CHECKOUT CHRONICLE . ISSUE 01 FEE TABLES REBUILT FROM STATEMENTS . NO AFFILIATE LINKS . CHECKOUTCHRONICLE.COM
CCCheckout ChronicleWhere online store money actually goes
← Checkout Chronicle/Authentication
Authentication

Does 3D Secure hurt conversion: the switch is not in your checkout

Whether your customer gets challenged is decided by a rolling 90 day fraud rate belonging to your provider, and by which of the 3 basket bands your order falls into. The published thresholds, what the European fraud data says the friction buys, and the 25 per cent the regulators say may not be exempt at all.

CCBY the settlements desk.13 MIN.4 AUG 2026

Every time somebody has asked me does 3d secure hurt conversion, I have answered it as a question about the checkout. Fewer steps, fewer drop-offs, so turn the challenges down as far as the acquirer will let you and watch the authorisation rate. That answer treats the challenge as a setting on your side of the glass.

It is not a setting on your side of the glass. I had assumed for 2 years that it was, and this is the corrected version. I read the regulation properly this week, and then the regulators' own data on top of it, and the honest version is that whether your customer gets challenged is decided by a rolling 90 day fraud rate that belongs to your payment provider and not to you. Your basket size decides which threshold that rate has to sit under.

That is the whole piece. What follows is the arithmetic, the published numbers, and the 2 things I still cannot find out. I should say at the top that everything quoted below comes out of the European rulebook and the European supervisors' own statistics, because those are the only places where any of this is written down in public, which makes this piece more useful to a shop selling into Europe than to one that never does, and I would rather put that limitation in the third paragraph than in a footnote.

What the exemption actually is

European rules require strong customer authentication on remote card payments, and then let providers skip it under named exemptions. The one that matters commercially is transaction risk analysis, and it is not a judgement call. It is published as a table.

Exemption threshold values and the reference fraud rates attached to them for remote electronic card payments, taken from the annex to the regulation and checked on 4 August 2026, with the last column showing how much room each band leaves against the market-wide card fraud rate of 0.033 per cent recorded for 2024.

BasketRate ceilingRoom vs 0.033%
To 500 EUR0.01%none
To 250 EUR0.06%1.8x
To 100 EUR0.13%3.9x

The regulation sets 3 exemption threshold values, each paired with a maximum fraud rate. A transaction up to 500 euros can skip authentication only while the relevant fraud rate is at or below 0.01 per cent. Up to 250 euros the line is 0.06 per cent. Up to 100 euros it is 0.13 per cent.

Read that as a merchant rather than as a compliance officer and it says something uncomfortable. A shop with an average basket of 90 euros is asking its provider to stay under 0.13 per cent. A shop selling a 260 euro item is asking the same provider to stay under 0.06, which is less than half the room, for exactly the same customers and the same checkout. The friction you experience is a function of your price list.

The fraud rate itself is defined tightly, and I had it wrong in my head before I read it. It is “the total value of unauthorised or fraudulent remote transactions, whether the funds have been recovered or not, divided by the total value of all remote transactions for the same type”, on “a rolling quarterly basis (90 days)”. By value, not by count. Recovery of the money does not help. And it counts both the authenticated transactions and every exempted one, so a provider cannot improve the number by pushing more traffic through authentication.

The part that made me rewrite the piece

There is a cessation rule underneath the table, and it is the reason this is not a static setting.

If a provider's monitored fraud rate goes above the reference rate for a threshold band “for two consecutive quarters”, it must “immediately cease to make use of the exemption” in that band. Coming back is not automatic either: the rate has to return to or below the line for a quarter, and the regulator has to be notified before the exemption is used again.

So there is a switch, it has 2 quarters of hysteresis on the way in and 1 on the way out, and it is thrown by a portfolio you cannot see. Everything above 100 euros can start getting challenged in your checkout because of fraud that happened at other merchants, on the same provider, over the previous 6 months.

I have never seen that explained to a merchant. I have also never seen a provider publish its rolling rate, which is the number that would let you predict any of this.

The rate is audited, at least, which I did not know. The methodology, the model and the reported rates go past an auditor “at a minimum on a yearly basis”, and in the first year of using the exemption and at least every 3 years after that the audit has to come from an independent external auditor. That is more oversight than I expected and it still tells you nothing in advance.

