
A chargeback costs an online merchant more than the disputed transaction amount. There is a chargeback fee, the lost merchandise or service, and if disputes accumulate, elevated scrutiny from the card networks. 3D Secure is one of the few fraud tools available that does not just reduce the odds of fraud occurring; when implemented correctly, it can shift financial responsibility for a fraudulent transaction away from the merchant entirely.
Quick Answer: 3D Secure is an authentication protocol that adds a verification step, often a one-time passcode or biometric confirmation, to online card transactions before they complete. When a transaction is successfully authenticated through 3D Secure and later disputed as fraud, liability for that chargeback generally shifts from the merchant to the card-issuing bank. The current version, EMV 3DS 2.2, runs largely in the background and approves most legitimate transactions without interrupting the customer. In the United States, 3D Secure is not a legal mandate the way it is in the European Union, but card network programs increasingly reward its use and penalize merchants with high fraud rates who are not using it.
What Is 3D Secure and How Does It Actually Work?
3D Secure, often shortened to 3DS, is an authentication protocol originally developed by Visa and later adopted by Mastercard, American Express, and other card networks. It adds a layer of identity verification to an online transaction beyond the card number, expiration date, and CVV.

The current standard, EMV 3DS 2.2 and its incremental updates, exchanges over a hundred data points between the merchant, the card network, and the issuing bank during checkout, including device information, transaction history, and behavioral signals. Based on that risk assessment, the transaction is handled one of three ways: approved silently with no customer interaction, challenged with an additional verification step like a one-time passcode sent to the cardholder's phone, or declined outright if the risk signals are strong enough.
This is a meaningful improvement over the original 3D Secure protocol from the early 2000s, which required a static password and a disruptive full-page redirect on nearly every transaction, leading to high cart abandonment and poor adoption. The current version is designed to approve the large majority of legitimate transactions frictionlessly, reserving the visible challenge step for transactions that carry genuine risk signals.
How Does the 3D Secure Liability Shift Actually Work?
This is the mechanism that makes 3D Secure valuable beyond simple fraud reduction: it can change who bears the financial responsibility when fraud does occur.

Under standard card-not-present processing without 3D Secure, if a transaction turns out to be fraudulent, the merchant typically bears the loss, the disputed amount, plus a chargeback fee. When a transaction is authenticated through 3D Secure and the issuer approves that authentication, successfully completing the challenge or the frictionless risk assessment, liability for a subsequent fraud dispute on that transaction generally shifts to the card-issuing bank instead.
What this means in practice:
A stolen card is used at your online store. The transaction goes through 3D Secure and is authenticated. The transaction is later disputed as fraudulent by the actual cardholder. Under a successful liability shift, the issuing bank absorbs the loss, not the merchant.
The same stolen card is used, but 3D Secure was not applied or the authentication attempt failed. The same dispute occurs. The merchant bears the loss and the chargeback fee.
The liability shift is not automatic or unconditional. It applies specifically to fraud-related disputes where the authentication was completed and properly documented, generally through data elements like the transaction identifier and cryptogram exchanged during the 3DS process. It does not apply to disputes that are not fraud-related, such as a customer disputing a charge over a service issue, a billing disagreement, or a case of what is commonly called friendly fraud, where a legitimate cardholder disputes a transaction they actually made.
Is 3D Secure Required for U.S. Merchants?
No, not as a legal requirement. This is a point worth being precise about, because it differs meaningfully from other regions.
In the European Union, the revised Payment Services Directive, commonly referred to as PSD2, legally mandates Strong Customer Authentication for most online transactions, which in practice means 3D Secure 2 is effectively required for merchants serving EU customers. The United States has no equivalent regulatory mandate. American merchants are not legally required to implement 3D Secure, and it only activates when the issuing bank requests it during a transaction.

That said, card network programs are increasingly using incentives and penalties to encourage adoption without a formal legal mandate. Both Visa and Mastercard have introduced monitoring programs that track fraud rates and can revoke certain merchant protections, including domestic liability shift benefits, for merchants who exceed fraud thresholds without using available authentication tools like 3D Secure. In other words, nothing forces a U.S. merchant to implement 3D Secure, but a merchant with elevated fraud rates who has not adopted it is increasingly exposed compared to one who has.
For U.S.-based merchants who sell internationally, particularly to customers in the EU or UK, implementing 3D Secure is closer to a practical necessity, since those transactions may require it to complete successfully regardless of the merchant's own preference.
Does 3D Secure Hurt Checkout Conversion?
This was the primary criticism of the original 3D Secure protocol, and it remains a valid concern with the current version, though to a smaller degree.
The original protocol interrupted nearly every transaction with a full-page redirect and a static password prompt, which measurably increased cart abandonment. The current version is designed to authenticate the majority of transactions without any visible interruption to the customer, reserving the challenge screen for transactions that carry genuine risk signals based on the data exchanged during the authentication process.
Merchants who apply 3D Secure selectively, to higher-risk transactions rather than every single order, tend to see the best balance between fraud reduction and checkout conversion. Applying it universally to every transaction regardless of risk level can introduce unnecessary friction on low-risk purchases that did not need the added scrutiny.
What Does 3D Secure Not Protect Against?
3D Secure reduces liability specifically for unauthorized fraud, cases where someone other than the legitimate cardholder made the purchase. It does not protect against every category of chargeback risk.
What 3D Secure does not cover:
Friendly fraud: A legitimate cardholder makes a purchase, then disputes the charge claiming they did not authorize it or did not receive the goods, despite having actually made the purchase
Service or product disputes: A customer disputes a charge because they were dissatisfied with the product, it arrived damaged, or a service was not delivered as promised
Billing disagreements: Disputes over subscription charges, recurring billing amounts, or cancellation timing
For these categories, which represent a meaningful share of overall chargeback volume, merchants still need clear return policies, accurate product descriptions, responsive customer service, and solid documentation practices. 3D Secure is one layer of a broader fraud and dispute management strategy, not a complete solution on its own.
Want 3D Secure Configured Correctly for Your Store?
3D Secure works best when applied selectively based on real risk signals, not as a blanket setting turned on or off. Rapid Payments helps eCommerce merchants configure 3D Secure alongside their broader fraud protection setup so it reduces fraud exposure without adding unnecessary friction to legitimate customers.



