Skip to main text

Identity authentication to prevent payment of impersonation

EMV 3-D Secure (3D Secure 2.0)

What is EMV 3-D Secure (3D Secure 2.0)?

EMV 3-D Secure (3D Secure 2.0) is a personal authentication service that determines whether a transaction during an online payment is made by the genuine cardholder or by 'spoofing' using stolen credit card numbers.

Currently, as a measure against credit card fraud, it is essential to implement it for all non-face-to-face e-commerce site operators in principle.

PG Multi-Payment Service 's EMV 3-D Secure (3D Secure 2.0) contributes to reducing input load for end users through risk-based authentication and lowering chargeback risks for operators.

Three Key Reasons Why PG Multi-Payment Service EMV 3-D Secure (3D Secure 2.0) Is Chosen

  1. POINT 01

    Identity authentication services that identify fraud and minimize spoofing transactions

  2. POINT 02

    Avoiding the chargeback burden of successful authentication transactions

  3. POINT 03

    Reducing the input load for end users through risk-based authentication

PG Multi-Payment Service
Contact Information for EMV 3-D Secure

Benefits of Introducing EMV 3-D Secure (3D Secure 2.0)

  • MERIT 01

    Reducing Credit Card fraud Risk

    Based on device, behavior, and attribute information, risk-based authentication is used to determine whether the card issuer is conducting a transaction with the person themselves or is being 'spoofed' through credit card number theft. Businesses can establish a highly secure transaction environment and more easily suppress fraud occurrence.

  • MERIT 02

    chargeback Avoiding Burdens

    If fraud occurs in an EMV 3-D Secure (3D Secure 2.0) authentication transaction, in principle, the business operator's chargeback is exempt. This helps reduce unexpected costs and stabilizes revenue.

  • MERIT 03

    Reducing the risk of cart abandonment through risk-based authentication

    With EMV 3-D Secure (3D Secure 2.0), if a risk-based authentication determines a transaction is low-risk, no additional authentication is required (frictionless). By reducing the input load on end users, we help suppress payment process abandonment and improve the purchase completion rate (CVR).

  • MERIT 04

    Compliance with Security Guideline Requirements

    The "Credit Card Security Guidelines," which serve as practical guidelines under the Installment Sales Act, require all EC merchants to implement EMV 3-D Secure (3D Secure 2.0) in principle. Taking the measures outlined in the guidelines is recognized as meeting the standards for the security measures specified under the Installment Sales Act.

Examples of industries and products that are likely to become "fraud targets"

  • High-priced products
    (Home appliances / branded goods / jewelry, etc.)

    This is an area where fraud for impersonation and resale purposes are often targeted.

  • Digital Content Services (Games/Video/E-books, etc.)

    Because they are delivered immediately, spoofing transactions tend to become more apparent.

  • subscription ・Subscription services (health foods/cosmetics, etc.)

    This area is crucial for identity verification when registering your card number.

  • Travel Tickets
    (Travel Reservations/Events, etc.)

    These products are expensive and highly convertible, making them easy targets for fraud through impersonation.

EMV 3-D Secure (3D Secure 2.0) Three Operating Patterns

The Credit Card Security Guidelines outline three operational patterns centered on EMV 3-D Secure (3D Secure 2.0). In all operations, the introduction of EMV 3-D Secure (3D Secure 2.0) is required. You can consider the most suitable operation according to the products you handle and your risk situation.

Three Operational Patterns for EMV 3-D Secure (3D Secure 2.0)

Operation Patterns Authentication when registering the card number payment Individual Authentication fraud Measures Required Outside EMV 3-D Secure
(1) Based on the merchant's risk assessment
3D Secure Operations for Authentication
Authentication only when necessary Authentication only when necessary
  • payment Comprehensive measures for before/ payment hours/ payment after timing
(2) When registering the card number
3D Secure Operations for Authentication
Must Authentication only when necessary
*Required for guest purchases
  • Preventing unauthorized logins
  • fraud Countermeasures such as Attribute and Behavior Analysis
(3) Each payment
3D Secure Operations for Authentication
Recommendation Must
  • Measures as needed

Overview of Each Pattern

  1. Operation of 3D Secure authentication based on merchant risk assessment

    payment Comprehensive fraud measures before, payment, and payment after have deterrent effects equal to or greater than EMV 3-D Secure (3D Secure 2.0), and the operator decides on the implementation of certification. Establishing specialized departments, analyzing attributes and behaviors, and establishing appropriate organizational structures and countermeasures are required. Separate approval from the acquirer is required to carry out this operation.

