3-D Secure: the liability
shift vs the conversion
cost you don't see coming
Turning on 3-D Secure sounds like a free win: the issuer eats the fraud, not you. It isn't free, it doesn't cover most disputes, and depending on how it's implemented it can cost you real checkout conversion. Here is the actual tradeoff, with 2026 US data.
Quick answer
3-D Secure (3DS) shifts liability for fraud-related chargebacks from the merchant to the card-issuing bank -- but only when authentication completes successfully, and only for fraud reason codes (Visa 10.1-10.5, Mastercard's 483x/487x series). It does nothing for the far larger bucket of non-fraud disputes: item not received, not as described, subscription cancelled. The cost side is real too: a frictionless 3DS pass has near-zero conversion impact, but a challenge flow -- the one-time passcode or bank-app step -- can cut checkout completion 10-18%, and Ravelin's 2026 report found frictionless rates falling in 28 of 37 countries tracked, meaning more shoppers are getting pushed into that costlier path than a year ago. The US isn't under a legal mandate like the EU's PSD2, so whether 3DS is worth running is a real per-business calculation, not a default yes.
Every card-not-present sale carries fraud exposure that a dipped or tapped card doesn't, a gap we laid out in full in card-not-present interchange and in e-commerce's true blended rate. 3-D Secure is the network-level tool built to blunt that exposure by authenticating the cardholder before the sale completes. It gets pitched as a simple win -- turn it on, push fraud liability to the bank. The reality has two sharp edges most merchants never get walked through: what the shift actually covers, and what running it costs you at checkout even when no fraud ever happens.
What the liability shift actually covers
When a 3DS authentication completes successfully, liability for a fraud-related chargeback on that transaction moves from the merchant to the card-issuing bank. That protection is scoped narrowly: it applies to fraud reason codes only -- 10.1 through 10.5 on Visa, the 4837/4840/4849/4871 family on Mastercard, and the F-series on American Express -- and it requires proof the authentication actually happened. That proof is an electronic commerce indicator (ECI) and cardholder authentication verification value (CAVV) the network generates at the moment of authentication; an ECI of 05 on a Visa transaction or 02 on Mastercard signals full authentication and is what your gateway or acquirer needs on file to invoke the shift when a dispute lands.
What it does not cover is the majority of what actually shows up in most merchants' dispute queues: product not received, not as described, duplicate billing, a subscription the customer says they cancelled, or a refund that was promised but never processed. Those are "customer" or "processing" dispute categories, not fraud, and 3DS liability protection has no bearing on any of them -- a distinction we cover from the dispute-management side in chargebacks as a hidden tax. A merchant who runs 3DS on every transaction and assumes their chargeback exposure dropped to near zero is measuring against the wrong bucket.
There is also a hard exception worth knowing before you build a fraud strategy around 3DS: merchants involuntarily enrolled in Visa's Acquirer Monitoring Program (VAMP) for elevated dispute or fraud ratios are not eligible for the liability shift even when Visa Secure runs successfully on the transaction. If your dispute ratio is already high enough to trip that program, 3DS stops being the safety net it's marketed as -- which is its own argument for fixing the underlying fraud and dispute-rate problem rather than layering a tool on top of it.
The cost side: frictionless vs challenge
3DS runs one of two ways on a given transaction. A frictionless pass authenticates the cardholder silently in the background using device, behavioral, and transaction-risk signals -- the shopper never sees a prompt, and the conversion impact is close to zero. A challenge flow escalates to an explicit step: a one-time passcode texted to the cardholder, a push notification in a banking app, a biometric prompt. That extra step is where the real cost lives -- industry analysis of 3DS checkout flows puts the conversion hit from a challenge at roughly 10-18% versus an unauthenticated baseline, almost entirely from shoppers abandoning at the extra step rather than completing it.
Which path a given transaction takes isn't fully in the merchant's control -- it's a joint decision between the merchant's risk rules, the gateway's exemption requests, and the issuing bank's own risk engine -- but the data submitted at authentication time (billing address match, order history, device signals) directly influences how often the issuer grants a frictionless pass instead of forcing a challenge. Ravelin's 2026 3-D Secure rates report found frictionless authentication rates declining or plateauing in 28 of 37 countries tracked globally, including the US, which the report attributes largely to merchants not submitting enough of the right data at authentication time to earn the frictionless path -- meaning more of the same transaction volume is quietly sliding into the costlier challenge flow than a year earlier, without any policy change on the merchant's end.
A frictionless pass costs you almost nothing. A challenge flow can cost you one in every six shoppers who would otherwise have completed the sale.
What Stripe found when it actually tested this in the US
Stripe ran a controlled analysis of 3DS across a set of US businesses and found something that cuts against the simple "3DS = safer" framing: when transactions were routed through the frictionless pathway, average authorization rates fell from an 87% no-3DS baseline to 82% -- a 5-point drop -- while transactions that completed a full two-factor challenge came back to 87%, matching the baseline. In other words, in Stripe's US sample, the frictionless path (the one merchants want, for conversion) actually approved fewer transactions than not using 3DS at all, and only the friction-heavy challenge path recovered approval parity. Stripe also noted at least one major US issuing bank sending 100% of its 3DS-eligible transactions through the frictionless flow regardless of risk signal, a very different posture from regulated markets like the EU and UK where challenge flows are used far more deliberately.
