FAQ: EMV® 3DS PSD2 Requirements for Strong Customer Authentication – General Questions
EMV<sup>®</sup> 3-D Secure and PSD2 Requirements for Strong Consumer Authentication Frequently Asked Questions (FAQ) 1. What is EMV<sup>®</sup> 3-D Secure (EMV 3DS)? The importance of authenticating the individual making the payment continues to be key in the fight against card-not-present (CNP) fraud. EMV 3DS is a fraud-prevention technology that enables consumers to authenticate themselves with their card issuer, without adding unnecessary friction to the payment process that often leads to abandoned purchases. The EMV 3DS Specification provides a common set of requirements to enable product providers to use this technology in their solutions to support seamless and secure e-commerce payments. 2. How is EMV 3DS different than 3DS? 3DS refers to 3DS 1.0, which was developed by Visa in 2001 to provide an additional security layer for online card payments. EMV 3DS refers to a set of specifications created, owned and managed by EMVCo to support the global adoption of this fraud-fighting technology for seamless and secure e-commerce payments. The EMV 3DS specification details a messaging protocol that enables cardholders to authenticate themselves with their card issuer when making card-not-present (CNP) e-commerce purchases and promotes frictionless customer authentication. The additional security layer it provides helps prevent unauthorised CNP transactions and protect the merchant from exposure to CNP fraud. The three domains consist of the: merchant / acquirer domain, issuer domain, and the interoperability domain (e.g. payment systems). Today, the EMV 3DS Specification:
- Authenticates cardholders across all e-commerce channels and connected devices, promoting customer familiarity, convenience and security;
- Uses rich data to enable informed, risk-based decisioning for better fraud prevention;
- Helps reduce checkout friction for improved customer experience. © 2020 EMVCo, LLC. All rights reserved. 3. How does EMVCo support the adoption of EMV 3DS? EMVCo developed the EMV 3DS Specifications, first one of the set being released in 2016, to support the widespread adoption of 3DS technology for delivering convenient and reliable e-commerce payments globally. EMVCo continues to evolve the EMV 3DS Specification to address industry needs for security, performance and user experience. The specification provides a common set of requirements to enable product providers to use this technology in their solutions. EMVCo supports the deployment of solutions that meet the EMV 3DS Specification for compatibility and security with testing and certification programmes that evaluate and approve solutions. As a technical body, EMVCo does not mandate the use of its specifications or set the business rules related to how the technology is implemented. Industry stakeholders are free to choose from any or all of the related EMV Specifications to address their customer and marketplace needs. To learn more about the role EMVCo plays within the payments ecosystem, read its Operating Principles. 4. How does authentication work with EMV 3DS? Payer authentication is the process of verifying that the individual making a purchase with a payment card is the legitimate user of the card. For e-commerce purchases where EMV 3DS solutions are used, the process works like this:
- Consumer uses a payment card to make an online purchase on a mobile phone, tablet, laptop or other device.
- To confirm that the consumer making the purchase is the actual cardholder, the merchant uses EMV 3DS for authentication. This involves sending data to the issuer so they can approve the transaction, which includes information about the transaction, payment method and device being used.
- The issuer reviews the data, decides the type of authentication needed, performs it and then processes the transaction per the usual authorisation process. For transactions that are higher risk, EMV 3DS provides an additional layer of security by validating that the individual making the purchase is the legitimate cardholder. In these cases, the issuer can choose to prompt the consumer to authenticate themselves using a one-time-passcode, knowledge-based questions, biometrics or other method. © 2020 EMVCo, LLC. All rights reserved. 5. How does EMV 3DS support Strong Customer Authentication (SCA) requirements as described in the Second Payment Services Directive (PSD2) by the European Commission? The European Banking Authority (EBA) Opinion published on 21 June 2019, recognised that protocols such as EMV<sup>®</sup> 3DS provide a means for merchants and issuers to support the use of SCA. Specifically, EMV<sup>®</sup> 3DS supports SCA by enabling the use of two-factor authentication. Its flexibility allows issuers to accommodate their authentication preferences, and using risk and regulatory factors, issuers decide how the customer will be authenticated, for example, using a one-time-passcode, knowledge-based questions or biometrics. 6. Can EMV 3DS be used to comply with PSD2 SCA? Yes. EMV 3DS-based solutions enable issuers to leverage the appropriate authentication methods to ensure PSD2 compliance. 7. Does it matter which version of EMV 3DS is used to meet PSD2 SCA requirements? The EBA notes that versions 2.0 and newer support a variety of SCA methods, while trying to ensure customer convenience, limiting fraud through data sharing and transaction risk analysis, and enable the use of exemptions set out in the Regulatory Technical Standards (RTS). While EMV 3DS 2.1 supports SCA, to access the optimum functionality, EMVCo recommends that v2.2 (or more recent versions) should be considered. 8. What added functionality does EMV 3DS Specification version 2.2 provide in meeting PSD2 SCA requirements? Version 2.2 of the EMV 3DS Specification offers enhanced support for PSD2 requirements. This includes support for PSD2 exemptions which allow merchants to communicate to issuers that SCA may not be needed or has already been achieved for that transaction. For example, a merchant may request a low-value exemption to the issuer as part of the 3DS authentication process. According to the EBA Opinion published on the 16 October 2019 states that the ‘[EMV] 3DS v2.2. communication protocol… should enable the application of the full © 2020 EMVCo, LLC. All rights reserved. range of SCA exemptions specified in the regulatory technical standards (RTS) and the out-of-scope of SCA transactions, such as payee-initiated transactions.’ 9. In addition to meeting PSD2 SCA requirements, how does the use of EMV 3DS support secure and convenient e-commerce payments? EMV 3DS solutions help card issuers to identify fraudulent transactions more quickly and accurately, so that merchants can prevent CNP fraud with minimal disruption to the purchase process, and consumers can expect a safe and easy checkout experience. Specifically:
- Issuers - Better data and flexible authentication methods improve the decision-making process for issuers to determine the legitimacy of a transaction, resulting in increased transaction approval rates, less CNP fraud and greater consumer confidence that transaction will not be falsely declined.
- Merchants - An additional layer of security helps merchants better prevent fraud and promote convenience for their customers, resulting in improved transaction security, liability for fraudulent transactions shifted to the card issuer, fewer false declines, and a reduced risk of checkout abandonment.
- Consumers - Consumers can use their preferred device to shop online and expect quicker, easier authentication, fewer purchases inaccurately declined, and confidence in the safety of the transaction. 10. Where can I learn more about EMV 3DS? Watch our webcast to get more details on how the EMV 3DS Specification can help the European payments community and retailers meet the requirements of PSD2 SCA. Read EMVCo’s Insight post which details the role of EMV 3DS to not only help meet European regulation, but also support the global fight against CNP fraud. For more general EMV 3DS information, view the press kit. EMV<sup>®</sup> is a registered trademark in the U.S. and other countries and an unregistered trademark elsewhere. The EMV trademark is owned by EMVCo, LLC. © 2020 EMVCo, LLC. All rights reserved.