PSD2 / SCA
Strong customer authentication for every card payment — 3D Secure 2.x challenge flow, liability shift, SCA exemptions, and full audit evidence storage.
3D Secure 2.x challenge flow.
Every card payment runs through 3D Secure 2.x. The flow starts with a frictionless device fingerprint check — if the issuer approves, no challenge is shown. If the risk score is high, a challenge (OTP, biometric, or app-based) is presented. Cronos handles the entire ACS interaction without redirecting away from the checkout.
3DS success = issuer absorbs fraud chargebacks
Liability shift to the issuer.
When 3DS authentication succeeds, liability for fraud chargebacks shifts from the merchant to the card-issuing bank. Cronos stores the ECI value, CAVV, and XID — the three pieces of evidence required to prove liability shift in a chargeback dispute.
Low value
≤ €30
Risk-based analysis
Trusted beneficiary
Whitelist
Customer-added
Recurring
MIT
Same amount, schedule
Secure corporate
B2B
Dedicated channels
Exemption requested via Stripe — issuer may still enforce SCA
SCA exemptions for frictionless checkout.
PSD2 allows exemptions from strong customer authentication for low-value transactions (TRC), trusted beneficiaries, recurring payments (MIT), and corporate cards. Cronos requests the appropriate exemption per transaction to minimize friction while staying compliant.
Transaction #PAY-0041
3DS result storage for audit.
The full 3DS authentication result — XID, CAVV, ECI value, authentication timestamp, and 3DS version — is stored per transaction for 18 months. This evidence is available on demand for chargeback disputes, acquirer audits, and PSD2 compliance reviews.
Customer authenticates · mandate created
Aug 1 · €29.00 · MIT exemption
Sep 1 · €29.00 · MIT exemption
Merchant-initiated transactions (MIT).
For recurring payments like subscriptions, SCA is performed on the first payment only. Subsequent charges reuse the stored 3DS result as a merchant-initiated transaction. The cardholder consent is recorded and stored, enabling frictionless renewals without re-authentication.
Issuer declined · retry with 3DS challenge
SCA mandated · 3DS2 challenge triggered
Issuer enforced SCA · fallback to 3DS
Merchant liability · no shift possible
SCA refusal and fallback handling.
When 3DS authentication fails — cardholder rejects the challenge, times out, or the ACS is unavailable — Cronos captures the specific refusal reason code and automatically retries with a fallback strategy. The customer sees a clear error message and can try an alternative payment method.
Frequently asked questions
What is PSD2 and why does it require strong customer authentication?
PSD2 (Payment Services Directive 2) is EU regulation that requires strong customer authentication (SCA) for most electronic payments. SCA means using two or more independent factors: something the customer knows (password), has (phone), or is (biometric). The goal is to reduce fraud in online payments.
What is 3D Secure 2.x and how is it different from 3DS 1.0?
3D Secure 2.x is the protocol that implements SCA for card payments. Unlike 3DS 1.0, which redirected the customer to a bank page, 3DS 2.x performs a background device fingerprint check first. If the risk is low, the payment is frictionless — no challenge shown. Only high-risk payments trigger a challenge.
When does liability shift to the issuing bank?
When 3DS authentication completes successfully, liability for fraud chargebacks shifts from the merchant to the card-issuing bank. Cronos stores the ECI value, CAVV, and XID as proof. If a chargeback dispute arises, this evidence proves the shift applies.
Which transactions are exempt from SCA?
PSD2 allows exemptions for low-value transactions (under €30), trusted beneficiaries (whitelisted merchants), recurring payments (MIT), and corporate card payments. Cronos requests the appropriate exemption per transaction to reduce friction while maintaining compliance.
How are recurring subscription payments handled?
SCA is performed on the first payment of a subscription. The customer authenticates once and grants consent for future charges. Subsequent payments are merchant-initiated transactions (MIT) that reuse the stored 3DS result — no additional authentication needed for renewals.
What happens if the customer fails the 3DS challenge?
The payment is declined with a specific refusal reason code (e.g., challenge rejected, timeout, ACS error). Cronos shows a clear error message and offers alternative payment methods. The failed attempt is logged with the reason code for audit purposes.
How long are 3DS results stored?
3DS authentication results — XID, CAVV, ECI value, timestamp, and version — are stored for 18 months per transaction. This covers the typical chargeback dispute window and PSD2 audit requirements.
Does Cronos support 3DS for non-EU cards?
Yes. 3DS is applied to all card payments regardless of origin. For non-EU cards that are not enrolled in 3DS, the payment proceeds without SCA but without liability shift. The transaction is flagged accordingly in the records.