3-D Secure and strong customer authentication: the exemptions that save revenue, and their price
Low value up to 30 euros, transaction risk analysis up to 500 euros, recurring payments, trusted beneficiaries: which exemptions from the two-factor requirement the law allows, how much of that providers actually implement, and why every exemption used shifts liability to the merchant.
The short answer
Since the second Payment Services Directive, an online card payment in the European Economic Area generally has to be confirmed with two factors, for example a banking app plus a fingerprint. 3-D Secure 2 is the protocol for that. Because every prompt costs customers, the law allows exemptions. They are the most important lever for checkout conversion, and they come at a price: without authentication, the merchant is liable in case of fraud.
How 3-D Secure 2 works
In the frictionless flow, merchant, acquirer and card-issuing bank exchange data about the device, purchase behaviour and transaction in the background; the bank decides without any customer action. In the challenge flow, the bank requires active confirmation. Whether the prompt appears within the merchant's own page (native) or via a redirect to the bank decides how many customers drop out: providers such as Adyen report better completion rates with the native variant.
The exemptions in the law
Delegated Regulation (EU) 2018/389 sets out when strong authentication may be waived:
| Article | Exemption | Limit |
|---|---|---|
| Art. 11 | Contactless at the terminal | up to 50 euros, cumulative 150 euros or five transactions |
| Art. 13 | Trusted beneficiaries | after an initial authentication, for listed merchants |
| Art. 14 | Recurring payments | only at set-up, then free for the same amount and beneficiary |
| Art. 16 | Low value in distance selling | up to 30 euros, cumulative 100 euros or five transactions |
| Art. 18 | Transaction risk analysis (TRA) | up to 500, 250 or 100 euros depending on the payment service provider's fraud rate |
Article 11, incidentally, is the same reason why the terminal in the shop asks for a PIN above 50 euros or after five contactless payments. Online and till follow the same legal text.
What the providers make of it
Practice is narrower than the law. Stripe supports three exemptions: low value below 30 euros, TRA up to 250 euros for merchants in the EEA, and merchant-initiated payments with a stored card without an amount limit. The regulation allows TRA up to 500 euros; the 250 euros are a provider decision. Anyone who wants to push higher baskets through without a prompt has to ask the provider about it, not the law.
The price of every exemption
On a successfully authenticated payment, liability for fraud passes to the card-issuing bank. That is the liability shift. It falls away in three cases:
- on approved exemption requests,
- on pure data submissions without an authentication request,
- on merchant-initiated payments with a stored card.
In all three cases the merchant bears the loss if the card was stolen. So the exemption saves abandoned baskets and buys chargeback risk in return. For a shop with goods around 20 euros and a low fraud rate, that is a good trade. For electronics or gift cards with high amounts, a single run of fraud can eat up a quarter's conversion gains.
How a merchant manages this
- Know the fraud rate and chargeback rate per product group, not just on average.
- Differentiate exemptions by basket: low value free, high amounts and risky products always authenticated.
- Insist on a native rather than a redirect integration; it reduces drop-outs without giving up the liability shift.
- Ask the provider about its TRA threshold and its fraud rate; that determines which threshold is possible at all.
- PSD3/the PSR will adjust the rules; the underlying logic of exemption versus liability remains.