We’re rated Excellent on:

trust pilot

3D Secure and Strong Customer Authentication: What UK Merchants Need to Know

Updated July 2026

Exclusive Rates From as Low as 0.26%

Strong Customer Authentication (SCA) is a legal requirement under UK payment regulations, and 3D Secure 2 (3DS2) is the technology most UK merchants use to satisfy it when accepting online card payments. Understanding how SCA and 3DS2 work is not optional for anyone selling online in the UK - getting it wrong means declined transactions, lost sales, and exposure to fraud chargeback liability that would otherwise sit with the card issuer. This guide explains the rules, the exemptions, and the practical steps UK merchants should take to implement 3DS2 correctly without sacrificing conversion rates.

Key Takeaways

  • Strong Customer Authentication has been enforced in the UK since March 2022, following a phased rollout by the FCA.
  • 3D Secure 2 (3DS2) is the dominant technical mechanism UK merchants use to meet SCA requirements for card-not-present transactions.
  • Successful SCA authentication shifts fraud liability from the merchant to the card issuer, protecting you from many chargeback losses.
  • Several legitimate exemptions exist - including low-value transactions, recurring payments, and Transaction Risk Analysis (TRA) - that can reduce friction without losing liability protection.
  • Poorly implemented 3DS2 flows can cause checkout abandonment of 15-30%, so choosing the right provider and configuration matters commercially, not just legally.
  • UK merchants should review their payment provider's 3DS2 version and exemption-handling capability at least annually, as issuer rules and scheme mandates continue to evolve.

What Is Strong Customer Authentication?

Strong Customer Authentication is a requirement under the UK's Payment Services Regulations (derived originally from the EU's revised Payment Services Directive, PSD2, and retained in UK law post-Brexit with FCA oversight). It requires that most electronic payments be authenticated using at least two of three independent elements: something the customer knows (a password or PIN), something the customer has (a phone or hardware token), and something the customer is (biometric data such as a fingerprint or face scan).

For UK online card payments, this typically means a one-time passcode sent to the cardholder's mobile phone, a biometric confirmation through a banking app, or a similar two-factor check at checkout. The UK's Financial Conduct Authority (FCA) enforced SCA for e-commerce transactions from 14 March 2022, following an 18-month extension granted to allow merchants and card issuers time to prepare their systems.

Why SCA Exists

SCA was introduced to combat rising online card fraud, which had grown significantly as e-commerce expanded. By requiring multi-factor authentication, regulators aimed to make it far harder for criminals to use stolen card details, since a static card number and CVV alone are no longer sufficient to complete most transactions.

How 3D Secure 2 Works in Practice

3D Secure 2 is the technical protocol that implements SCA for card payments. It replaced the older 3D Secure 1 (often recognised by pop-up windows and static passwords), which suffered from poor mobile compatibility and high abandonment rates. 3DS2 was designed specifically to reduce friction while still meeting regulatory authentication requirements.

When a customer pays online, the merchant's payment gateway sends additional data - device information, transaction history, billing address, and more - to the card issuer in real time. The issuer's system evaluates this data and decides whether to:

  • Approve the transaction with no further authentication (a "frictionless flow"), if risk is assessed as low.
  • Request additional authentication (a "challenge flow"), typically an OTP or biometric confirmation via a banking app.

This risk-based approach means many low-risk transactions pass through with zero customer friction, while higher-risk transactions receive an additional verification step. This is a significant improvement over 3DS1, which challenged nearly every transaction regardless of risk.

The Three Domains of 3D Secure

The "3D" in 3D Secure refers to three domains involved in the process: the acquirer domain (merchant and payment provider), the issuer domain (the cardholder's bank), and the interoperability domain (the card scheme, such as Visa or Mastercard, which routes messages between the two). Each domain plays a distinct role, and a failure in any one - for example, a merchant's gateway not supporting 3DS2 correctly - can cause otherwise valid transactions to be declined or unnecessarily challenged.

Liability Shift: The Financial Case for Getting SCA Right

Beyond the legal obligation, correctly implemented 3DS2 delivers a direct commercial benefit: liability shift. When a transaction is successfully authenticated through 3DS2 and later turns out to be fraudulent, liability for the resulting chargeback generally transfers from the merchant to the card issuer. Without successful authentication, the merchant typically bears the loss.

This makes 3DS2 implementation not just a compliance checkbox but a core part of your fraud and chargeback strategy. For a detailed breakdown of how chargebacks work and how liability is assigned more broadly, see our guide on what a chargeback is and how the UK process works.

What Happens When Authentication Fails or Is Skipped

If a merchant fails to apply SCA when required - for instance, by not integrating 3DS2 correctly, or by wrongly applying an exemption - the issuing bank may decline the transaction outright, or the merchant may lose liability protection even if the payment goes through. Repeated failures can also draw scrutiny from acquirers and, in serious cases, affect a merchant's ability to process card payments at all.