There is a second exemption underneath, and it is the one that covers small baskets outright. Below 30 euros a remote payment can skip authentication, but only while the running total since the last authentication stays under 100 euros, or while the count of consecutive unauthenticated payments stays under 5. A customer buying a 12 euro item for the ninth time hits a challenge that has nothing to do with your shop.

What the fraud data says about the trade

The European Banking Authority and the European Central Bank publish payment fraud jointly, and the 2025 edition covers 6 half-year periods to the end of 2024. It is the closest thing to an answer that exists.

In 2024, fraudulent card transactions in the reporting area came to 1.3 billion euros, which is a fraud rate of 0.033 per cent of value. Set that against the exemption table and something jumps out: the market-wide card fraud rate is already 3 times the 0.01 per cent line that a 500 euro basket needs. High-value exemptions are a narrow privilege, not a normal state.

Authentication is also far from universal. Around 64 per cent of card payment value was authenticated, and only 40 per cent of the number of transactions, because contactless payments at the till dominate the count and mostly skip it.

The comparison everybody wants is in there, and it is smaller than the marketing on both sides implies. Within the reporting area, fraud rates on card transactions without authentication ran “twice as high in both value and volume terms” as on authenticated ones. Where the transaction was acquired outside the area, non-authenticated fraud ran 3 times higher by value and 4 times higher by volume. And the headline figure that I think is the most useful single number here: fraud rates for card payments were “about seventeen times higher when the counterpart was outside the EEA, where SCA may not be required, compared to domestic transactions”.

Seventeen times. Not seventeen per cent, seventeen times. If you take cross-border payments and you have been treating authentication as a conversion tax, that is the size of what it is buying.

Where the exempted traffic actually comes from

The same report breaks down remote card payments that skipped authentication, by reason, and the composition surprised me.

In the second half of 2024, transaction risk analysis accounted for 31 per cent of them. Merchant-initiated transactions accounted for 21 per cent. That category is worth more attention than its share suggests, because the report describes it as covering payments made against a mandate the customer set up earlier, where authentication is required when the mandate is granted rather than each time it is used, which means a subscription business pays the friction once at sign-up and a one-off business pays it on every order it cannot exempt. The structural difference is larger than any tuning either of them can do. Secure corporate protocols took 18 per cent, and low value took only 5 per cent, which is far less than I would have guessed for an exemption everybody talks about.

Then there is the remaining 25 per cent, reported as outside the scope of the rules altogether. The authorities are unusually direct about that one. The figure “remains high despite the clarifications provided in the EBA Q&As”, and it “warrants further investigation as to whether SCA requirements under PSD2 have been applied correctly”.

That is a regulator saying, in the politest available language, that a quarter of the exempted traffic may not be properly exempted at all. The footnote attached to it names the specific confusion, which is that mail order and telephone order payments genuinely do sit outside the requirement and have apparently been used as a filing category for things that do not, so some unknown part of that 25 per cent is a labelling problem inside reporting systems rather than a hole in anybody's authentication, and there is no way from the outside to tell which part is which. I do not know what happens to a merchant sitting downstream of that when it gets tidied up, and neither, I suspect, does the merchant. My guess is that it lands as a reporting change rather than as a rule change, and I would not defend that.

A digression about the word conversion

Nothing here helps your checkout, and I have been chewing on it for a fortnight.

We say authentication hurts conversion as though conversion were one number. The regulation splits the same traffic by value, the fraud rate is computed by value, and the exemption bands are value bands, so the entire machine thinks in money. Merchants, meanwhile, almost always look at conversion by count, because that is what the analytics package shows on the front page.

Those 2 views disagree about which transactions matter. A shop that loses 3 per cent of its orders to challenges may be losing 1 per cent of its money, or 8 per cent, and only one of those is a problem worth an engineering quarter. I have watched this argument happen with both sides quoting correct numbers at each other. Anyway, back to the practical part.

What I would actually do

Work out what share of your revenue sits in each band before you touch a setting. Orders under 30 euros, orders under 100, under 250, under 500, and the rest. That distribution is your exposure map. If 70 per cent of your orders sit under 100 euros while 60 per cent of your revenue sits above 250, then the band that matters to your finance director and the band that matters to your conversion dashboard are two different bands, and I would rather learn that from a spreadsheet in August than from an argument in November about why the authorisation rate moved. It takes an afternoon with an export.

