Get started

3D Secure and SCA: how authentication affects approval rates

Gabriele Strimaite
  • 7 min read

  • Updated: September 22, 2026

3D Secure and SCA: how authentication affects approval rates

Strong customer authentication is not a zero-sum game where higher security must come at the expense of lower conversions – that is simply not how modern payment processing works.

Take the EU as a prime example: card payment processing in Europe is heavily regulated and requires strict security protocols, making it an ideal environment to see how a strong customer authentication approval rate directly impacts merchant performance.

The short version? While early regulatory rollouts triggered reports of sudden conversion drops, optimized payment setups now regularly achieve high authorization recovery after addressing initial challenges with 3D Secure and SCA approval rates.

However, mastering this landscape goes far deeper than managing basic 3DS friction, checkout conversion issues. Learn more about 3D Secure in our article.

Understanding the mechanics of SCA and 3D Secure 2.0

What is strong customer authentication (SCA)?

Card payment processing in Europe has mandatory safety requirements under PSD2, which means customer authentication is essential for any online payment. The USA has no federal-level regulations like these, and each country has its own approach.

So, here is how it works in Europe. The customer must prove identity with at least two independent elements:

  • Knowledge: Something only the customer knows, such as a password or PIN.

  • Possession: Something only the customer holds (a registered smartphone receiving a banking app push notification, or a hardware token).

  • Inherence: Something the customer is, such as a fingerprint or face scan.

While certain low-risk transactions may qualify for exemptions, in practice, most European consumers manage their finances using mobile phones and banking apps, where PIN codes or fingerprints serve as the primary validation layer to access the app and authorize payments.

Open an account

in Genome online

Get Started

The evolution from 3DS1 to 3D Secure 2.0

3DS1 is the original security protocol, developed back in 1999 by Visa and currently retired. The first iteration used a full redirect from the merchant’s site, which caused a major cart abandonment rate crisis. Balancing 3D Secure and SCA approval rates was a new challenge at the time, and many merchants were unprepared for the added friction.

Side note: While “3DS” (short for Three-Domain Secure) has become a common industry term, modern implementations operate under specific card scheme branding, such as Visa Secure, Mastercard Identity Check, and UnionPay PaySecure, all built on the global EMV 3DS standard.

3D Secure 2.0 (EMV 3DS) was a breakthrough. Instead of simply asking the customer for a password or one-time code, the 3DS2 flow gives the issuing bank a much richer picture of the transaction – including device information, IP address, email, shipping details, and customer account history.

This changed lots of payment mechanisms and allowed for a frictionless flow – when a customer and their payment can be authenticated quietly in the background. That’s when the 3DS friction-checkout conversion talk comes in.

Passwords or fingerprints are required only when a bank or online store needs additional information.

Feature

3DS1

3DS2

Data shared with issuer

A handful of fields

100+ potential data points

Checkout experience

Redirect or pop-up to issuer page

In-page challenge, native mobile SDK

Authentication method

Static password, SMS code

Biometrics, banking app, one-time codes

Frictionless flow

None, every payment challenged

Risk-based, low-risk payments skip the challenge

Status

Retired in 2022

Current standard, 2.3 adds new data fields

How 3D Secure authentication impacts payment approval rates

Ravelin’s Global Payments Report 2026 tracks 37 countries. Frictionless authentication decreased in Europe and globally, and 28 of the 37 countries recorded falling or flat frictionless rates.

The same report shows how wide the gap is within one regulatory regime: 3DS success rates of 93% in Italy, 92% in the Netherlands, 91% in France, 87% in Germany, 81% in Spain, and 72% in Finland.

The friction vs. security trade-off at checkout

Authentication has one clear operational upside: when a payment is fully authenticated via 3DS, the liability for unauthorized fraud chargebacks shifts from the merchant to the card issuer. For online merchants, protecting cash flow and maintaining a low chargeback ratio is critical.

However, introducing friction at checkout directly threatens conversion rates. Every password prompt or challenge screen is an extra step where potential customers wait, switch to a banking app, or abandon their cart out of confusion – an experience that is especially frustrating for returning customers.

Managing 3DS friction checkout conversion risks requires a strategic approach. Merchants cannot simply declare every transaction low risk on their own to bypass SCA. While payment service providers can request frictionless authentication exemptions (such as Transaction Risk Analysis or low-value exemptions), the card-issuing bank ultimately decides whether to grant the exemption or require step-up authentication.

To maximize 3D Secure and SCA approval rates through frictionless flows, rich transaction data is essential. Passing detailed signals, including device fingerprinting, IP location, purchase history, and customer behavior, allows issuing banks to confidently verify low-risk transactions in the background without prompting unnecessary challenge screens.

