3D Secure: what it is, why your customers see it, and how to stop it becoming a sales obstacle
It's the only checkout step you don't control directly, but how smooth it feels still depends on the provider you choose.
Your customer has entered their card details, is about to complete the purchase, and suddenly a verification request pops up: an SMS code, a notification on the banking app, a popup they weren't expecting. This is 3D Secure, and it's a legal requirement for most European payments. The question isn't whether to use it, but how to do it without scaring off the person about to buy from you.
What 3D Secure is and why it exists
It's an extra layer of cardholder identity verification, required by the European PSD2 directive in the form of Strong Customer Authentication (SCA).
The goal is to reduce fraud with stolen or cloned cards: even if someone has the card details, without the extra verification (usually checked by the customer's bank, not by you) the transaction is blocked.
3D Secure 2: what changes from the previous version
The newer version (3DS2) exchanges much more contextual data with the customer's bank (device used, browsing behaviour, purchase history) to decide whether to request extra verification or approve the transaction directly with no friction.
The practical result: in most low-risk transactions, the customer sees no extra step at all. Verification only appears when the system detects a higher-risk element.
How to stop it becoming a sales obstacle
Choose a payment gateway that handles 3DS2 natively and keeps it up to date: older versions of the protocol (3DS1) cause far more abandonment due to a clunkier user experience.
Tell the customer, with a brief message in checkout, that they might receive a verification request from their bank: this removes some of the anxiety around an unexpected step.
Monitor the specific abandonment rate at the authentication stage: if it's high, the problem is almost always technical (an outdated gateway), not the customer.
- 3D Secure is a legal requirement for most European payments, it's not optional.
- 3DS2 drastically reduces extra verification requests compared to the previous version, thanks to more contextual data.
- A gateway updated to 3DS2 reduces checkout abandonment compared to older implementations.
- Telling the customer what to expect reduces the anxiety tied to the verification step.
- Using a gateway still based on the older version of the 3D Secure protocol.
- Not monitoring the specific abandonment rate at the authentication stage.
- Never explaining to the customer what might happen during payment.
Frequently asked questions
No, it's a regulatory requirement for most European card payments. Some exceptions exist for very low-value transactions, but it's not a merchant's discretionary choice.
The decision is made in real time by the card-issuing bank, based on the perceived risk level of the transaction, not by the merchant or the gateway.
Yes, in many cases it shifts fraud liability from the merchant to the issuing bank, if the transaction was correctly authenticated with 3D Secure.
A secure checkout, without slowing down sales
Daevon's gateway natively handles 3D Secure 2, reducing unnecessary verification requests for your customers.