Key facts
- Topic
- 3D Secure and Strong Customer Authentication developments
- Generated
- 2026-08-28
- Evidence window
- last month
- Sources analysed
- 3 (0 regulator/official, 0 company primary)
Executive Summary
- Strong Customer Authentication (SCA) under PSD2 has fundamentally reshaped how merchants implement 3D Secure, forcing decisions on which protocol version to deploy and how to manage transactions that risk failure due to non-compliance S1.
- Future authentication flexibility is being designed into EU regulation: eIDAS 2.0 incorporates user authentication mechanisms intended to satisfy PSD2's SCA requirement, potentially allowing payers to choose their authentication method S1.
- 3D Secure is positioned commercially as a fraud-liability tool: verified transactions shift dispute liability from merchant to issuing bank, which is relevant amid rising friendly fraud S3.
- Vendors in the 3D Secure authentication market (e.g., JCB, Worldpay) continue to invest in risk-based authentication, tokenization, and AI-driven fraud prevention as differentiators S2.
What Happened
Strong Customer Authentication, introduced under PSD2, requires payment service providers to authenticate payers on push payments unless a specific exemption applies S1. This requirement has driven merchant-side implementation choices around 3D Secure protocol versions and created risk of transaction failure where SCA is not properly executed S1. Separately, eIDAS 2.0 is being developed to include user authentication mechanisms that satisfy the SCA requirement under PSD2, with the stated aim of eventually letting payers select their preferred authentication method (the source references "face" authentication as an example, though the text is truncated) S1.
On the commercial/vendor side, market analysis describes 3D Secure (used interchangeably with "Strong Customer Authentication" in some regions) as a checkout-time identity verification step that shifts chargeback liability to the bank when a verified transaction is disputed S3. This is framed in the context of rising friendly fraud, which is estimated to represent a growing share of chargebacks and merchant losses S3. Vendors named as active in the 3D Secure authentication market include JCB, which expanded secure payment services in 2025, and Worldpay, which is cited as expanding in June 2025 with risk-based authentication and tokenization capabilities S2.
Why It Matters
SCA/3DS compliance directly affects transaction approval rates, fraud liability allocation, and merchant checkout friction — three variables central to payments P&L across the value chain S1S3. As friendly fraud grows as a share of chargebacks, the liability-shift mechanism inherent in 3D Secure becomes a more prominent commercial lever for merchants to control losses, not just a compliance obligation S3.
Strategic Implications
Merchants
- Must continue to manage 3DS protocol version choices and SCA exemption logic to avoid failed transactions S1.
- Can use verified 3DS authentication as a defense mechanism against friendly-fraud disputes by shifting liability to the issuing bank S3.
Banks/Issuers
- Carry SCA execution responsibility on push payments absent an applicable exemption S1.
- Assume liability for disputes on transactions that were successfully authenticated via 3DS S3.
PSPs
- Responsible for performing or orchestrating SCA on transactions unless an exemption applies S1.
Fintechs
- eIDAS 2.0-enabled authentication mechanisms may open space for new authentication method providers if payers gain choice over how SCA is performed S1.
*Insufficient evidence in the retrieved sources for Acquirers and Card Networks as distinct strategic actors.*
Competitive Impact
Vendors offering risk-based authentication, tokenization, and AI-driven fraud prevention within the 3D Secure ecosystem — named examples include JCB and Worldpay — are positioned to benefit from continued market investment in secure payment acceptance S2. ANALYSIS: This suggests incumbents with existing issuer/merchant network relationships and established 3DS infrastructure are better placed to capture demand than new entrants, though the evidence does not name any disadvantaged players directly.
Technology Impact
- 3D Secure (protocol versioning relevant to merchant implementation choices) S1.
- Strong Customer Authentication as a regulatory/technical requirement under PSD2 S1.
- eIDAS 2.0 authentication mechanisms, intended to be interoperable with PSD2 SCA requirements S1.
- Risk-based authentication, tokenization, and AI/cybersecurity investment referenced as vendor capabilities in the 3DS market S2.
Regulatory Impact
PSD2's SCA requirement remains the primary regulatory driver discussed, mandating authentication on payments absent an exemption S1. eIDAS 2.0 is described as being built to incorporate SCA-compliant user authentication, indicating regulatory convergence between digital identity and payments authentication frameworks S1. No evidence in the retrieved sources addresses PSD3 or PSR specifically.
Opportunities
- Vendors offering integrated risk-based authentication and tokenization within 3DS flows have a market opportunity as demand for secure payment acceptance continues S2.
- Merchants can use 3DS liability-shift mechanics as a structured tool against rising friendly-fraud chargeback rates S3.
- ANALYSIS: If eIDAS 2.0 enables payer choice of authentication method, this likely creates an opportunity for new authentication-method providers to integrate into the PSD2 SCA compliance chain S1.
Risks
- Transactions may fail where SCA is not correctly implemented, directly impacting conversion S1.
- Friendly fraud is described as a growing share of chargebacks and merchant losses, indicating an escalating cost risk even where 3DS liability shift applies S3.
- ANALYSIS: Divergence in 3DS protocol version adoption across merchants could create inconsistent authentication experiences and compliance risk exposure, though this is inferred rather than stated directly.
Outlook — What to Monitor Next
- Whether eIDAS 2.0 implementation formally enables payer-selected SCA authentication methods, as suggested but not confirmed in S1.
- Further vendor product announcements from JCB and Worldpay on 3DS-related capabilities beyond those already cited S2.
- Updated friendly fraud and chargeback statistics from Juniper Research or the Merchant Risk Council beyond the figures already cited S3.
- Any regulatory guidance clarifying SCA exemption criteria referenced in S1.
Confidence Assessment
Source count: 3. None are primary regulatory or standards-body sources (e.g., no EBA, European Commission, EMVCo, or PCI SSC documents); all are tier-4 secondary commentary (a podcast summary, a market research blog, and a fraud-tools blog). Overall confidence: Low. The evidence provides directional insight into SCA/3DS dynamics but lacks primary-source verification, quantitative rigor, and depth needed for high-confidence strategic conclusions.
Sources
S1 Episode 299 - The Evolving Payments Regulatory ... — glenbrook.com — https://glenbrook.com/payments_on_fire/episode-299-the-evolving-payments-regulatory-environment-in-the-european-union-with-scott-mcinnes-bird-bird
S2 Top 15 Companies in Global 3D Secure Pay Authentication Market — sphericalinsights.com — https://www.sphericalinsights.com/blogs/top-15-companies-in-global-3d-secure-pay-authentication-market-2026-2035-spherical-insights-analysis
S3 Tools That Prevent Friendly Fraud Chargebacks — chargeflow.io — https://www.chargeflow.io/blog/what-tools-prevent-friendly-fraud-chargebacks
*Generated automatically. All factual claims carry [S#] markers referring to the numbered sources above. Analytical judgements are the model's interpretation and are not sourced.*