SB n° 255 EMV® 3-D Secure Specification Version Configuration

v5.0 Specification Bulletins
3-D Secure

EMV® Specification Bulletin No. 255 v5 February 2025 EMV® 3-D Secure Specification Version Configuration This Specification Bulletin No. 255 provides the status of the EMV 3-D Secure Protocol and Core Functions Specification, the EMV 3-D Secure SDK—Device Information versions, and the list of EMV 3-D Secure Message Extensions.

Applicability

This Specification Bulletin applies to:

  • EMV 3-D Secure Protocol and Core Functions Specification, Version 2.3.1.1
  • EMV 3-D Secure SDK Specification, Version 2.3.1.1
  • EMV 3-D Secure Split-SDK Specification, Version 2.3.1.0
  • EMV 3-D Secure SDK—Device Information, all versions
  • EMV 3-D Secure Specifications Frequently Asked Questions (FAQ)

Effective Date

February 2025

3-D Secure Core Specification Status Table 1 provides the testing status of the EMV 3-D Secure Protocol and Core Functions Specifications for each Protocol Version Number. Protocol Version Testing Status

  • Sunsetted—No EMVCo testing support (no need for 3DS components to support for EMVCo approval).
  • Active—EMVCo testing support required by 3DS components. Table 1: Protocol Version Testing Status Protocol Version Number 2.0.0 2.1.0 2.2.0 2.3.0 2.3.1 Testing Status Sunsetted Sunsetted Active Sunsetted Active Table 2 provides the potential Active Protocol Version Numbers for the EMV 3-D Secure Protocol and Core Functions Specifications. The DS may support all or some of the Active Protocol Version Numbers listed below. Table 2: Active Protocol Version Numbers Active Protocol Version Numbers 2.2.0 2.3.1 Note: Version 2.1.0 may still be supported by some DSs. Please check with the relevant DS regarding the supported Active Protocol Version Number. 3-D Secure SDK—Device Information Status Table 3 provides the Data Version Number status for each 3-D Secure Protocol Version. Device Information Status
  • Sunsetted—No EMVCo testing support (no need for 3DS SDK or ACS to support for EMVCo approval).
  • Active—ACS must support this Data Version Number for this Protocol Version Number.
  • No need to support—ACS does not need to support this Data Version Number for this Protocol Version Number. Table 3: Data Versions ACS Protocol Version Data Version Number Device Information Status 2.0.0 1.0 Sunsetted 2.1.0 1.1 Sunsetted 1.3 Sunsetted 1.4 Sunsetted 1.5 Sunsetted 1.6 Sunsetted 2.2.0 1.1 Active 1.3 Active 1.4 Active 1.5 Active 1.6 Active 1.7 Active 2.3.1 1.1 No need to support 1.3 Active 1.4 Active 1.5 Active 1.6 Active 1.7 Active Note: Refer to the EMV 3-D Secure Protocol and Core Functions Specification for ACS- and SDK-specific requirements regarding the Data Version support for the EMV 3-D Secure SDK—Device Information. 3-D Secure Message Extensions Table 4 provides the list of Message Extensions with Name, Assigned Extension Group Identifier, and Version Number. Table 4: Message Extensions Extension Name Device Acknowledgement Dev Ack - Split-SDK Dev Ack - Split-SDK Travel Industry Travel Industry EMV Payment Token Bridging Bridging Attribute Verification Assigned Extension Group Identifier A000000802-001 A000000802-001 A000000802-001 A000000802-002 A000000802-002 A000000802-003 A000000802-004 A000000802-004 A000000802-005-001 Extension Version Number 1.0 2.0 3.0 1.0 2.0 1.0 1.0 2.0 1.0

Legal Notice

The EMV® Specifications are provided “AS IS” without warranties of any kind, and EMVCo neither assumes nor accepts any liability for any errors or omissions contained in these Specifications. EMVCO DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NONINFRINGEMENT, AS TO THESE SPECIFICATIONS. EMVCo makes no representations or warranties with respect to intellectual property rights of any third parties in or in relation to the Specifications. EMVCo undertakes no responsibility to determine whether any implementation of the EMV® Specifications may violate, infringe, or otherwise exercise the patent, copyright, trademark, trade secret, know-how, or other intellectual property rights of third parties, and thus any person who implements any part of the EMV® Specifications should consult an intellectual property attorney before any such implementation. Without limiting the foregoing, the Specifications may provide for the use of public key encryption and other technology, which may be the subject matter of patents in several countries. Any party seeking to implement these Specifications is solely responsible for determining whether its activities require a license to any such technology, including for patents on public key encryption technology. EMVCo shall not be liable under any theory for any party’s infringement of any intellectual property rights in connection with the EMV® Specifications