What is 3DS2?
3D Secure 2 (3DS2) is an added layer of fraud prevention required by card networks that authenticates a cardholder during an online payment.
It is the updated version of 3D Secure (3DS1) and is designed to:
Reduce fraud
Improve approval rates
Shift liability for certain fraud disputes
Comply with Strong Customer Authentication (SCA) regulations (where applicable)
3DS2 allows the issuing bank to verify that the person making the transaction is the legitimate cardholder before approving the payment.
When does 3DS2 trigger?
3DS2 typically triggers on Client-Initiated Transactions (CIT), including:
Online checkout payments
First-time payments entered by the cardholder
Payments where the cardholder is actively present
3DS2 does not trigger on Merchant-Initiated Transactions (MIT), including:
Recurring billing
Subscriptions
Stored card charges processed without the customer present
However:
The initial transaction used to set up recurring billing may require 3DS2 authentication.
Future recurring charges may be exempt only if properly set up under MIT rules and authenticated correctly at the start.
What forms of authentication are used?
If 3DS2 is triggered, the cardholder may be asked to complete authentication through their issuing bank.
Common authentication methods include:
One-time passcodes via SMS
One-time passcodes via email
Banking app push notifications
Biometric authentication (fingerprint or Face ID)
Banking app approval
Security questions (less common with 3DS2)
The issuing bank determines the method, not the merchant or processor.
How do issuing banks decide what level of authentication is used?
There are several factors that issuers take into consideration when issuing a specific authentication:
What authentication methods the customer has enrolled In
Risk level of the transaction
Device being used
Regulatory requirements
Is 3DS2 mandatory?
In the UK, Strong Customer Authentication (SCA) is required for online transactions when the cardholder’s issuing bank is located in the UK or EEA.
Transactions involving cards issued outside these regions (e.g., US or Canada) are not subject to UK SCA requirements, although authentication may still be requested by the issuing bank.
SCA requires two of the following:
Something the customer knows (password, PIN)
Something the customer has (phone, banking app)
Something the customer is (biometrics)
Failure to authenticate when required may result in transaction declines.
Important: 3DS2 Authentication does NOT transfer between processors
If a credit card is:
Authenticated via 3DS2 with Processor A
Then imported into Processor B
The authentication history does not carry over.
Each processor relationship is separate. Any required 3DS2 authentication must be completed again within the new processing environment.
3DS2 & recurring billing requirements
Even if:
A card is imported into your processor
The card was previously used successfully elsewhere
Recurring billing can fail if:
The original transaction was not properly authenticated under 3DS2 when required.
The recurring framework was not correctly established as a Merchant-Initiated Transaction (MIT).
In regions where SCA applies (e.g., UK), the initial cardholder transaction must be properly authenticated for recurring billing to function successfully.
If this is not done, future recurring charges may decline.
Additional important considerations
3DS2 doesn't guarantee approval
Successful authentication:
Confirms the cardholder’s identity
Does not guarantee the transaction will be approved
The issuing bank still evaluates:
Available funds
Fraud risk
Account status
Other internal risk criteria
Frictionless vs Challenge Flow
3DS2 supports two flows:
Frictionless Flow
No visible authentication step for the customer
Issuer approves based on risk data
Challenge Flow
Customer must complete authentication (SMS code, biometric, etc.)
The issuer decides which flow applies.
Liability shift
When 3DS2 is successfully completed:
Fraud liability may shift from the merchant to the issuer (depending on region and card network rules).
This can reduce exposure to fraud chargebacks.
However, liability shift rules vary by card brand and region.
Customer experience impact
3DS2 can:
Improve approval rates when properly configured
Add friction if triggered frequently
Cause confusion if customers are unfamiliar with bank authentication steps
Clear communication with customers can help reduce support tickets related to failed authentication attempts.
Summary
3DS2:
Is an added authentication layer for online payments
Triggers primarily on client-initiated transactions
Is mandatory in the UK (and EEA under SCA)
Does not transfer between processors
Must be properly established for recurring billing compliance
Does not guarantee transaction approval
May shift fraud liability when successfully completed