SCA Exemptions UK Merchants Can Use

Not every transaction requires a full authentication challenge. UK regulations and card scheme rules allow for specific exemptions, which - when properly applied - can reduce checkout friction while often retaining some liability protection. Exemption requests are typically flagged by the merchant's payment gateway and approved or rejected by the issuer in real time.

Exemption Type Description Typical Threshold / Condition
Low-value payment Small transactions carry lower fraud risk and may be exempted Under £30 per transaction (subject to cumulative limits)
Transaction Risk Analysis (TRA) Acquirer or issuer fraud rates are low enough to qualify for exemption up to higher value limits Up to £100-£250 depending on acquirer/issuer fraud rate thresholds
Recurring transactions Subscription or instalment payments after the first authenticated payment Fixed amount, same merchant, subsequent payments
Merchant-initiated transactions (MIT) Payments not directly initiated by the cardholder at that moment, e.g. renewals No cardholder present at time of transaction
Trusted beneficiary / whitelisting Cardholder marks a merchant as trusted via their bank's app Requires prior cardholder opt-in with issuing bank
Secure corporate payments Payments made using dedicated commercial card processes with their own security protocols B2B corporate card use cases

Important Caveats on Exemptions

Exemptions are requested by the merchant or acquirer but the final decision rests with the issuing bank, which can override the request and still trigger a challenge if it judges the transaction to be higher risk. Merchants should also be aware that some exemptions, particularly low-value and TRA exemptions, may reduce liability protection compared to a fully authenticated transaction, so the trade-off between conversion and fraud risk should be assessed for your specific business model.

The Impact on Conversion Rates and Checkout Design

One of the biggest concerns UK merchants raise about 3DS2 is its effect on conversion. Industry data has consistently shown that poorly implemented authentication flows - slow redirects, confusing OTP requests, or challenges applied to every transaction regardless of risk - can cause cart abandonment rates of 15-30% at the payment step alone. This is a substantial commercial cost that goes well beyond the compliance question.

The solution lies largely in your choice of payment gateway and how it is configured, rather than in avoiding SCA itself. Modern 3DS2-compliant gateways from providers such as Stripe, Worldpay, Checkout.com, and Adyen support risk-based frictionless flows, meaning the vast majority of low-risk transactions should pass without a challenge at all if the integration is done correctly.

Common Implementation Mistakes

  • Using an outdated 3DS1 integration that still triggers unnecessary pop-up challenges on every transaction.
  • Failing to pass rich transaction data (billing history, device fingerprinting, delivery address) to the issuer, which increases the likelihood of a challenge being triggered.
  • Not testing the mobile checkout experience separately, where OTP and app-based challenges are more likely to cause abandonment if poorly designed.
  • Applying no exemption logic at all, meaning every transaction - even low-value, low-risk ones - goes through a full challenge unnecessarily.

3DS1 vs 3DS2: What Changed and Why It Matters

Many UK merchants who set up online payments some years ago may still be running on older 3DS1 infrastructure via their payment provider, particularly if they have not reviewed their integration recently. Understanding the difference is important both for compliance and for conversion performance.

Feature 3D Secure 1 3D Secure 2
Authentication method Static password or security question, browser pop-up OTP, biometrics, banking app push notifications
Mobile experience Poor - pop-ups often break on mobile browsers Native mobile SDK support, app-based flows
Risk-based authentication Limited or none - most transactions challenged Data-rich risk scoring allows frictionless approval
SCA regulatory compliance Does not fully satisfy UK SCA requirements Designed specifically to meet SCA requirements
Data shared with issuer Minimal Extensive (device, transaction, behavioural data)

If your business is still relying on 3DS1 in any part of your payment flow, this should be treated as an urgent priority. Not only does it fail to reliably meet SCA requirements, it also delivers a materially worse checkout experience than 3DS2, directly costing you sales.

How to Check Your Current 3DS2 Implementation

Most UK merchants do not build their own 3DS2 integration from scratch - this is typically handled by your payment gateway or provider. However, you remain responsible for ensuring the implementation is correct and appropriate for your business. Here is a practical checklist:

1. Confirm Your Provider Supports 3DS2 (Not Just 3DS1)

Ask your payment provider directly which version of 3D Secure is active on your account and whether it supports the EMV 3DS2.1 or later specification, which includes mobile SDK support and richer data exchange.

2. Review Your Exemption Configuration

Check whether your gateway is configured to request appropriate exemptions (low-value, TRA, recurring) where suitable for your transaction profile. Many providers apply conservative default settings that challenge more transactions than necessary.

