What is EMV 3DS?
EMV 3DS (short for EMV 3-Domain Secure and commonly referred to as 3DS2) is the latest global authentication standard for Card-Not-Present (CNP) transactions. It allows merchants to securely share transaction data with card issuers to improve decision-making during the checkout process.
The protocol was developed by EMVCo to replace the older 3DS version 1. Its main goal is to reduce fraud, prevent false declines, and create a smoother user experience—especially on mobile and in-app purchases.
Why it matters
CNP fraud is one of the biggest risks in digital commerce. At the same time, legitimate transactions are sometimes mistakenly declined, frustrating customers and affecting sales. EMV 3DS helps solve both problems by enabling:
Stronger customer authentication (SCA) in compliance with regulations like PSD2
Smarter risk analysis by sharing detailed transaction data
Frictionless flow for low-risk transactions, minimizing unnecessary step-ups
How it works
Compared to the older 3DS1 protocol, EMV 3DS can transmit over 10 times more data points to the issuer—more than 40 required fields and up to 150 optional fields. These include:
Device information (e.g. operating system, screen size)
Shipping and billing details
Customer’s payment history
Merchant category code
Authentication risk indicators
With this richer dataset, issuers can more accurately assess risk and approve legitimate payments without extra verification steps.
What is a “frictionless” transaction?
A frictionless flow means the customer is authenticated without needing to complete an extra challenge, such as entering a one-time password (OTP) or using biometrics.
According to industry estimates, over 90% of authentication requests using EMV 3DS result in frictionless approvals.
Benefits of EMV 3DS for merchants
Fewer false declines: More transactions are approved thanks to better risk insights.
Reduced fraud: Stronger authentication protects against unauthorized use.
Improved checkout experience: Fewer interruptions during payment.
Mobile-first compatibility: Optimized for apps and responsive design.
Regulatory compliance: Meets SCA requirements under PSD2.
