EMV 3-D Secure (3DS) - Payment Authentication Protocol
EMVCo's EMV 3-D Secure protocol for authenticating cardholders in card-not-present payments and non-payment identity checks: the three-domain model, the 3DS Server, Directory Server, Access Control Server and 3DS SDK, the AReq/ARes, CReq/CRes, RReq/RRes, PReq/PRes and OReq/ORes messages, app-based, browser-based and 3RI flows, frictionless, challenge and decoupled authentication, user interface, message handling, timeouts and the secure links and functions, from the complete v2.0.0 specification; and the features 2.1 to 2.3.1 added (3RI and decoupled fallback, exemptions, Trust List, device binding, Secure Payment Confirmation, out-of-band app switching, message extensions, the Split-SDK, operation messages) read against the complete v2.3.1.1 core specification.
EMV 3-D Secure (3DS) - Payment Authentication Protocol is a compliance framework from Global (payment systems participating in EMVCo) with 6 domains and 53 controls that map to 4 other frameworks. The largest domains are Versions 2.2 and 2.3.1: features added after v2.0.0 – EMV 3-D Secure (3DS) - Payment Authentication Protocol (20 controls), Authentication flow requirements (chapter 3: app-based, out-of-band, browser-based) – EMV 3-D Secure (3DS) - Payment Authentication Protocol (12 controls), Message handling requirements (chapter 5) – EMV 3-D Secure (3DS) - Payment Authentication Protocol (9 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Authentication flow requirements (chapter 3: app-based, out-of-band, browser-based) – EMV 3-D Secure (3DS) - Payment Authentication Protocol
| Code | Title |
|---|---|
| emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S10-11 | 3.1.S10-11 App: SDK completes the secure channel and sends the first CReq (Steps 10 and 11) |
| emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S12-14 | 3.1.S12-14 App: ACS builds the challenge and the SDK renders it (Steps 12 to 14) |
| emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S15-17 | 3.1.S15-17 App: cardholder response, verification, retries and abandonment (Steps 15 to 17) |
| emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S18-22 | 3.1.S18-22 App: results messaging RReq and RRes (Steps 18 to 22) |
| emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S23-25 | 3.1.S23-25 App: final CRes and completion (Steps 23 to 25) |
| emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S4 | 3.1.S4 App: Requestor App and SDK gather AReq data (Steps 1 to 4) |
| emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S5 | 3.1.S5 App: 3DS Server verifies the SDK, routes and sends the AReq (Step 5) |
| emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S6 | 3.1.S6 App: DS validates, checks participation and forwards the AReq (Step 6) |
| emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S7 | 3.1.S7 App: ACS decides the transaction status and prepares any challenge (Step 7) |
| emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S8-9 | 3.1.S8-9 App: DS relays the ARes and the 3DS Server acts on the status (Steps 8 and 9) |
| emv-3-d-secure-3ds-payment-authentication-protocol::3.2 | 3.2 Out-of-band challenge flow exceptions |
| emv-3-d-secure-3ds-payment-authentication-protocol::3.3 | 3.3 Browser-based flow requirements |
Data elements, extensions and risk information (Annex A) – EMV 3-D Secure (3DS) - Payment Authentication Protocol
| Code | Title |
|---|---|
| emv-3-d-secure-3ds-payment-authentication-protocol::A.1-6 | A.1-6 Data elements: presence, edit criteria, AReq encryption, detailed values and message extensions |
| emv-3-d-secure-3ds-payment-authentication-protocol::A.7 | A.7 3DS Requestor risk information: cardholder account, merchant risk indicator and requestor authentication |
Message handling requirements (chapter 5) – EMV 3-D Secure (3DS) - Payment Authentication Protocol
| Code | Title |
|---|---|
| emv-3-d-secure-3ds-payment-authentication-protocol::5.1 | 5.1 General message handling: POST, content type, Base64, versions, parsing and validation |
| emv-3-d-secure-3ds-payment-authentication-protocol::5.2-4 | 5.2-4 Outages, availability and error codes |
| emv-3-d-secure-3ds-payment-authentication-protocol::5.5.1 | 5.5.1 Transaction timeouts (Req 5.35 to 5.43) |
| emv-3-d-secure-3ds-payment-authentication-protocol::5.5.2 | 5.5.2 Connection and read timeouts per message pair (Req 5.44 to 5.61) |
| emv-3-d-secure-3ds-payment-authentication-protocol::5.6 | 5.6 PReq/PRes card range cache |
| emv-3-d-secure-3ds-payment-authentication-protocol::5.7 | 5.7 App-based message handling and CReq/CRes protection |
| emv-3-d-secure-3ds-payment-authentication-protocol::5.8.1 | 5.8.1 3DS Method handling |
| emv-3-d-secure-3ds-payment-authentication-protocol::5.8.2 | 5.8.2 Browser challenge window (Req 5.81 to 5.86) |
| emv-3-d-secure-3ds-payment-authentication-protocol::5.9 | 5.9 Message error handling per component |
Security requirements: links and functions (chapter 6) – EMV 3-D Secure (3DS) - Payment Authentication Protocol
| Code | Title |
|---|---|
| emv-3-d-secure-3ds-payment-authentication-protocol::6.1.1 | 6.1.1 Link a: consumer device to 3DS Requestor |
| emv-3-d-secure-3ds-payment-authentication-protocol::6.1.2-3 | 6.1.2-3 Links b and c: 3DS Server to DS and DS to ACS |
| emv-3-d-secure-3ds-payment-authentication-protocol::6.1.4 | 6.1.4 Link d: SDK or browser to ACS for the challenge |
| emv-3-d-secure-3ds-payment-authentication-protocol::6.1.8 | 6.1.8 Link h: browser to ACS for the 3DS Method |
| emv-3-d-secure-3ds-payment-authentication-protocol::6.2.1-2 | 6.2.1-2 Functions H and I: SDK authenticity and SDK encryption to the DS |
| emv-3-d-secure-3ds-payment-authentication-protocol::6.2.3-4 | 6.2.3-4 Functions J and K: SDK to ACS secure channel and protected challenge messages |
User interface requirements (chapter 4) – EMV 3-D Secure (3DS) - Payment Authentication Protocol
| Code | Title |
|---|---|
| emv-3-d-secure-3ds-payment-authentication-protocol::4.2.1 | 4.2.1 App processing screen (Req 4.1 to 4.12) |
