Framework Information Security & Privacy
3-DS
The PCI 3DS Core Security Standard governs the security of the three server-side components that run EMV 3-D Secure card authentication: the Access Control Server (ACS) on the issuer side, the Directory Server (DS) operated by the card brands, and the 3DS Server on the merchant or acquirer side.
It applies to any company that provides an environment where those functions are performed. A separate PCI 3DS SDK Security Standard covered merchant app SDKs; PCI SSC announced a sunset period for the SDK standard from May 1 to October 31, 2026, so check the Council site before relying on it.
The standard has two parts: baseline security requirements for the environment and 3DS-specific requirements for the functions themselves. In writing, a 3DS entity needs documented security policies, a defined 3DS environment and data flows, key management procedures, change and access control procedures, incident response, and evidence for each requirement.
Compliance obligations and deadlines are set by the payment brands, not by PCI SSC, and the Council does not publish a list of assessed 3DS entities.
help
Who has to comply
Entities that provide or host ACS, DS or 3DS Server functions, including issuer processors, acquirer processors, payment gateways and the card brands' directory operators. The trigger is the payment brand compliance program or a contractual requirement from a brand or acquirer.
What the assessor asks to see
3DS environment scope, network and data flow diagrams; inventory of ACS, DS or 3DS Server systems; security policies and procedures; cryptographic key management procedures and key custodian records; access control and MFA evidence; change management records; logging and monitoring evidence; vulnerability management and penetration test results; incident response plan; prior ROC or AOC.
3DS SDK standard sunset
PCI SSC announced a formal sunset period for the PCI 3DS SDK Security Standard running May 1 to October 31, 2026. The Core standard for ACS, DS and 3DS Server environments continues. Verify the current status and version numbers in the PCI SSC document library.
Assessors
Who assesses 3-DS
A PCI SSC qualified 3DS Assessor company with qualified 3DS assessor employees, performing the assessment per the 3DS Assessor Program Guide and producing a Report on Compliance and Attestation of Compliance. Accredited by PCI Security Standards Council qualification (not a national accreditation body).
Public register of assessors: https://www.pcisecuritystandards.org/assessors_and_solutions/3ds_assessors/
No firm has claimed a 3-DS assessor listing yet. Claim yours →
Consultants
Who helps with 3-DS
A niche readiness ecosystem exists among PCI QSA companies that also hold 3DS Assessor status: scoping the 3DS environment, gap assessments, key management design and evidence preparation. Engagements are usually a readiness phase followed by the formal assessment.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a 3-DS consultant listing yet. Claim yours →
Software
Tools for 3-DS
Tools that name this framework in their own material.
No firm has claimed a 3-DS tool listing yet. Claim yours →
Related reading
- 3D Secure authenticationExplains the protocol the PCI 3DS standard secures: the three domains, frictionless flow and the liability shift.Stripe
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for 3-DS
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with 3-DS
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.