Strong Customer Authentication is not going away, but the 30-second challenge screen can. This guide explains how 3-D Secure 2 decides who gets challenged, which exemptions let you skip it, where the fraud liability sits after each decision — and what the numbers look like across the merchants on Target.
What 3-D Secure 2 is
3-D Secure is the card schemes’ protocol for authenticating a cardholder during an online payment. The “three domains” are the merchant and its acquirer, the card scheme in the middle, and the bank that issued the card. Version 1, launched in 2001, redirected the shopper to a password page and lost roughly a quarter of them on the way. Version 2, specified by EMVCo in 2016 and the only version the schemes have accepted since 3DS 1 was retired in October 2022, works the other way round: instead of asking the shopper for a password, it sends the issuer a data set of 100+ fields — device and browser, billing and shipping addresses, the age of the account, its order history — and lets the issuer’s risk engine decide whether the shopper needs to prove anything at all.
The protocol matters in Europe because of Strong Customer Authentication (SCA) under PSD2 and the matching UK rules. An electronic payment has to be verified with two of three factors — something the customer knows, has or is — unless one of the listed exemptions applies. For a card payment, 3-D Secure 2 is the only practical way to meet that requirement. Target runs version 2.2 on every transaction; it is the release that lets us flag an exemption inside the authentication message rather than only at authorisation, which is what makes the automation in section 06 possible.
Frictionless or challenge: the two flows
Every 3DS2 authentication follows the same four steps. The shopper only notices the third one — and only when the issuer is not convinced.
Collect
Your checkout, or Target’s hosted page, gathers the device fingerprint and order data through the 3DS method URL. About one second, invisible.
Score
Target’s 3DS Server sends the packet through the scheme directory to the issuer’s ACS, which scores it against the cardholder’s history in real time.
Decide
Low risk: frictionless — the shopper sees nothing. High risk: a challenge — one-time code, app push or biometric, typically 25–35 seconds.
Authorise
The result (CAVV and ECI values) travels with the authorisation request, and the fraud liability moves to the issuer.
In the frictionless flow the issuer approves silently and the whole exchange adds about 1.5 seconds to the checkout. In the challenge flow the issuer’s page opens in an iframe (or the banking app on mobile) and asks for a second factor. Across the merchants on Target in the second quarter of 2026, 74% of authentications were frictionless; the remaining 26% were split between issuer-initiated challenges and challenges we asked for on purpose — see the exemption logic below.
Exemptions: when you can skip the challenge
The SCA rules list situations where the second factor can be skipped. An exemption is either requested by the acquirer (Target, on your behalf) or applied by the issuer, and the issuer can always refuse it and demand a challenge instead — a so-called soft decline. The table covers the exemptions that matter for an online merchant.
| Exemption | Limit | Who applies it | Fraud liability |
|---|---|---|---|
| Low value | Up to €30 per transaction; the issuer must challenge after 5 consecutive exempt payments or €100 cumulative | Acquirer or issuer | Merchant, when Target requests it |
| TRA | Transaction risk analysis: up to €100 at a fraud rate of 0.13%, €250 at 0.06%, €500 at 0.01% | Acquirer or issuer | Merchant if acquirer-requested, issuer if issuer-applied |
| Trusted beneficiary | No limit — the cardholder adds you to a whitelist held by their bank during a challenge | Issuer, at the shopper’s request | Issuer |
| Recurring | Same amount, same payee; the first payment of the series needs full SCA | Issuer | Issuer, from the second payment |
| Corporate | Payments made with dedicated corporate processes — lodged or virtual cards | Issuer | Issuer |
Three common cases are not exemptions at all but are simply out of scope of SCA: merchant-initiated transactions (a stored card charged without the cardholder present, such as a usage-based subscription), mail and telephone orders, and “one-leg-out” payments where either the issuer or the acquirer sits outside the EEA and UK. They need no authentication, but they need to be flagged correctly — an MIT sent as a normal customer-present payment will be soft-declined.
Liability shift
The commercial point of 3-D Secure has always been the liability shift. When a transaction is authenticated — a passed challenge, or a frictionless approval where the issuer took the decision — fraud chargebacks (“fraudulent transaction, cardholder does not recognise”) are charged to the issuer, not to you. When an exemption is requested by the acquirer, the liability stays with the merchant: you chose to skip the challenge, so you carry the fraud. Issuer-applied exemptions keep the liability with the issuer, which is why a trusted-beneficiary whitelisting is the best outcome a merchant can get.