| emv-3-d-secure-3ds-payment-authentication-protocol::4.2.2-3 | 4.2.2-3 App native UI templates and message exchange (Req 4.13 to 4.18) |
| emv-3-d-secure-3ds-payment-authentication-protocol::4.2.4-5 | 4.2.4-5 App HTML UI templates and exchange (Req 4.19 to 4.31) |
| emv-3-d-secure-3ds-payment-authentication-protocol::4.3 | 4.3 Browser UI: processing screen and challenge window content (Req 4.32 to 4.43) |
Versions 2.2 and 2.3.1: features added after v2.0.0 – EMV 3-D Secure (3DS) - Payment Authentication Protocol
| Code | Title |
|---|---|
| emv-3-d-secure-3ds-payment-authentication-protocol::V.1 | V.1 Specification set, version numbers and product approval |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.10 | V.10 Out-of-band in the browser channel, repeated CReqs and iframe conduct |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.11 | V.11 Challenge cancellation reasons and challenge error reporting |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.12 | V.12 Challenge entry boxes, autofill and masking |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.13 | V.13 Device information, 3DS Method and browser data for risk assessment |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.14 | V.14 Message extensions: format, limits, criticality and supported extensions |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.15 | V.15 Bridging Message Extension for 2.2 components |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.16 | V.16 Attribute Verification Message Extension |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.17 | V.17 Split-SDK and SDK type |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.18 | V.18 Cardholder information text, results message status and final CRes values |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.19 | V.19 Operation messages (OReq and ORes) |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.2 | V.2 3DS Requestor Initiated (3RI) flow: account confirmation, recurring and instalment payments |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.20 | V.20 UTC time, HTTP request identifiers and broadcast information |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.3 | V.3 Decoupled authentication and decoupled authentication fallback |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.4 | V.4 Challenge preference, challenge mandate and exemptions |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.5 | V.5 Trust List (formerly whitelisting) |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.6 | V.6 Device binding |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.7 | V.7 3DS Requestor authentication information and delegated authentication data |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.8 | V.8 Secure Payment Confirmation (SPC): requestor-initiated and ACS-initiated |
| emv-3-d-secure-3ds-payment-authentication-protocol::V.9 | V.9 Out-of-band authentication: requirements and automatic app switching |
Your Compliance Coverage
If you comply with EMV 3-D Secure (3DS) - Payment Authentication Protocol, you already cover:
PSD2 SCA
5%
4 controls mapped
Compare →PCI 3DS Core Security Standard
5%
4 controls mapped
Compare →GDPR
4%
3 controls mapped
Compare →+ 1 more: NIST SP 800-63 Digital Identity Guidelines (4%)
See all 4 mapped frameworks ↓Maps to 4 other frameworks
Coverage is not the same as your position
This page shows what EMV 3-D Secure (3DS) - Payment Authentication Protocol overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is EMV 3-D Secure (3DS) - Payment Authentication Protocol and who does it apply to?
EMV 3-D Secure (3DS) - Payment Authentication Protocol is a compliance framework from Global (payment systems participating in EMVCo) with 6 domains and 53 controls. EMVCo's EMV 3-D Secure protocol for authenticating cardholders in card-not-present payments and non-payment identity checks: the three-domain model, the 3DS Server, Directory Server, Access Control Server and 3DS SDK, the AReq/ARes, CReq/CRes, RReq/RRes, PReq/PRes and OReq/ORes messages, app-based, browser-based and 3RI flows, frictionless, challenge and decoupled authentication, user interface, message handling, timeouts and the secure links and functions, from the complete v2.0.0 specification; and the features 2.1 to 2.3.1 added (3RI and decoupled fallback, exemptions, Trust List, device binding, Secure Payment Confirmation, out-of-band app switching, message extensions, the Split-SDK, operation messages) read against the complete v2.3.1.1 core specification. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does EMV 3-D Secure (3DS) - Payment Authentication Protocol actually require?
EMV 3-D Secure (3DS) - Payment Authentication Protocol has 53 controls organised across 6 domains. The largest domains are Versions 2.2 and 2.3.1: features added after v2.0.0 – EMV 3-D Secure (3DS) - Payment Authentication Protocol (20 controls), Authentication flow requirements (chapter 3: app-based, out-of-band, browser-based) – EMV 3-D Secure (3DS) - Payment Authentication Protocol (12 controls), Message handling requirements (chapter 5) – EMV 3-D Secure (3DS) - Payment Authentication Protocol (9 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of EMV 3-D Secure (3DS) - Payment Authentication Protocol do I already cover?
EMV 3-D Secure (3DS) - Payment Authentication Protocol maps to 4 other compliance frameworks. The top mapping partners are PSD2 SCA (5% coverage), PCI 3DS Core Security Standard (5% coverage), GDPR (4% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement EMV 3-D Secure (3DS) - Payment Authentication Protocol?
Start your EMV 3-D Secure (3DS) - Payment Authentication Protocol compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EMV 3-D Secure (3DS) - Payment Authentication Protocol requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 53 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 894 frameworks.
Get Started Free →Free forever — no credit card required