Back to Frameworks

EMV 3-D Secure (3DS) - Payment Authentication Protocol

Global (payment systems participating in EMVCo)
vProtocol and Core Functions Specification v2.3.1.1 (May 2023) held complete in EMVCo's Portuguese edition and v2.0.0 (October 2016) held complete in English; approvals run against 2.3.1.1 and 2.2.0 with Bulletins 214 v3 and 255 v5
6 domains
53 controls

EMVCo's EMV 3-D Secure protocol for authenticating cardholders in card-not-present payments and non-payment identity checks: the three-domain model, the 3DS Server, Directory Server, Access Control Server and 3DS SDK, the AReq/ARes, CReq/CRes, RReq/RRes, PReq/PRes and OReq/ORes messages, app-based, browser-based and 3RI flows, frictionless, challenge and decoupled authentication, user interface, message handling, timeouts and the secure links and functions, from the complete v2.0.0 specification; and the features 2.1 to 2.3.1 added (3RI and decoupled fallback, exemptions, Trust List, device binding, Secure Payment Confirmation, out-of-band app switching, message extensions, the Split-SDK, operation messages) read against the complete v2.3.1.1 core specification.

Verified

EMV 3-D Secure (3DS) - Payment Authentication Protocol is a compliance framework from Global (payment systems participating in EMVCo) with 6 domains and 53 controls that map to 4 other frameworks. The largest domains are Versions 2.2 and 2.3.1: features added after v2.0.0 – EMV 3-D Secure (3DS) - Payment Authentication Protocol (20 controls), Authentication flow requirements (chapter 3: app-based, out-of-band, browser-based) – EMV 3-D Secure (3DS) - Payment Authentication Protocol (12 controls), Message handling requirements (chapter 5) – EMV 3-D Secure (3DS) - Payment Authentication Protocol (9 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykControl text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

Authentication flow requirements (chapter 3: app-based, out-of-band, browser-based) – EMV 3-D Secure (3DS) - Payment Authentication Protocol

12 controls
Controls in the Authentication flow requirements (chapter 3: app-based, out-of-band, browser-based) – EMV 3-D Secure (3DS) - Payment Authentication Protocol domain of EMV 3-D Secure (3DS) - Payment Authentication Protocol — 12 controls
CodeTitle
emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S10-113.1.S10-11 App: SDK completes the secure channel and sends the first CReq (Steps 10 and 11)
emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S12-143.1.S12-14 App: ACS builds the challenge and the SDK renders it (Steps 12 to 14)
emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S15-173.1.S15-17 App: cardholder response, verification, retries and abandonment (Steps 15 to 17)
emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S18-223.1.S18-22 App: results messaging RReq and RRes (Steps 18 to 22)
emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S23-253.1.S23-25 App: final CRes and completion (Steps 23 to 25)
emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S43.1.S4 App: Requestor App and SDK gather AReq data (Steps 1 to 4)
emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S53.1.S5 App: 3DS Server verifies the SDK, routes and sends the AReq (Step 5)
emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S63.1.S6 App: DS validates, checks participation and forwards the AReq (Step 6)
emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S73.1.S7 App: ACS decides the transaction status and prepares any challenge (Step 7)
emv-3-d-secure-3ds-payment-authentication-protocol::3.1.S8-93.1.S8-9 App: DS relays the ARes and the 3DS Server acts on the status (Steps 8 and 9)
emv-3-d-secure-3ds-payment-authentication-protocol::3.23.2 Out-of-band challenge flow exceptions
emv-3-d-secure-3ds-payment-authentication-protocol::3.33.3 Browser-based flow requirements

Data elements, extensions and risk information (Annex A) – EMV 3-D Secure (3DS) - Payment Authentication Protocol

2 controls
Controls in the Data elements, extensions and risk information (Annex A) – EMV 3-D Secure (3DS) - Payment Authentication Protocol domain of EMV 3-D Secure (3DS) - Payment Authentication Protocol — 2 controls
CodeTitle
emv-3-d-secure-3ds-payment-authentication-protocol::A.1-6A.1-6 Data elements: presence, edit criteria, AReq encryption, detailed values and message extensions
emv-3-d-secure-3ds-payment-authentication-protocol::A.7A.7 3DS Requestor risk information: cardholder account, merchant risk indicator and requestor authentication

Message handling requirements (chapter 5) – EMV 3-D Secure (3DS) - Payment Authentication Protocol