The takeaway isn't "don't use 3DS in the US." It's that 3DS behavior in an unregulated market is inconsistent issuer-to-issuer in a way it isn't in the EU under PSD2's Strong Customer Authentication mandate, so results from a European case study don't transfer cleanly to a US storefront. Test it on your own traffic before assuming either the liability benefit or the conversion cost will land the way a vendor's pitch deck says it will.
Deciding whether to run it
- Check what's actually in your dispute queue. If the majority of your chargebacks are non-fraud (item not received, subscription disputes, refund complaints), 3DS liability protection won't move your numbers much -- fix the underlying service or fulfillment issue instead.
- If fraud chargebacks are the real driver, weigh the liability protection against your checkout's tolerance for friction -- a high-ticket, low-frequency purchase can usually absorb a challenge step; a high-volume, low-ticket checkout usually can't.
- Push your gateway on data quality before assuming a challenge flow is unavoidable -- complete billing, shipping, and account-history data submitted at authentication time is what earns a frictionless pass instead of a challenge.
- Confirm your acquirer can actually produce ECI/CAVV proof at dispute time. A 3DS pass that can't be documented when a chargeback lands doesn't shift anything.
- Re-test conversion impact directly on your own traffic rather than trusting a vendor benchmark -- Stripe's own US findings show issuer behavior here is inconsistent enough that generic numbers don't transfer.
Frequently asked questions
Does 3-D Secure protect against all chargebacks?
No. The liability shift only covers fraud-related chargebacks -- reason codes 10.1 through 10.5 on Visa and the equivalent Mastercard fraud codes -- and only when authentication actually completed successfully. It does nothing for the far more common non-fraud disputes: product not received, not as described, subscription cancelled, or a credit never processed. A merchant using 3DS still owns every one of those.
What does a successful 3-D Secure authentication actually shift?
It shifts liability for that specific fraud loss from the merchant to the card-issuing bank. To prove the shift applies, the merchant or its gateway has to be able to produce the electronic commerce indicator and cardholder authentication verification value the network generated at authentication time -- an ECI of 05 on Visa or 02 on Mastercard signals a fully authenticated transaction. Without that proof, the liability stays put even if 3DS technically ran.
Does 3-D Secure hurt checkout conversion?
It depends entirely on which path the transaction takes. A frictionless pass -- authenticated silently in the background with no shopper action -- has close to no conversion impact. A challenge flow that pushes the shopper to a one-time passcode or bank app step can cut conversion 10 to 18 percent, largely from abandonment during the extra step. Ravelin's 2026 report found frictionless rates falling in 28 of 37 tracked countries, meaning more shoppers are getting pushed into the costlier challenge path than a year earlier.
Is 3-D Secure required for US merchants?
Not by law. The EU and UK require Strong Customer Authentication under PSD2, which is what pushed 3DS adoption there; the US has no equivalent mandate. US merchants use 3DS voluntarily, weighing the fraud-liability protection and any interchange-qualification benefit against the conversion friction of a challenge flow -- which is why US usage and success rates lag deeply regulated markets even as they climb.
Key takeaways
- 3DS liability shift covers fraud chargebacks only (Visa 10.1-10.5, Mastercard's 483x/487x family) -- not the non-fraud disputes that make up most merchants' actual chargeback volume.
- The shift requires proof: an ECI of 05 (Visa) or 02 (Mastercard) plus a CAVV on file at dispute time. No proof, no protection, even if 3DS ran.
- Merchants involuntarily placed in Visa's Acquirer Monitoring Program (VAMP) lose eligibility for the liability shift even when Visa Secure completes successfully.
- Frictionless 3DS costs almost nothing in conversion; a challenge flow can cost 10-18%, and frictionless rates are declining in most tracked markets, including the US, per Ravelin's 2026 data.
- Stripe's own US analysis found the frictionless path can approve fewer transactions than no 3DS at all (82% vs an 87% baseline) -- US issuer behavior is inconsistent enough that European benchmarks don't transfer directly.
Sources & how to verify
3DS liability shift scope, ECI/CAVV proof requirements, and the VAMP exclusion are drawn from TabaPay's developer documentation on 3D Secure liability shift and GPayments' analysis of the 3DS liability shift in the United States; verify current reason-code scope against your acquirer's own dispute documentation, since network rule updates can shift specific code ranges. US and global 3DS success-rate and frictionless-rate figures (88% US success rate, 47% year-over-year improvement, 28-of-37-country frictionless decline) are from Ravelin's "3D Secure rates 2026" report. US conversion and authorization-rate findings (87% baseline vs 82% frictionless vs 87% challenge) are from Stripe's published analysis of 3DS transactions in the US; Stripe notes its sample was a limited set of businesses over a short test window, so treat the exact percentages as directional for your own traffic rather than a universal benchmark.
Get a real read on your fraud and dispute costs
Send us a recent statement and dispute log and we'll show you whether 3-D Secure would actually move your numbers, or whether your real exposure is somewhere else entirely.
Talk to MidPay โ Sell online? See our e-commerce pricing.