3. Monitor Your Challenge Rate and Abandonment Data

Your payment dashboard or gateway reporting should show what percentage of transactions are frictionless versus challenged. A very high challenge rate (well above 10-15% for typical retail transactions) may indicate an overly conservative or poorly tuned configuration.

4. Test the Mobile Checkout Journey

Walk through your own checkout on a mobile device and confirm the authentication step is smooth, loads quickly, and does not require the customer to leave your app or site unnecessarily.

5. Review Fraud and Chargeback Data Regularly

Cross-reference your chargeback data against your authentication logs to confirm you are receiving liability shift protection on authenticated transactions. If you are still absorbing fraud losses on transactions that were successfully authenticated, raise this with your acquirer immediately, as it may indicate a configuration or reporting error.

For a broader view of fraud prevention tactics beyond authentication, see our guide to card fraud prevention for UK businesses, and for practical steps on reducing overall dispute volume, read our article on reducing chargebacks as a UK merchant.

Sector-Specific Considerations

Subscription and Recurring Billing Businesses

Subscription businesses benefit significantly from the recurring transaction exemption, but only the first payment in a series typically requires full SCA. Merchants should ensure their billing system correctly flags subsequent payments as merchant-initiated transactions to avoid unnecessary declines.

Marketplaces and Platforms

Marketplaces facilitating payments between multiple parties need to consider where SCA responsibility sits - often with the platform's acquiring relationship rather than individual sellers - and should confirm this clearly with their payment provider.

High-Value and B2B Transactions

Corporate and B2B payments often qualify for secure corporate payment exemptions, but this depends on the specific card products and processes used, and should be confirmed directly with your acquirer rather than assumed.

What's Next: Ongoing Changes to SCA and 3DS Rules

Card schemes and regulators continue to refine SCA and 3DS requirements. Mandates around EMV 3DS version upgrades, changes to exemption thresholds, and evolving issuer risk models mean that a compliant setup today may need adjustment in future. UK merchants should treat 3DS2 configuration as an ongoing operational responsibility, reviewed at least annually alongside broader payment provider performance, rather than a one-off technical project completed in 2022.

Frequently Asked Questions

Is 3D Secure the same thing as Strong Customer Authentication?

No - Strong Customer Authentication is the legal requirement set out in UK payment regulations, while 3D Secure 2 is the technical protocol most commonly used to meet that requirement for online card payments. You can technically satisfy SCA through other authentication methods, but 3DS2 is by far the dominant mechanism used across UK e-commerce.

Do all online card transactions require Strong Customer Authentication?

Most do, but there are specific exemptions - including low-value payments under roughly £30, recurring subscription payments after the first authenticated charge, and transactions that qualify for Transaction Risk Analysis based on low fraud rates. The final decision on whether to apply an exemption rests with the card issuer, who can still request full authentication if they judge the transaction to be higher risk.

What happens if my business does not implement 3DS2 correctly?

Incorrect or missing 3DS2 implementation can lead to increased transaction declines, loss of liability shift protection on fraudulent transactions, and in some cases scrutiny from your acquirer regarding your ability to process card payments reliably. It can also materially harm conversion rates if customers face confusing or broken authentication challenges at checkout.

Does 3D Secure 2 guarantee I will never suffer a fraud chargeback?

No - successful authentication shifts liability for many fraud-related chargebacks to the card issuer, but it does not eliminate all chargeback risk, particularly disputes relating to goods not received, quality issues, or subscription cancellation complaints. 3DS2 specifically addresses fraud liability, not the full range of chargeback reason codes.

Can I reduce checkout friction while still complying with SCA?

Yes - a well-configured 3DS2 integration using risk-based authentication and appropriate exemption requests should allow the majority of low-risk transactions to be approved frictionlessly, without any customer-facing challenge. The key is ensuring your payment gateway is passing rich transaction data to issuers and is configured to request exemptions where appropriate for your business.

Which UK payment providers offer strong 3DS2 support?

Most established UK payment gateways, including Stripe, Worldpay, Checkout.com, Adyen, and Barclaycard, offer robust 3DS2 support with configurable exemption handling. The quality of implementation can vary significantly depending on how your integration is set up, so it is worth reviewing your specific configuration rather than assuming compliance based on provider name alone.

How often should I review my 3DS2 setup?

At minimum annually, though more frequent reviews are sensible if you notice rising decline rates, increased chargeback volumes, or if your payment provider announces changes to their authentication or exemption handling. Card scheme rules and issuer risk models continue to evolve, so a setup that performed well previously may need adjustment over time.

How Compare Card Fees Can Help

Compare Card Fees is a free, independent advisory service. We compare rates from leading UK payment providers to find you the best deal available - no fee, no obligation.

Whether you are looking to reduce your card processing costs, switch provider, or understand what you are currently paying, our experts can help. Tell us about your business and we will find the best rates available.