9 controls
Controls in the Message handling requirements (chapter 5) – EMV 3-D Secure (3DS) - Payment Authentication Protocol domain of EMV 3-D Secure (3DS) - Payment Authentication Protocol — 9 controls
CodeTitle
emv-3-d-secure-3ds-payment-authentication-protocol::5.15.1 General message handling: POST, content type, Base64, versions, parsing and validation
emv-3-d-secure-3ds-payment-authentication-protocol::5.2-45.2-4 Outages, availability and error codes
emv-3-d-secure-3ds-payment-authentication-protocol::5.5.15.5.1 Transaction timeouts (Req 5.35 to 5.43)
emv-3-d-secure-3ds-payment-authentication-protocol::5.5.25.5.2 Connection and read timeouts per message pair (Req 5.44 to 5.61)
emv-3-d-secure-3ds-payment-authentication-protocol::5.65.6 PReq/PRes card range cache
emv-3-d-secure-3ds-payment-authentication-protocol::5.75.7 App-based message handling and CReq/CRes protection
emv-3-d-secure-3ds-payment-authentication-protocol::5.8.15.8.1 3DS Method handling
emv-3-d-secure-3ds-payment-authentication-protocol::5.8.25.8.2 Browser challenge window (Req 5.81 to 5.86)
emv-3-d-secure-3ds-payment-authentication-protocol::5.95.9 Message error handling per component

Security requirements: links and functions (chapter 6) – EMV 3-D Secure (3DS) - Payment Authentication Protocol

6 controls
Controls in the Security requirements: links and functions (chapter 6) – EMV 3-D Secure (3DS) - Payment Authentication Protocol domain of EMV 3-D Secure (3DS) - Payment Authentication Protocol — 6 controls
CodeTitle
emv-3-d-secure-3ds-payment-authentication-protocol::6.1.16.1.1 Link a: consumer device to 3DS Requestor
emv-3-d-secure-3ds-payment-authentication-protocol::6.1.2-36.1.2-3 Links b and c: 3DS Server to DS and DS to ACS
emv-3-d-secure-3ds-payment-authentication-protocol::6.1.46.1.4 Link d: SDK or browser to ACS for the challenge
emv-3-d-secure-3ds-payment-authentication-protocol::6.1.86.1.8 Link h: browser to ACS for the 3DS Method
emv-3-d-secure-3ds-payment-authentication-protocol::6.2.1-26.2.1-2 Functions H and I: SDK authenticity and SDK encryption to the DS
emv-3-d-secure-3ds-payment-authentication-protocol::6.2.3-46.2.3-4 Functions J and K: SDK to ACS secure channel and protected challenge messages

User interface requirements (chapter 4) – EMV 3-D Secure (3DS) - Payment Authentication Protocol

4 controls
Controls in the User interface requirements (chapter 4) – EMV 3-D Secure (3DS) - Payment Authentication Protocol domain of EMV 3-D Secure (3DS) - Payment Authentication Protocol — 4 controls
CodeTitle
emv-3-d-secure-3ds-payment-authentication-protocol::4.2.14.2.1 App processing screen (Req 4.1 to 4.12)
emv-3-d-secure-3ds-payment-authentication-protocol::4.2.2-34.2.2-3 App native UI templates and message exchange (Req 4.13 to 4.18)
emv-3-d-secure-3ds-payment-authentication-protocol::4.2.4-54.2.4-5 App HTML UI templates and exchange (Req 4.19 to 4.31)
emv-3-d-secure-3ds-payment-authentication-protocol::4.34.3 Browser UI: processing screen and challenge window content (Req 4.32 to 4.43)

Versions 2.2 and 2.3.1: features added after v2.0.0 – EMV 3-D Secure (3DS) - Payment Authentication Protocol

