Flexible 3DS authentication in the DECTA gateway gives payments product managers at PSPs and acquirers a way to assess EMV 3DS 2.3.1.1 against older implementations. This article covers the certification, security, approval rate, and compliance criteria worth considering.
July 01, 2025
For payment service providers and acquirers seeking competitive advantage, DECTA's configurable 3D Secure authentication stands out for superior security, enhanced performance metrics, and significant operational benefits.
As one of the first European processors to achieve EMV 3DS 2.3.1.1 certification, DECTA offers authentication capabilities that outperform traditional implementations while reducing costs and complexity.
News: DECTA Achieves Early Certification for EMV 3DS 2.3.1.1 Protocol with Mastercard
DECTA implements the EMV 3DS 2.3.1.1 protocol to support secure, modern payment authentication. The following sections outline DECTA's certification, data intelligence, and risk assessment capabilities with this latest protocol version.
Industry-Leading Certification Achievement
As one of the first payment processors in Europe to gain this capability, DECTA ensures PCI DSS Level 1 standards for merchant solutions. PCI DSS Level 1 is the highest of the four card industry compliance tiers and applies to processors handling the largest transaction volumes, so it is the level most PSP and acquirer procurement checklists ask for by name.
This certification provides PSPs and acquirers with a competitive edge.
Superior Data Intelligence and Risk Assessment
EMV 3DS 2.3.1.1 is the latest payment authentication version, offering, compared to earlier releases, enhanced data exchanges, superior risk assessment capabilities, and increased accommodations associated with newer authentication options such as biometric verification and Secure Payment Confirmation (SPC).
Secure Payment Confirmation (SPC): a browser-level standard that lets a cardholder confirm a payment with a device biometric instead of a redirect to the issuer's challenge page.
While older 3DS versions utilize minimal data points for payment authentication, DECTA operates on the full-featured options afforded by the 3DS 2.x protocol to create more comprehensive risk assessment opportunities and real-time decisions.
The risk signals the protocol carries include:
Device fingerprinting
Transaction history
Pattern recognition
Geographic risk factors
Temporal risk factors
Merchant-specific risk profiles
Customer authentication preferences
This allows DECTA to achieve a much higher threshold for frictionless authentication without losing any real-time fraud detection ability.
Frictionless flow: the issuer approves on the data alone and the cardholder sees nothing.
Challenge flow: the cardholder is asked to confirm.
The share of transactions that clear frictionlessly is the single number that separates one 3DS authentication solution from another, because every challenge is a point where a buyer can drop out.
Key Benefits of Flexible 3D Secure Authentication for Businesses
Transaction history and device fingerprinting, which identify the browser or handset behind a transaction and flag when a familiar card appears on an unfamiliar device
Real-time fraud detection using machine learning algorithms
Liability shift from merchants to issuer banks, which moves the chargeback cost of fraudulent authenticated transactions off the merchant and is the commercial reason merchants accept any authentication friction at all
Risk scoring and fraud mitigation logic at both authorization-level and transaction-level fraud management
Improved Transaction Approval Rates and Fewer False Declines
DECTA's 3DS enables greater approval rates by providing cardholder issuers with additional data, reducing false declines and supporting real-time authentication with low-friction challenge flow and frictionless flow.
Regulatory Compliance
EMV 3DS 2.3.1.1 authentication at DECTA achieves compliance with PSD2, the EU regulation that makes Strong Customer Authentication (SCA) mandatory for most online card payments, and with the European Banking Authority (EBA) technical standards that define how SCA is applied.
It also supports the SCA exemptions that let a transaction skip the challenge legally: low-value payments, transaction risk analysis, where a provider's own fraud rate determines the exemption ceiling it can claim, and recurring payments.
Minimizing authentication steps for low-risk transactions
Ensuring a seamless user experience
Reducing average authentication time
White-Label Customization Capabilities
With DECTA's white-label payment gateway, merchants, PSPs, and acquirers can offer white-label 3DS authentication under their own brand, so the authentication screen never breaks the checkout experience with a third party's name on it. Branded authentication covers:
Consistent user interface (UI) design
Control over authentication screens based on transaction type
Application ecosystem integration
Customizable customer-facing elements
Technical Architecture and Integration Advantages
DECTA's technical architecture is designed for EMV 3DS integration across issuer and acquirer services. The sections below set out the integration methods and support for advanced authentication flows.
3DS Authentication Architecture
DECTA's platform provides 3D Secure v2.2 support for issuer services and acquirer services, complying with PSD2 SCA and integrating with a wide range of card systems, payment methods, and acquirer processing options.
Integration Options for 3DS Authentication
DECTA's white-label payment gateway supports:
Hosted Payment Page, where the gateway hosts the checkout and authentication entirely, keeping card data off the merchant's servers
iFrame integration, which keeps the checkout inside the merchant's own page while the gateway handles the card fields
Direct Post, which sends card data straight from the browser to the gateway and reduces PCI scope
API integration
E-commerce plugins
SOAP integration
All integrations are PCI DSS-compliant and compatible with digital wallets, including Apple Pay, Google Pay, Samsung Pay, and Garmin Pay.
Those wallets carry their own tokenized authentication path rather than a standard challenge screen.
Acquirer-Side 3DS Implementation
DECTA applies the latest 3DS 2.x protocol for acquirer processing, supporting SCA exemptions, challenge flow, frictionless flow, tokenization, EMV tokenization, and secure cardholder data handling during transaction processing.
EMV tokenization: replaces the card number with a scheme-issued token so the real number is never exposed during authentication or processing.
Fraud monitoring and risk scoring are integrated at both authorization and transaction levels.
Issuer-Side 3DS Implementation
DECTA offers issuer banks 3DS v2.2 support, meeting Mastercard and Visa requirements.
Authentication flows support in-band and out-of-band (OOB) authentication, push notifications, SMS notifications, biometric authentication apps (iOS, Android), card registration, smartphone registration, and card lifecycle management via issuing API.
Out-of-band (OOB) authentication: the cardholder confirms in a separate banking app rather than on the checkout page, which is the mechanism behind biometric approval and Mastercard's biometric prompt requirements.
APIs allow rapid integration and token provisioning for digital wallets, with extensive API documentation available.
Testing, Security, and Compliance
Sandbox environment for full testing parity with live services and API documentation at dapidocs.decta.com, so authentication flows can be tested end to end before any integration is committed
PCI DSS Level 1 infrastructure for all payment authentication and processing
EMV tokenization for cardholder data security
24/7 technical support
Built-in fraud monitoring and fraud reporting tools
With DECTA's EMV 3DS 2.3.1.1, businesses achieve security, compliance, customer satisfaction, and higher conversion rates in online payments and mobile payments.
Talk to DECTA About Your Setup
DECTA works with PSPs, acquirers, and issuers on payment authentication, processing, and compliance across Europe and APAC.