3D Secure / ACS

All ProductsSecuring & Switching

3D Secure / ACS

An EMV 3DS2 Access Control Server (ACS) for card issuers — delivering frictionless, risk-based authentication for online transactions while meeting PSD2 SCA requirements. Supports challenge flows via OTP, biometric, and out-of-band authentication, with full exemption management and analytics.

Architecture Overview

EMV 3DS2 Authentication Flow

Click to expand. The diagram shows the full 3DS2 protocol flow — from cardholder browser through the merchant requestor, directory server, ACS, and back to the acquirer.

3D Secure / ACSEMV 3DS2 authentication & Access Control ServerCardholderBrowserMerchant3DS RequestorDSDirectoryACSIssuerAuthResultAcquirerAuthoriseACS CapabilitiesFrictionless AuthRisk-based, no challengeChallenge FlowOTP, biometric, appDecoupled AuthOut-of-band verifyEMV 3DS 2.2Latest protocolExemptions EngineTRA, low-value, trustedReportingAuth rates & analyticsPSD2 / SCAEMV 3DS 2.2Visa SecureMC Identity CheckGDPREMV 3DS2 ACS — frictionless authentication at scale
Expand diagram

Platform Capabilities

What the Platform Delivers

EMV 3DS 2.2 protocol support
Frictionless authentication via risk-based decisioning
OTP challenge via SMS, email, and push notification
Biometric authentication integration
Decoupled authentication (out-of-band)
Exemption management (TRA, low-value, trusted beneficiary)
Visa Secure and Mastercard Identity Check certified
Authentication rate analytics and optimisation
Issuer rules engine configuration
Real-time fraud signal integration
PSD2 SCA compliance
GDPR-compliant data handling

Key Features

Built for APAC Requirements

Maximise Frictionless Rates

Risk-based decisioning analyses 100+ data points per transaction to approve as many transactions frictionlessly as possible — reducing cart abandonment while maintaining fraud control.

Flexible Challenge Methods

Challenge cardholders via SMS OTP, push notification, biometric, or out-of-band app authentication — configurable per issuer, card product, and risk level.

Exemption Engine

Automatically apply PSD2 exemptions — transaction risk analysis, low-value, trusted beneficiary, and corporate — to reduce unnecessary challenges on low-risk transactions.

Analytics Dashboard

Monitor authentication rates, challenge rates, abandonment, and fraud by channel, merchant, and card product — with drill-down to individual transaction detail.

Typical Use Cases

Who Uses This Platform

  • Card issuers deploying 3DS2 ACS for online transaction authentication
  • Banks migrating from 3DS1 to EMV 3DS2
  • Issuers seeking to improve authentication rates and reduce fraud
  • Banks needing PSD2 SCA compliance for European card programmes
  • Processors providing managed ACS services to multiple issuers

Get Started

Ready to Implement?

Proximo's specialists will scope the implementation, manage the vendor relationship, and deliver a production-ready system — configured for your APAC market.

Discuss 3DS2 Implementation