Common triggers for authentication-related payment declines

Here, we’ll cover the most common problem affecting strong customer authentication approval rates.

  • SMS OTP latency: One-time passcodes arrive late or fail to deliver entirely, particularly for cross-border transactions or customers roaming internationally.

  • Biometric and app failures: Outdated banking apps or unregistered devices can cause biometric verification to fail, even when the customer’s credentials are valid.

  • Unsupported issuer protocols: Occurs when a cardholder’s bank lacks the infrastructure to process modern 3DS2 data – an increasingly rare issue within Europe, but still present in non-regulated markets.

  • Customer confusion and timeouts: Clunky UI redirects or poorly designed authentication pop-ups confuse buyers, leading to session timeouts and abandoned carts before the challenge is completed.

  • Unhandled soft declines: Integration bugs in checkout software can prevent the system from recognizing a soft decline (a bank’s request for 3DS verification) and retrying the transaction, causing valid sales to fail outright.

Each of these friction points directly reduces your strong customer authentication approval rate. Fortunately, the vast majority can be eliminated through intelligent checkout design and proper payment infrastructure.

Optimize your checkout experience with Genome

You require a reliable merchant account provider to navigate complex checkout friction and safeguard your strong customer authentication approval rate.

With a Genome merchant account, businesses can effortlessly accept payments from customers using our hosted payment page, with host-to-host integration coming soon.

To bypass traditional card network bottlenecks and dispute risks entirely, Genome enables instant bank payments, delivering a seamless Pay by Bank alternative payment method powered by SEPA Instant Transfers for immediate settlement confirmation.

Furthermore, card payment processing in Europe for Visa and Mastercard is launching soon for Genome merchant account holders, giving you an even broader suite of payment solutions under one roof.​

Open an account

in Genome online

Get Started

Strategies to optimize authorization rates under PSD2

Leveraging frictionless authentication exemptions

Exemptions represent the single most effective lever for improving your 3D Secure and SCA approval rates. Under PSD2, the primary exemption mechanisms include:

  • Low-value exemption: payments under €30, up to a cumulative €100 or five consecutive transactions before the issuer forces a challenge.

  • Transaction risk analysis (TRA): the acquirer can exempt payments up to €100, €250, or €500 if its card fraud rate stays under 0.13%, 0.06%, or 0.01%, respectively.

  • Trusted beneficiary: the cardholder whitelists your business with their issuer, so future payments skip the challenge. Issuer support is uneven.

However, requesting frictionless authentication exemptions does not guarantee automatic approval. The final decision always rests with the cardholder’s issuing bank. Industry reports indicate that while 78% of merchants actively request exemptions, frictionless approval rates have dipped in certain markets because issuers are sharpening their risk algorithms and declining weak exemption requests.

Frictionless authentication exemptions work when matched to customers’ purchase behavior, meaning you need one in the first place. They won’t apply by default, and that is how you protect 3DS friction checkout conversion.

Side note: PSD3 is the newest European Payment Services Regulation, provisionally agreed in November 2025, refines SCA and exemption rules but keeps the 3DS2 liability mechanism.

Smart payment routing and backup payment rails

When an issuer soft-declines and asks for authentication, retry instantly with a 3DS challenge instead of showing an error. This should be a rule – you never shove clients with the message that something went wrong.  

Then offer a second way to pay at the point of failure. If you can’t proceed with Visa or PayPal, propose a Pay by Bank alternative payment method if you are in Europe, or another alternative payment method if you are outside the EU.

Real-time account-to-account payments already rank in the top three payment types in Germany and the Netherlands.

Open Banking merchant tools that use SEPA Instant Transfers for account-to-account payments will clear in seconds and skip client authentication scoring entirely.

Open an account

in Genome online

Get Started

Frequently asked questions about 3D Secure and approval rates

Does 3D Secure 2.0 always require manual customer interaction?

No. 3DS2 shares device and transaction data with the issuer in the background. If the issuer judges the payment low-risk, it approves the authentication with no prompt. Only higher-risk payments trigger a challenge such as a biometric check or a one-time code.

How does 3DS shift fraud liability for merchants?

When a payment is successfully authenticated with 3DS, chargeback liability for unauthorized fraud moves from the merchant to the card-issuing bank. It doesn’t cover every dispute type, but it generally helps a lot.

Why do card approval rates vary across European countries?

Payment providers do not make identical risk decisions. That is why 3D Secure and SCA approval rates differ so much by country.

You may also like