20 controls
Controls in the Versions 2.2 and 2.3.1: features added after v2.0.0 – EMV 3-D Secure (3DS) - Payment Authentication Protocol domain of EMV 3-D Secure (3DS) - Payment Authentication Protocol — 20 controls
CodeTitle
emv-3-d-secure-3ds-payment-authentication-protocol::V.1V.1 Specification set, version numbers and product approval
emv-3-d-secure-3ds-payment-authentication-protocol::V.10V.10 Out-of-band in the browser channel, repeated CReqs and iframe conduct
emv-3-d-secure-3ds-payment-authentication-protocol::V.11V.11 Challenge cancellation reasons and challenge error reporting
emv-3-d-secure-3ds-payment-authentication-protocol::V.12V.12 Challenge entry boxes, autofill and masking
emv-3-d-secure-3ds-payment-authentication-protocol::V.13V.13 Device information, 3DS Method and browser data for risk assessment
emv-3-d-secure-3ds-payment-authentication-protocol::V.14V.14 Message extensions: format, limits, criticality and supported extensions
emv-3-d-secure-3ds-payment-authentication-protocol::V.15V.15 Bridging Message Extension for 2.2 components
emv-3-d-secure-3ds-payment-authentication-protocol::V.16V.16 Attribute Verification Message Extension
emv-3-d-secure-3ds-payment-authentication-protocol::V.17V.17 Split-SDK and SDK type
emv-3-d-secure-3ds-payment-authentication-protocol::V.18V.18 Cardholder information text, results message status and final CRes values
emv-3-d-secure-3ds-payment-authentication-protocol::V.19V.19 Operation messages (OReq and ORes)
emv-3-d-secure-3ds-payment-authentication-protocol::V.2V.2 3DS Requestor Initiated (3RI) flow: account confirmation, recurring and instalment payments
emv-3-d-secure-3ds-payment-authentication-protocol::V.20V.20 UTC time, HTTP request identifiers and broadcast information
emv-3-d-secure-3ds-payment-authentication-protocol::V.3V.3 Decoupled authentication and decoupled authentication fallback
emv-3-d-secure-3ds-payment-authentication-protocol::V.4V.4 Challenge preference, challenge mandate and exemptions
emv-3-d-secure-3ds-payment-authentication-protocol::V.5V.5 Trust List (formerly whitelisting)
emv-3-d-secure-3ds-payment-authentication-protocol::V.6V.6 Device binding
emv-3-d-secure-3ds-payment-authentication-protocol::V.7V.7 3DS Requestor authentication information and delegated authentication data
emv-3-d-secure-3ds-payment-authentication-protocol::V.8V.8 Secure Payment Confirmation (SPC): requestor-initiated and ACS-initiated
emv-3-d-secure-3ds-payment-authentication-protocol::V.9V.9 Out-of-band authentication: requirements and automatic app switching

Your Compliance Coverage

If you comply with EMV 3-D Secure (3DS) - Payment Authentication Protocol, you already cover:

Maps to 4 other frameworks

75 total controls
PSD2 SCA
4 source controls mapped|4 target controls covered
5%
PCI 3DS Core Security Standard
4 source controls mapped|6 target controls covered
5%
GDPR
3 source controls mapped|2 target controls covered
4%
NIST SP 800-63 Digital Identity Guidelines
3 source controls mapped|1 target controls covered
4%

Coverage is not the same as your position

This page shows what EMV 3-D Secure (3DS) - Payment Authentication Protocol overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is EMV 3-D Secure (3DS) - Payment Authentication Protocol and who does it apply to?

EMV 3-D Secure (3DS) - Payment Authentication Protocol is a compliance framework from Global (payment systems participating in EMVCo) with 6 domains and 53 controls. EMVCo's EMV 3-D Secure protocol for authenticating cardholders in card-not-present payments and non-payment identity checks: the three-domain model, the 3DS Server, Directory Server, Access Control Server and 3DS SDK, the AReq/ARes, CReq/CRes, RReq/RRes, PReq/PRes and OReq/ORes messages, app-based, browser-based and 3RI flows, frictionless, challenge and decoupled authentication, user interface, message handling, timeouts and the secure links and functions, from the complete v2.0.0 specification; and the features 2.1 to 2.3.1 added (3RI and decoupled fallback, exemptions, Trust List, device binding, Secure Payment Confirmation, out-of-band app switching, message extensions, the Split-SDK, operation messages) read against the complete v2.3.1.1 core specification. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does EMV 3-D Secure (3DS) - Payment Authentication Protocol actually require?

EMV 3-D Secure (3DS) - Payment Authentication Protocol has 53 controls organised across 6 domains. The largest domains are Versions 2.2 and 2.3.1: features added after v2.0.0 – EMV 3-D Secure (3DS) - Payment Authentication Protocol (20 controls), Authentication flow requirements (chapter 3: app-based, out-of-band, browser-based) – EMV 3-D Secure (3DS) - Payment Authentication Protocol (12 controls), Message handling requirements (chapter 5) – EMV 3-D Secure (3DS) - Payment Authentication Protocol (9 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of EMV 3-D Secure (3DS) - Payment Authentication Protocol do I already cover?

EMV 3-D Secure (3DS) - Payment Authentication Protocol maps to 4 other compliance frameworks. The top mapping partners are PSD2 SCA (5% coverage), PCI 3DS Core Security Standard (5% coverage), GDPR (4% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement EMV 3-D Secure (3DS) - Payment Authentication Protocol?

Start your EMV 3-D Secure (3DS) - Payment Authentication Protocol compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about EMV 3-D Secure (3DS) - Payment Authentication Protocol requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 53 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 894 frameworks.

Get Started Free →

Free forever — no credit card required