  2. Operation of 3D Secure authentication when registering the card number

    Authentication is always performed when registering, changing, re-registering, or adding credit card numbers, and authentication is performed when necessary for payment time based on fraud risk assessment. Operations are combined with fraud measures such as unauthorized logins and attribute behavior analysis. Also, when accepting guest purchases, authentication at payment time is mandatory.

  3. Operation that performs 3D Secure authentication for each payment

    payment Each time, EMV 3-D Secure (3D Secure 2.0) authentication is performed. It is also recommended to perform authentication when registering your credit card number.

*Created based on Credit Card Security Guidelines version 6.1.

Features of EMV 3-D Secure (3D Secure 2.0): Authentication Conductor

Identity authentication is a mechanism to prevent fraud by implementing the identity verification process, such as entering a PIN at a Credit card payment at a physical store, even on non-Card Present Transactions sites such as e-commerce sites. In EMV 3-D Secure (3D Secure 2.0), the authentication process is divided into three patterns by "risk-based authentication" that determines the degree of risk based on device information, behavioral information, and attribute information used in online shopping.

Authentication conductor

Features of EMV 3-D Secure (3D Secure 2.0): chargeback burden

For transactions implemented with EMV 3-D Secure (3D Secure 2.0), if (1) authentication is successful (2) in transactions where the card company or member does not participate * fraud occurs, the card company generally bears the cost.

* The EC business operator has conducted a transaction via EMV 3-D Secure (3D Secure 2.0), but authentication is not performed depending on the status of the card company or the cardholder's settings.

status

Risk Burden

1

EMV 3-D Secure Authentication Successful

Merchants are exempt from liability *1

2

Member's card issuer or member has not joined EMV 3-D Secure

3

EMV 3-D Secure Authentication Out of Trade

Merchants are not exempt from liability *2

  • *1 Even if EMV 3-D Secure authentication is performed at the time of card registration, it is not subject to liability unless EMV 3-D Secure authentication is also performed at the time of subsequent transactions.
  • *2 Based on the content of the contract with the contract card company (acquirer).

Credit card payment Trends in Fraud and EMV 3-D Secure (3D Secure 2.0)

Credit card fraud damage amounts have been increasing year by year, exceeding 50 billion yen in 2023. Since April 2025, when the introduction of EMV 3-D Secure (3D Secure 2.0) became mandatory, the amount of damage from number theft where identity authentication is valid has started to decrease.

The introduction of EMV 3-D Secure (3D Secure 2.0) is effective in suppressing fraud caused by number theft and underscores the importance of identity authentication services that detect impersonation.

PG Multi-Payment Service | EMV 3-D Secure (3D Secure 2.0) Specifications

Supported Brands Visa/Mastercard/JCB/American Express/Diners Club
Connection method
?
What is the connection method?

This is how to connect your business site, system, and PG Multi-Payment Service. Depending on your site layout and operation method, you can choose from OpenAPI type, Link Type, Plus, and more.

OpenAPI Type / Link Type Plus / Protocol Type *Planned Closure / Module Type *Planned Closure
cost Monthly Usage Fee

Frequently Asked Questions

  • Is EMV 3-D Secure (3D Secure 2.0) mandatory?

    In principle, it is mandatory. It is regulated by the 'Credit Card Security Guidelines [Version 6.0]' set by the Japan Credit Association.

  • Please tell me about brands that support EMV 3-D Secure (3D Secure 2.0).

    VISA,​ ​Mastercard, JCB, American Express *, and Diners brands are supported. For other credit card brands, normal transactions are conducted without identity verification.

    * If you use merchant acquiring service, you must have a contract with JCB Co., Ltd. to be a condition of use.
    If you are contract directly with your card company, you must have a contract with American Express International, Inc., Inc. as a condition of use.

  • Are there any points to note after the price change for EMV 3-D Secure (3D Secure 2.0)?

    If you change the amount of payment using EMV 3-D Secure (3D Secure 2.0), you will be payment without using 3D Secure.
    Therefore, if you receive a chargeback from the credit card company at a later date by fraud, etc., you may have no choice but to accept it.

  • What are the installation and operation costs for EMV 3-D Secure (3D Secure 2.0)?

    Introduction and operation costs are quoted individually. For more details, please contact us.

  • Can EMV 3-D Secure (3D Secure 2.0) be installed on my current shopping cart or system?

    Whether or not it can be introduced depends on the development environment such as EC cart. Please check with the development company.

  • How accurate is fraud authentication in EMV 3-D Secure (3D Secure 2.0)?

    Even transactions that have passed EMV 3-D Secure (3D Secure 2.0) certification may still be fraud, but in such cases, the chargeback burden is generally considered an issuer.

Related Content

PG Multi-Payment Service
Contact Information for EMV 3-D Secure