iGamingPayments.AI
Payments·9 min read

3D Secure and SCA for iGaming Payments Explained

Christian Hodges
Christian Hodges
22 July 2026
3D Secure authentication check on an iGaming card deposit

Every card deposit a player makes at an EU or UK iGaming site has to clear an authentication check before the money moves. That check is Strong Customer Authentication, and the technology that runs it on card payments is 3D Secure.

Get it right and it's invisible: the player taps their bank app, the deposit lands, fraud liability shifts off your books. Get it wrong and it becomes the single biggest source of failed deposits an operator has - a friction step that pushes players to abandon before they've funded an account.

This guide covers what 3D Secure and SCA actually are, how they interact, which exemptions an operator can use, and where the money leaks. Facts verified as of July 2026.

What is Strong Customer Authentication (SCA)?

Strong Customer Authentication is a European legal requirement to verify a payer with at least two independent factors before an electronic payment goes through. It applies to remote card deposits at iGaming sites in the EU and UK.

Term: Strong Customer Authentication. Definition: A regulatory rule requiring two or more independent authentication factors - knowledge, possession or inherence - to approve most electronic payments in the EU and UK.

The two factors have to come from different categories: something the player knows (a password or PIN), something they have (a phone or card reader), or something they are (a fingerprint or face scan). Two passwords don't count. Neither does a password plus a security question, because both are knowledge.

SCA sits inside the EU's second Payment Services Directive (PSD2) and is spelled out in the technical rules that support it, Commission Delegated Regulation (EU) 2018/389 - the Regulatory Technical Standards, or RTS, on strong customer authentication. In the UK, the same rules were retained after Brexit and are supervised by the Financial Conduct Authority.

For a gambling operator, the practical translation is simple: a card deposit from a player in scope needs SCA unless a specific exemption applies. Withdrawals paid back to a card are payouts, not payer-initiated payments, so they sit outside SCA.

What is 3D Secure and how does it work?

3D Secure is the messaging protocol that lets a merchant, the card schemes and the cardholder's bank run an authentication check during an online card payment. On modern cards it's the mechanism operators use to satisfy SCA.

The current version is EMV 3DS, often called 3D Secure 2, published by EMVCo - the body jointly owned by Visa, Mastercard, American Express, Discover, JCB and UnionPay. It replaced the original 3DS 1, the clunky pop-up password page most people remember from a decade ago.

Here's the flow on a deposit. When the player hits pay, the operator's 3DS server sends a package of transaction data to the card scheme's directory server, which passes it to the issuing bank's Access Control Server. That data set runs to over 100 fields - device, amount, history, behaviour. The bank scores it in milliseconds and picks one of two paths:

The frictionless path is the whole point of the 2.0 rebuild. The more data the operator sends, the more often the bank waves the payment through without a challenge. Thin data forces challenges, and every challenge is a chance for the player to give up.

How does 3D Secure affect iGaming approval rates?

3D Secure moves approval rates in both directions. Done well, it lifts them by shifting fraud liability and building issuer trust. Done badly, it drops deposits at the challenge screen - the biggest avoidable leak on the deposit funnel.

iGaming feels this harder than most sectors. Gambling deposits already carry a high-risk merchant category code, so issuers are quicker to trigger a challenge and quicker to decline when authentication stumbles. A player funding an account at 11pm on a phone is exactly the profile a bank scrutinises.

The failure points are mundane but expensive. A challenge that renders badly on mobile. An SMS one-time passcode that never arrives. A player who doesn't recognise the merchant name and abandons mid-flow. Each one is a funded account that didn't happen. You can put a number on what recovering those deposits is worth with our approval rate uplift calculator.

My view, after years of watching these funnels: most operators blame the issuer when the real problem is the data they're sending into 3DS. Rich, accurate transaction data is what earns frictionless flow, and frictionless flow is where the approval rate lives.

Does 3D Secure shift chargeback liability?

Yes, for one category of dispute. When a transaction is successfully authenticated through 3D Secure, liability for fraud-based chargebacks moves from the operator to the issuing bank. It does nothing for non-fraud disputes.

Term: liability shift. Definition: The transfer of financial responsibility for a fraudulent-transaction chargeback from the merchant to the card issuer when a payment has been authenticated through 3D Secure.

The shift only applies when authentication actually succeeds. If it fails, errors out, or was never attempted, the chargeback stays with you. And it covers unauthorised-transaction disputes only - the "I never made this payment" reason codes. It does not touch friendly fraud dressed up as something else, or a player disputing gambling losses.

That's why 3D Secure is one lever, not the answer. The full picture on disputes, including the Visa and Mastercard monitoring thresholds, sits in our guide to cutting iGaming chargebacks.

What SCA exemptions can iGaming operators use?

SCA has built-in exemptions that let a payment skip the challenge while staying compliant. Used well, they recover the deposits that friction would have cost you. The two that matter most for gambling are transaction risk analysis and the low-value exemption.

Transaction risk analysis (TRA) lets a payment provider skip SCA on lower-value payments when its fraud rate stays under set thresholds. The RTS ties the value ceiling to the provider's fraud performance: up to EUR 100 at a fraud rate below 0.13%, up to EUR 250 below 0.06%, and up to EUR 500 below 0.01%. Cleaner fraud numbers buy a higher exemption ceiling.

The low-value exemption covers remote payments under EUR 30 (around GBP 30 in the UK), with two guard rails: SCA must kick back in once the running total since the last authentication passes EUR 100, or after five consecutive exempt payments, whichever comes first.