Ask your provider 2 questions in writing. The first is what its current rolling 90 day fraud rate is for remote card payments. The second is whether it has ceased using the risk analysis exemption in any threshold band in the last year. Neither is a trade secret, both are audited, and the quality of the answer tells you a great deal about who you are dealing with.

Do not read a rise in challenges as your own failure. It may be the switch, thrown 2 quarters ago by traffic that never touched your site, and the fix in that case is a conversation with the provider rather than a change to your checkout.

Keep the exemption bands in mind when you price. Moving a 260 euro bundle to 245 does not change the rules that apply to it, since the band boundary sits at 250 and the rate demanded either side of it differs by a factor of 6. I am not suggesting you price a catalogue around a payments regulation. I am saying that if a price sits within a few euros of 100, 250 or 500, the cheaper side is quietly the easier one to authorise.

And separate this from your dispute ratio, which is a different machine with different numbers. Dispute monitoring runs monthly on counts and ratios at the card networks. This runs quarterly on value at your provider's regulator. The 2 systems can point in opposite directions in the same quarter, because a wave of disputes raises the ratio the networks watch while doing very little to the value-weighted fraud rate that decides your exemptions, and a single large fraudulent order can do exactly the reverse, moving the number your provider reports without registering at all in the count the networks are monitoring. Two dashboards, two verdicts, both correct. I have conflated them in conversation more than once and it produced confident nonsense both times.

What I could not find out

I cannot tell you how many customers abandon at the authentication step. I went looking for that number first, before any of the rest of this. No network publishes it, no acquirer publishes it, and the figures that circulate come from vendors selling something adjacent, with no method attached. I looked for a fortnight and found nothing I would put a number on in public, and that is the exact question in the headline, which is an uncomfortable place to end up.

I also cannot tell you what any of this means for a shop selling only inside the United States. The rules quoted here are European, the fraud data is European, and there is no equivalent published mandate or dataset on the American side. A US merchant selling into Europe is inside this machine whether or not anybody told them. A US merchant selling only domestically is looking at a neighbour's rulebook, which is still worth 20 minutes, because the American card networks watch what Europe measures and the European figures are the only published ones that address this question at all.

None of this is legal or compliance advice, and we are not your acquirer. The bands, the rates and the cessation rule are quoted from the regulation itself, and your own arrangements sit on top of them in ways only your provider can describe.

I keep thinking about the 25 per cent. A quarter of exempted remote card payments are reported as outside the scope of a rule that the authorities say probably covers them, the authorities have written that down in a public document, and nothing appears to have happened since. I do not know whether that resolves quietly through better reporting or arrives one morning as a step change in how often your customers get challenged. I would like to know which. I have asked 2 people who would know and neither would say.

Questions this raises

How does the 3D Secure liability shift work? A payment authenticated through the protocol moves the loss on a fraud dispute from you to the issuer. That is the trade the challenge buys, and it is why turning challenges down as far as your acquirer allows is not free: you keep more baskets and you also keep the losses on the ones that turn out to be fraud.

Which EMV 3DS exemptions can I actually use? The exemptions live with the party that asks for them, and in practice that is your provider rather than your checkout. Your leverage is the fraud rate that decides which band the provider sits in, and the rate is rolling, so today's basket affects challenges for the next ninety days.

Sources

  1. Commission Delegated Regulation (EU) 2018/389, regulatory technical standards on strong customer authentication: article 16 on low-value payments, article 18 and the annex for the transaction risk analysis thresholds and reference fraud rates, article 19 for the rolling 90 day calculation, article 20 for cessation of the exemption, article 3(2) for the audit requirement. eur-lex.europa.eu. Checked 4 August 2026.
  2. European Banking Authority and European Central Bank, 2025 report on payment fraud, covering six half-year periods to the end of 2024: the 1.3 billion euro card fraud figure and the 0.033 per cent rate, the share of transactions authenticated, the comparisons between authenticated and non-authenticated fraud rates, the seventeen times figure for counterparts outside the EEA, and the composition of exempted remote card payments. ecb.europa.eu. Read 4 August 2026.

Sourcing note: the thresholds and the cessation rule are quoted from the regulation itself rather than from a processor's summary of it. The fraud figures are European and cover payments with cards issued in the EU and EEA, so they describe that market and not the American one.