PCI 3DS Compliance UK – the Ultimate Guide

PCI 3DS Assessor logo

What is PCI 3DS Compliance (UK)?

PCI 3DS compliance (UK) is achieved through adhering to the requirements of the PCI 3DS standard. This ensures that businesses implement the 3D Secure protocol to enhance the security of online payments.

What is PCI 3DS?

PCI 3DS is a security protocol for online credit and debit card transactions. It’s designed to add an extra layer of security when making online payments to reduce the risk of fraudulent transactions, because it allows the cardholder to verify their identity.

This reduces payment fraud, which in turn reduces the amount of merchant chargebacks (claims that the payment transaction did not take place) and helps minimise unauthorised card transactions.

By incorporating 3DS (3-D Secure) into their operations, payment service providers (PSPs) can expect a decrease in card fraud incidents, because cardholders are required to take additional authentication steps before finalising their payments.

The most recent iteration of 3-D Secure, known as 3DS2 (3-D Security 2.0), seamlessly integrates with the card transaction process. Only when suspicious or unfamiliar activities are detected will a transaction be earmarked for authentication.

This means that cardholders will not be redirected to their respective banks for authentication. Instead, they can conveniently verify their identity through methods like text messages or confirmation codes via a dedicated app.

PCI 3DS vs PCI DSS

PCI DSS (Payment Card Industry Data Security Standard) focuses on securing cardholder data by setting guidelines for how businesses handle, process, and store payment information. It applies to any organisation that processes credit card payments.

PCI 3DS (3D Secure) is a security protocol specifically designed for online payments. It adds an extra layer of authentication (like a password or biometric verification) to reduce fraud and improve transaction security. While PCI DSS covers general payment security, PCI 3DS is focused on authentication during online transactions.

What is the PCI SSC

PCI SSC stands for the PCI Security Standards Council. This is a global organisation founded by major payment card companies American Express, Discover Financial Services, JCB International, MasterCard and Visa Inc. on September 7, 2006. It develops and maintains security standards for payment card transactions, including PCI DSS (Data Security Standard) and PCI 3DS (3D Secure). 

Why is PCI 3DS important?

  • PCI 3DS adds an extra layer of security to prevent fraud. It ensures that only authorised users complete online transactions, decreasing the risk of fraudulent charges.
  • PCI 3DS helps organisations comply with other regulations.
  • The authentication process shifts liability for fraudulent transactions to the card issuer, protecting merchants from chargeback risks.
  • Transactions processed with PCI 3DS are more likely to be approved since they are seen as more secure by payment processors.
  • PCI 3DS compliance signals to customers that their data is secure, improving confidence and trust in your organisation.  

What does it mean to be a 3DS Assessor?

A 3DS Assessor is an individual who is authorised and certified to conduct PCI 3DS Assessments, validate and attest to an entity’s PCI 3DS Core Security Standard compliance status, and prepare appropriate compliance reports (such as Reports on Compliance (RoC)) required by payment card brands and acquiring banks. Securious is a qualified 3DS Assessor Company.

Steps to Achieve PCI 3DS Compliance UK:

  1. Get in touch with a PCI 3DS assessor: PCI 3DS assessors are required to assess compliance and ensure your systems meet all necessary security requirements. In the UK, Securious is one of only five PCI 3DS assessors.
  2. Conduct a PCI 3DS Assessment: The assessor will examine your systems to ensure they meet PCI 3DS compliance UK standards.
  3. Prepare Reports on Compliance (RoC): After the assessment your assessor will prepare a Report on Compliance (RoC). This report may be required by payment card brands or acquiring banks and will detail your security posture, confirming that your systems meet PCI 3DS compliance UK standards.
  4. Ongoing Maintenance and Monitoring: Compliance is not a one-time event. Regular assessments and updates are necessary to keep your systems compliant as standards evolve and security threats change.

Benefits of PCI 3DS Compliance UK:

  • Enhanced Security for Online Transactions – 3DS adds an extra layer of authentication during online transactions, reducing the risk of unauthorised transactions and providing reassurance for both businesses and customers.
  • Reduced Fraud and Chargebacks – with 3DS, cardholders are required to authenticate themselves, minimising the likelihood of fraud. This also reduces chargebacks and associated fees, as the liability for fraud shifts to the card issuer.
  • Increased Customer Confidence – displaying 3DS certification can build trust with customers, as they know their transactions are secure. This can improve customer confidence in your platform and reduce the likelihood of abandoned carts.
  • Compliance with Payment Regulations – many regions, including the EU, require strong customer authentication for online payments under regulations like PSD2. 3DS helps businesses meet these regulatory requirements, avoiding fines and potential restrictions on payment capabilities.
  • Higher Transaction Approval Rates – some payment providers are more likely to approve transactions that use 3DS, which can lead to fewer declined payments and, consequently, increased sales and customer satisfaction.
  • Improved Dispute Resolution – in the event of a chargeback dispute, transactions that have been processed through 3DS often favour the merchant. This certification acts as evidence of additional security steps taken during the transaction.

How Securious can help you with PCI 3DS UK compliance

Securious has a team of qualified, experienced PCI DSS QSA and PCI 3DS assessors who can help you achieve and maintain compliance with the latest PCI DSS and PCI 3DS standards.

We are one of only 5 PCI 3DS Assessors in the UK, and are the only PCI DSS QSA in the region (we are based in Exeter, Devon).

We can help you ensure that your systems and processes comply with the PCI 3DS standard. This is essential for merchants and payment processors that wish to offer secure 3DS authentication for online transactions.

Get in touch to get started now

Fill in the form below, email pci@securious.co.uk or call us on +44 (0)1392 247 110 to learn more.

We can provide an initial 90-minute consultation with a PCI 3DS Assessor.

Prices for this are from £295 (+ vat).

If you go ahead with a PCI 3DS service, the £295 will be deducted from the cost of your engagement.