables the exchange of transaction, device, and cardholder data among the three domains (merchant/acquirer, issuer, and interoperability) to support risk-based and, where needed, challenge-based authentication of e-commerce and app-based transactions. The specification (for example, 3-D Secure Specification v2.2.0) defines the messaging framework, while related components such as the 3DS SDK are governed by separate EMVCo and PCI standards; notably, the PCI 3DS SDK Security Standard applies to entities developing 3DS SDKs as defined in the EMV 3-D Secure 3DS SDK Specification. EMV 3DS addresses cardholder authentication at the transaction-initiation stage and is distinct from PCI DSS scope controls, EMV chip authentication, and multi-factor authentication; it is intended to help reduce CNP fraud but does not by itself eliminate fraud, and any associated liability or chargeback treatment is governed by card brand and network rules that vary by region and change over time. Practitioners should confirm protocol versions and requirements against the current EMVCo and PCI published specifications.
Why it matters
Card-not-present (CNP) transactions, such as e-commerce and in-app purchases, lack the physical card and chip verification available at a point-of-sale terminal, which makes confirming that a shopper is the legitimate cardholder more difficult. EMV 3-D Secure is intended to help address this gap by enabling merchants and card issuers to exchange transaction, device, and cardholder information at checkout so the issuer can assess the likelihood that a purchase is legitimate. As card networks brand and promote their own implementations, such as Visa Secure, the protocol has become a widely referenced component of online payment security.
EMV 3DS matters to practitioners because it operates at the transaction-initiation stage and can influence both fraud outcomes and the customer experience. The protocol is designed to improve on the earlier 3-D Secure 1 protocol by supporting a smoother, more integrated checkout, which addresses the friction and abandonment concerns associated with the older protocol. However, it is intended to help reduce CNP fraud rather than eliminate it, and its effectiveness depends on how risk-based and challenge-based authentication are configured and tuned.
EMV 3DS should not be treated as a substitute for other controls. It is distinct from PCI DSS scope-reduction measures, from EMV chip authentication used in card-present environments, and from multi-factor authentication generally. Any liability shift or chargeback treatment associated with an authenticated transaction is governed by card brand and network rules, which vary by region and change over time, so teams should not assume a fixed outcome from using the protocol alone.
Who it's relevant to
Inside EMV 3DS
Common questions
Answers to the questions practitioners most commonly ask about EMV 3DS.