Skip to content
← Back to Intelligence
Regulation28 Aug 20263 src

3D Secure and Strong Customer Authentication Evolving Under PSD2 and eIDAS 2.0 Frameworks

PSD2's Strong Customer Authentication (SCA) requirements have driven widespread adoption of 3D Secure solutions across payment service providers, merchants, and financial institutions. SCA is now a foundational requirement for electronic payments in regulated markets, with exemptions available under specific conditions. eIDAS 2.0 incorporates SCA requirements, and market players including JCB and Worldpay are expanding authentication technologies and risk-based solutions. The market is growing with increasing focus on fraud prevention and liability shift mechanisms.

JCBWorldpay

Key facts

Topic
3D Secure and Strong Customer Authentication developments
Generated
2026-08-28
Evidence window
last month
Sources analysed
3 (0 regulator/official, 0 company primary)

Executive Summary

  • Strong Customer Authentication (SCA) under PSD2 has fundamentally reshaped how merchants implement 3D Secure, forcing decisions on which protocol version to deploy and how to manage transactions that risk failure due to non-compliance S1.
  • Future authentication flexibility is being designed into EU regulation: eIDAS 2.0 incorporates user authentication mechanisms intended to satisfy PSD2's SCA requirement, potentially allowing payers to choose their authentication method S1.
  • 3D Secure is positioned commercially as a fraud-liability tool: verified transactions shift dispute liability from merchant to issuing bank, which is relevant amid rising friendly fraud S3.
  • Vendors in the 3D Secure authentication market (e.g., JCB, Worldpay) continue to invest in risk-based authentication, tokenization, and AI-driven fraud prevention as differentiators S2.

What Happened

Strong Customer Authentication, introduced under PSD2, requires payment service providers to authenticate payers on push payments unless a specific exemption applies S1. This requirement has driven merchant-side implementation choices around 3D Secure protocol versions and created risk of transaction failure where SCA is not properly executed S1. Separately, eIDAS 2.0 is being developed to include user authentication mechanisms that satisfy the SCA requirement under PSD2, with the stated aim of eventually letting payers select their preferred authentication method (the source references "face" authentication as an example, though the text is truncated) S1.

On the commercial/vendor side, market analysis describes 3D Secure (used interchangeably with "Strong Customer Authentication" in some regions) as a checkout-time identity verification step that shifts chargeback liability to the bank when a verified transaction is disputed S3. This is framed in the context of rising friendly fraud, which is estimated to represent a growing share of chargebacks and merchant losses S3. Vendors named as active in the 3D Secure authentication market include JCB, which expanded secure payment services in 2025, and Worldpay, which is cited as expanding in June 2025 with risk-based authentication and tokenization capabilities S2.

Why It Matters

SCA/3DS compliance directly affects transaction approval rates, fraud liability allocation, and merchant checkout friction — three variables central to payments P&L across the value chain S1S3. As friendly fraud grows as a share of chargebacks, the liability-shift mechanism inherent in 3D Secure becomes a more prominent commercial lever for merchants to control losses, not just a compliance obligation S3.

Strategic Implications

Merchants

  • Must continue to manage 3DS protocol version choices and SCA exemption logic to avoid failed transactions S1.
  • Can use verified 3DS authentication as a defense mechanism against friendly-fraud disputes by shifting liability to the issuing bank S3.

Banks/Issuers

  • Carry SCA execution responsibility on push payments absent an applicable exemption S1.
  • Assume liability for disputes on transactions that were successfully authenticated via 3DS S3.

PSPs

  • Responsible for performing or orchestrating SCA on transactions unless an exemption applies S1.

Fintechs

  • eIDAS 2.0-enabled authentication mechanisms may open space for new authentication method providers if payers gain choice over how SCA is performed S1.

*Insufficient evidence in the retrieved sources for Acquirers and Card Networks as distinct strategic actors.*

Competitive Impact

Vendors offering risk-based authentication, tokenization, and AI-driven fraud prevention within the 3D Secure ecosystem — named examples include JCB and Worldpay — are positioned to benefit from continued market investment in secure payment acceptance S2. ANALYSIS: This suggests incumbents with existing issuer/merchant network relationships and established 3DS infrastructure are better placed to capture demand than new entrants, though the evidence does not name any disadvantaged players directly.