Two points operators miss. First, the exemption is requested by the acquirer but granted by the issuer - the bank can override you and challenge anyway. Second, dynamic linking still applies: even on an exempt or authenticated payment, the authentication code has to be tied to the exact amount and payee, so the details can't be altered in transit.

The Visa PSD2 SCA Regulatory Guide sets out how each exemption is flagged in the authorisation message. Getting exemption strategy right is a job for an orchestration layer, which brings me to the routing point.

3D Secure vs open banking: which is better for deposits?

They solve the same SCA obligation in different ways. 3D Secure adds an authentication step on top of a card payment; open banking is authentication-native, because the player approves the payment inside their own bank app from the start.

For iGaming, that difference matters. Open banking deposits carry no separate 3DS challenge, settle fast, and report approval rates above 90% because there's no issuer second-guessing a card transaction. There are no chargebacks either, since the player has authorised a bank transfer, not a card charge.

The trade-off is coverage and habit. Cards are still what most players reach for, and card rails support instant withdrawals in ways account-to-account payments don't always match. My honest read: this isn't 3DS versus open banking, it's both. Offer open banking as a first-class option and treat 3D Secure as the card path that has to be tuned. Our guide to open banking for iGaming covers where account-to-account earns its place.

When does SCA apply to cross-border iGaming payments?

SCA is mandatory only when both the player's bank and the operator's acquirer sit inside the EU or UK. When one side is outside that zone - a "one-leg-out" transaction - SCA is best-efforts, not required.

This shapes routing decisions more than most operators realise. A deposit from an EU player through an EU-licensed acquirer is fully in scope. The same player paying through an offshore acquirer may not trigger a mandatory challenge, but the issuer can still decline an unauthenticated gambling transaction it doesn't like the look of.

There's also the road ahead. The EU's payments package - PSD3 and the accompanying Payment Services Regulation, first proposed in June 2023 - reached provisional political agreement between the Parliament and Council in late 2025, with the texts published in 2026. The direction of travel tightens SCA and extends fraud protections rather than loosening them, so operators building for the next few years should plan for authentication to get stricter, not lighter. Exact application dates are still being confirmed, so treat that as the trajectory, not a fixed deadline.

Where routing meets all of this is payment orchestration: a layer that decides which acquirer, which exemption and which authentication path each deposit takes. For choosing providers that handle SCA properly market by market, the iGamingPayments.ai directory filters PSPs by region and method, and the payments glossary defines the surrounding terms.

Key Takeaways

  • SCA requires two independent authentication factors on most EU and UK card deposits; 3D Secure is how cards satisfy it
  • EMV 3DS (3D Secure 2) picks between a silent frictionless path and a challenge - richer transaction data earns more frictionless approvals
  • A successful 3DS authentication shifts fraud-chargeback liability to the issuer, but only for unauthorised-transaction disputes
  • Transaction risk analysis and the sub-EUR 30 low-value exemption let compliant deposits skip the challenge and recover lost conversions
  • Exemptions are requested by the acquirer but granted by the issuer, which can still challenge; dynamic linking always applies
  • Open banking sidesteps the 3DS challenge entirely, and cross-border "one-leg-out" deposits fall outside mandatory SCA

Frequently asked questions

Is 3D Secure mandatory for iGaming card deposits?

Where both the player's bank and the operator's acquirer are in the EU or UK, SCA is mandatory and 3D Secure is the standard way to meet it on card payments. An operator can apply exemptions to skip the challenge on qualifying deposits, but the underlying authentication obligation still applies unless the transaction is out of scope.

Can I turn off 3D Secure to reduce friction?

Not for in-scope deposits. Sending an unauthenticated payment where SCA is required usually gets it declined by the issuer, so switching 3DS off tends to cut approvals rather than raise them. The right move is exemption strategy and cleaner data, not skipping authentication.

What happens if a player fails a 3D Secure challenge?

The deposit is declined and the money doesn't move. The player can retry, but a failed authentication is a common abandonment point, which is why frictionless flow and working challenge delivery matter so much to deposit conversion.

Does 3D Secure apply to withdrawals?

No. SCA applies to payer-initiated payments, and a withdrawal paid back to a player's card is a payout initiated by the operator, not the player. Withdrawal speed and method are their own problem, covered in our withdrawal processing guide.

Is 3D Secure the same as PSD2 SCA?

They're related but not identical. SCA is the legal requirement under PSD2 to authenticate with two factors; 3D Secure is the technical protocol that delivers that authentication on card transactions. You use 3DS to comply with SCA, but SCA also covers non-card payments like open banking.

Do 3D Secure exemptions work for high-risk gambling merchants?

They can, but issuers scrutinise gambling deposits more closely, so a requested exemption is more likely to be overridden with a challenge than it would be for low-risk retail. Keeping fraud rates low is what protects access to the transaction risk analysis exemption at higher value ceilings.

Does open banking need 3D Secure?

No. Open banking payments are authenticated inside the player's own banking app when they approve the transfer, so they meet SCA without a separate 3D Secure step. That's part of why open banking deposits report higher approval rates and no chargebacks.

Christian Hodges
Christian Hodges

Christian Hodges has worked in payments and iGaming since 2010. He is the Founder of iGamingPayments.ai, an independent marketplace connecting operators with payment infrastructure, and the creator of the iGaming Roundtable Network, a community of over 850 senior industry professionals. He also acts as a fractional commercial strategist for iGaming suppliers.

iGamingPayments.AI

Find the right payment provider for your operation

Browse 342+ vetted PSPs, crypto processors, open banking providers and fraud vendors - filtered by region, vertical and payment method. Or run the numbers before your next PSP negotiation.

Browse the directoryUse the calculator
Back to News