PSD2 / SCA

Strong customer authentication for every card payment — 3D Secure 2.x challenge flow, liability shift, SCA exemptions, and full audit evidence storage.

3DS2 authentication flow
1
Payment initiated · €129.00
2
3DS2 challenge · bank app
3
Customer authenticates
4
Payment authorized · liability shifted

3D Secure 2.x challenge flow.

Every card payment runs through 3D Secure 2.x. The flow starts with a frictionless device fingerprint check — if the issuer approves, no challenge is shown. If the risk score is high, a challenge (OTP, biometric, or app-based) is presented. Cronos handles the entire ACS interaction without redirecting away from the checkout.

Liability shift log
Transaction3DSLiability
#PAY-0041PassedIssuer
#PAY-0042PassedIssuer
#PAY-0043FrictionlessIssuer
#PAY-0044FailedMerchant

3DS success = issuer absorbs fraud chargebacks

Liability shift to the issuer.

When 3DS authentication succeeds, liability for fraud chargebacks shifts from the merchant to the card-issuing bank. Cronos stores the ECI value, CAVV, and XID — the three pieces of evidence required to prove liability shift in a chargeback dispute.

SCA exemptions

Low value

≤ €30

Risk-based analysis

Trusted beneficiary

Whitelist

Customer-added

Recurring

MIT

Same amount, schedule

Secure corporate

B2B

Dedicated channels

Exemption requested via Stripe — issuer may still enforce SCA

SCA exemptions for frictionless checkout.

PSD2 allows exemptions from strong customer authentication for low-value transactions (TRC), trusted beneficiaries, recurring payments (MIT), and corporate cards. Cronos requests the appropriate exemption per transaction to minimize friction while staying compliant.

3DS evidence storage

Transaction #PAY-0041

XIDd3f4a8e2···91c
CavvBAAAA···AAA
ECI05 (2.2.0)
Version2.2.0
Retained18 months

3DS result storage for audit.

The full 3DS authentication result — XID, CAVV, ECI value, authentication timestamp, and 3DS version — is stored per transaction for 18 months. This evidence is available on demand for chargeback disputes, acquirer audits, and PSD2 compliance reviews.

Merchant-initiated transactions
Initial paymentSCA applied

Customer authenticates · mandate created

Recurring charge #1No SCA needed

Aug 1 · €29.00 · MIT exemption

Recurring charge #2No SCA needed

Sep 1 · €29.00 · MIT exemption

Merchant-initiated transactions (MIT).

For recurring payments like subscriptions, SCA is performed on the first payment only. Subsequent charges reuse the stored 3DS result as a merchant-initiated transaction. The cardholder consent is recorded and stored, enabling frictionless renewals without re-authentication.

Refusal reason mapping
200Do not honor

Issuer declined · retry with 3DS challenge

401Authentication required

SCA mandated · 3DS2 challenge triggered

402Exemption rejected

Issuer enforced SCA · fallback to 3DS

481SCA not performed

Merchant liability · no shift possible

SCA refusal and fallback handling.

When 3DS authentication fails — cardholder rejects the challenge, times out, or the ACS is unavailable — Cronos captures the specific refusal reason code and automatically retries with a fallback strategy. The customer sees a clear error message and can try an alternative payment method.

Frequently asked questions

What is PSD2 and why does it require strong customer authentication?

PSD2 (Payment Services Directive 2) is EU regulation that requires strong customer authentication (SCA) for most electronic payments. SCA means using two or more independent factors: something the customer knows (password), has (phone), or is (biometric). The goal is to reduce fraud in online payments.

What is 3D Secure 2.x and how is it different from 3DS 1.0?

3D Secure 2.x is the protocol that implements SCA for card payments. Unlike 3DS 1.0, which redirected the customer to a bank page, 3DS 2.x performs a background device fingerprint check first. If the risk is low, the payment is frictionless — no challenge shown. Only high-risk payments trigger a challenge.

When does liability shift to the issuing bank?

When 3DS authentication completes successfully, liability for fraud chargebacks shifts from the merchant to the card-issuing bank. Cronos stores the ECI value, CAVV, and XID as proof. If a chargeback dispute arises, this evidence proves the shift applies.

Which transactions are exempt from SCA?

PSD2 allows exemptions for low-value transactions (under €30), trusted beneficiaries (whitelisted merchants), recurring payments (MIT), and corporate card payments. Cronos requests the appropriate exemption per transaction to reduce friction while maintaining compliance.

How are recurring subscription payments handled?

SCA is performed on the first payment of a subscription. The customer authenticates once and grants consent for future charges. Subsequent payments are merchant-initiated transactions (MIT) that reuse the stored 3DS result — no additional authentication needed for renewals.

What happens if the customer fails the 3DS challenge?

The payment is declined with a specific refusal reason code (e.g., challenge rejected, timeout, ACS error). Cronos shows a clear error message and offers alternative payment methods. The failed attempt is logged with the reason code for audit purposes.

How long are 3DS results stored?

3DS authentication results — XID, CAVV, ECI value, timestamp, and version — are stored for 18 months per transaction. This covers the typical chargeback dispute window and PSD2 audit requirements.

Does Cronos support 3DS for non-EU cards?

Yes. 3DS is applied to all card payments regardless of origin. For non-EU cards that are not enrolled in 3DS, the payment proceeds without SCA but without liability shift. The transaction is flagged accordingly in the records.

← All compliance