What 3D Secure 2.0 does
3D Secure 2.0 (3DS2) adds an authentication step between the customer and their issuing bank — confirmed by app approval, biometric or one-time code. When authentication succeeds, two things happen: stolen-card fraud is blocked at the gate, and chargeback liability for fraud disputes shifts from you to the issuer.
Why 3DS2, not legacy 3DS1
Old 3DS1 forced a clunky redirect on every transaction and tanked conversion. 3DS2 is built around risk-based, frictionless authentication: it passes rich data to the issuer, who silently approves low-risk transactions and only challenges the risky ones. Most good customers never see a prompt.
The liability shift
On an authenticated 3DS2 transaction, a later "unauthorized" fraud chargeback is generally the issuer’s liability, not yours — directly protecting your ratio.
Deploying it without hurting conversion
- Use dynamic/risk-based 3DS2 — challenge only higher-risk transactions, not everyone.
- Send rich data (device, history, billing) so issuers can approve frictionlessly.
- Exempt low-value and trusted-customer transactions where the rules allow.
- Monitor challenge and abandonment rates and tune the thresholds.
- Combine with AVS/CVV and velocity rules for layered defense.
Don’t challenge everyone
Forcing a challenge on every transaction is the classic mistake — it recreates the 3DS1 conversion hit. Risk-based is the entire point of 3DS2.
How MIDs helps
MIDs supports 3DS2 with dynamic authentication across its acquirer network, passes the data issuers need for frictionless approval, and lets you tune exactly when a challenge fires — so you capture the liability shift without sacrificing conversion.
Key takeaways
- 3DS2 authenticates the cardholder and shifts fraud-chargeback liability to the issuer.
- Risk-based authentication keeps most good customers friction-free, unlike legacy 3DS1.
- Send rich data and exempt low-risk transactions to maximize frictionless approvals.
- Layer 3DS2 with AVS/CVV and velocity rules for the strongest defense.