After the cardholder responds, the SDK re-establishes the secure link, formats and protects a CReq with the response and sends it, setting the challenge cancellation indicator if the cardholder abandons; the ACS validates the CReq and checks the authentication data: if correct it sets status Y, the ECI, the Authentication Value and completion indicator Y and proceeds to results; if incorrect it increments the interaction counter and, at the ACS maximum, sets status N with reason 19 and completion Y, otherwise repeats the challenge.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.