HomeFrameworksInformation Security & Privacy3-DS

Framework  Information Security & Privacy

3-DS

The PCI 3DS Core Security Standard governs the security of the three server-side components that run EMV 3-D Secure card authentication: the Access Control Server (ACS) on the issuer side, the Directory Server (DS) operated by the card brands, and the 3DS Server on the merchant or acquirer side.

It applies to any company that provides an environment where those functions are performed. A separate PCI 3DS SDK Security Standard covered merchant app SDKs; PCI SSC announced a sunset period for the SDK standard from May 1 to October 31, 2026, so check the Council site before relying on it.

The standard has two parts: baseline security requirements for the environment and 3DS-specific requirements for the functions themselves. In writing, a 3DS entity needs documented security policies, a defined 3DS environment and data flows, key management procedures, change and access control procedures, incident response, and evidence for each requirement.

Compliance obligations and deadlines are set by the payment brands, not by PCI SSC, and the Council does not publish a list of assessed 3DS entities.

AI-compiled
Share
Sponsored
3-DS
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with 3-DS
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Entities that provide or host ACS, DS or 3DS Server functions, including issuer processors, acquirer processors, payment gateways and the card brands' directory operators. The trigger is the payment brand compliance program or a contractual requirement from a brand or acquirer.

What the assessor asks to see

3DS environment scope, network and data flow diagrams; inventory of ACS, DS or 3DS Server systems; security policies and procedures; cryptographic key management procedures and key custodian records; access control and MFA evidence; change management records; logging and monitoring evidence; vulnerability management and penetration test results; incident response plan; prior ROC or AOC.

3DS SDK standard sunset

PCI SSC announced a formal sunset period for the PCI 3DS SDK Security Standard running May 1 to October 31, 2026. The Core standard for ACS, DS and 3DS Server environments continues. Verify the current status and version numbers in the PCI SSC document library.

Assessors

Who assesses 3-DS

A PCI SSC qualified 3DS Assessor company with qualified 3DS assessor employees, performing the assessment per the 3DS Assessor Program Guide and producing a Report on Compliance and Attestation of Compliance. Accredited by PCI Security Standards Council qualification (not a national accreditation body).

Public register of assessors: https://www.pcisecuritystandards.org/assessors_and_solutions/3ds_assessors/

No firm has claimed a 3-DS assessor listing yet. Claim yours →

Consultants

Who helps with 3-DS

A niche readiness ecosystem exists among PCI QSA companies that also hold 3DS Assessor status: scoping the 3DS environment, gap assessments, key management design and evidence preparation. Engagements are usually a readiness phase followed by the formal assessment.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a 3-DS consultant listing yet. Claim yours →

Software

Tools for 3-DS

Tools that name this framework in their own material.

No firm has claimed a 3-DS tool listing yet. Claim yours →

Related reading

  1. 3D Secure authenticationExplains the protocol the PCI 3DS standard secures: the three domains, frictionless flow and the liability shift.Stripe

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for 3-DS

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with 3-DS

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

[email protected]
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

[email protected]
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.