EMV 3‑D Secure (3DS) - Payment Authentication Protocol
EMV 3DS - Three-Domain Model and Roles

EMV 3‑D Secure (3DS) - Payment Authentication Protocol 05: Access Control Server (Issuer Domain)

The Access Control Server (ACS), in the Issuer Domain, performs cardholder authentication on behalf of the issuer, decides frictionless vs challenge, conducts the challenge where required, and generates the authentication value/result. EMVCo approves ACS products.

What else in your programme already covers this

This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 1 control

  • 6.6 Access control
  • NISTSP63-5 AAL1 and AAL2 Authentication: MFA, Approved Authenticators, Session Binding

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in EMV 3DS - Three-Domain Model and Roles

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.