Technology Impact

  • 3D Secure (protocol versioning relevant to merchant implementation choices) S1.
  • Strong Customer Authentication as a regulatory/technical requirement under PSD2 S1.
  • eIDAS 2.0 authentication mechanisms, intended to be interoperable with PSD2 SCA requirements S1.
  • Risk-based authentication, tokenization, and AI/cybersecurity investment referenced as vendor capabilities in the 3DS market S2.

Regulatory Impact

PSD2's SCA requirement remains the primary regulatory driver discussed, mandating authentication on payments absent an exemption S1. eIDAS 2.0 is described as being built to incorporate SCA-compliant user authentication, indicating regulatory convergence between digital identity and payments authentication frameworks S1. No evidence in the retrieved sources addresses PSD3 or PSR specifically.

Opportunities

  • Vendors offering integrated risk-based authentication and tokenization within 3DS flows have a market opportunity as demand for secure payment acceptance continues S2.
  • Merchants can use 3DS liability-shift mechanics as a structured tool against rising friendly-fraud chargeback rates S3.
  • ANALYSIS: If eIDAS 2.0 enables payer choice of authentication method, this likely creates an opportunity for new authentication-method providers to integrate into the PSD2 SCA compliance chain S1.

Risks

  • Transactions may fail where SCA is not correctly implemented, directly impacting conversion S1.
  • Friendly fraud is described as a growing share of chargebacks and merchant losses, indicating an escalating cost risk even where 3DS liability shift applies S3.
  • ANALYSIS: Divergence in 3DS protocol version adoption across merchants could create inconsistent authentication experiences and compliance risk exposure, though this is inferred rather than stated directly.

Outlook — What to Monitor Next

  • Whether eIDAS 2.0 implementation formally enables payer-selected SCA authentication methods, as suggested but not confirmed in S1.
  • Further vendor product announcements from JCB and Worldpay on 3DS-related capabilities beyond those already cited S2.
  • Updated friendly fraud and chargeback statistics from Juniper Research or the Merchant Risk Council beyond the figures already cited S3.
  • Any regulatory guidance clarifying SCA exemption criteria referenced in S1.

Confidence Assessment

Source count: 3. None are primary regulatory or standards-body sources (e.g., no EBA, European Commission, EMVCo, or PCI SSC documents); all are tier-4 secondary commentary (a podcast summary, a market research blog, and a fraud-tools blog). Overall confidence: Low. The evidence provides directional insight into SCA/3DS dynamics but lacks primary-source verification, quantitative rigor, and depth needed for high-confidence strategic conclusions.

Sources

S1 Episode 299 - The Evolving Payments Regulatory ... — glenbrook.com — https://glenbrook.com/payments_on_fire/episode-299-the-evolving-payments-regulatory-environment-in-the-european-union-with-scott-mcinnes-bird-bird

S2 Top 15 Companies in Global 3D Secure Pay Authentication Market — sphericalinsights.com — https://www.sphericalinsights.com/blogs/top-15-companies-in-global-3d-secure-pay-authentication-market-2026-2035-spherical-insights-analysis

S3 Tools That Prevent Friendly Fraud Chargebacks — chargeflow.io — https://www.chargeflow.io/blog/what-tools-prevent-friendly-fraud-chargebacks

*Generated automatically. All factual claims carry [S#] markers referring to the numbered sources above. Analytical judgements are the model's interpretation and are not sourced.*

Evidence — 3 sources

  1. S1
    Episode 299 - The Evolving Payments Regulatory ...
    glenbrook.com○ tier 4via tavilyWed, 05 Aug 2026 00:00:00 GMT
  2. S2
    Top 15 Companies in Global 3D Secure Pay Authentication Market
    sphericalinsights.com○ tier 4via tavilyFri, 28 Aug 2026 06:00:00 GMT
  3. S3
    Tools That Prevent Friendly Fraud Chargebacks
    chargeflow.io○ tier 4via tavilySun, 23 Aug 2026 19:00:00 GMT