Two things do not change either way. Non-fraud disputes — item not received, not as described, duplicate charge — follow the usual chargeback rules whatever the authentication result. And Target’s chargeback fee of €15 per case applies to every dispute; what an exemption strategy protects is the fraud losses themselves, which for a mid-sized store are typically ten to twenty times larger than the fees.
The rule of thumb: exempt where the basket is small and your fraud rate is low; authenticate where either is not.
What it does to conversion
The figures below come from Target merchants processing EU and UK cards in the second quarter of 2026 — averages, not the best case.
- A frictionless authentication loses under 1% of shoppers and adds about 1.5 seconds to the checkout.
- A challenge loses 12% on average: 9% when the issuer uses an app push or biometric, 16% on an SMS one-time code. Older cards and small issuers are the weak spot.
- Merchants who switched exemptions on saw their approval rate rise by 3.4 percentage points on average — from 84.8% to 88.2% — which is where the platform-wide 88% figure comes from.
- Soft declines ran at 6% of exemption requests. Every one has to be retried with a challenge automatically, or the sale is lost; a retry the shopper has to trigger with a second click converts at half the rate.
Put together: on a store with 10,000 card payments a month and a €60 average basket, moving from “challenge everything” to a tuned exemption policy is worth roughly 340 extra approved orders, or about €20,000 in revenue, every month — at the cost of carrying fraud liability on the exempt share.
How Target applies exemptions automatically
You do not need to build an exemption engine. Target’s 3DS Server sits behind the fraud engine, so by the time a payment reaches authentication it already has a machine-learning risk score and the result of your own rules. From that score, the basket value, the card’s country and our acquirer’s rolling fraud rate — which we keep below the TRA thresholds, otherwise the exemption disappears for everyone — the engine picks one of three routes: request a TRA exemption, request a low-value exemption, or authenticate in full.
The choice is flagged in the 3DS 2.2 message, or at authorisation for the few issuers still on 2.1. If the issuer soft-declines, we retry with a challenge in the same session without a second click from the shopper. Merchant-initiated and recurring payments are sent with the original transaction reference, so they never hit an unexpected challenge. Every decision is visible in the transaction detail in the merchant dashboard — route taken, ECI value, issuer response — and the thresholds can be tuned per merchant: a lower TRA ceiling for a new customer, “always challenge” for a product category, or exemptions off entirely for a high-risk country. Your personal manager sets the initial policy with you during onboarding and reviews it quarterly against your fraud and dispute figures.
Checklist for merchants
- Send the full data set: billing and shipping address, e-mail, phone, account creation date, order count. Issuers challenge sparse requests more often.
- Let the 3DS method URL run before the shopper presses Pay so the device fingerprint is ready — it is worth roughly 10 percentage points of frictionless rate on its own.
- Render the challenge in a 390×400 iframe on desktop and full-screen on mobile; a cramped challenge window is the most common cause of avoidable abandonment.
- Flag merchant-initiated and recurring payments correctly and store the reference of the first authenticated transaction.
- Decide your exemption policy by basket size and customer risk — or accept Target’s defaults and adjust once you have a month of data.
- Handle soft declines automatically: a response of “authentication required” must trigger a challenged retry, not an error message.
- Test both flows in the sandbox with the frictionless and challenge test cards before going live.
- Watch three numbers weekly in the dashboard: challenge rate, challenge abandonment and fraud rate. Keep the last one under 0.13% and the TRA exemption stays available.
- Keep the CAVV, ECI and 3DS transaction ID with every order — they are the evidence you need to win a fraud dispute.
Conclusion
3-D Secure 2 is not a tax on conversion. Treated as a data problem — send more, challenge less, exempt where the risk allows — it is the mechanism that gets a mid-sized store from the low eighties to an approval rate near 90% while moving most of the fraud liability to the issuer. The work on your side is small: complete data, correct flags, a sandbox test of both flows and a monthly look at three numbers.
See how authentication fits into the checkout, smart routing and the payment methods we support on the online acquiring page, and find the 3DS parameters, response codes and test cards for both flows in the developer documentation. If you would rather talk it through, the form below reaches the risk team directly.