Isometric illustration of a card payment passing through a secure tunnel and a checkpoint, representing PCI DSS and 3-D Secure.
Technology

PCI DSS and 3-D Secure in plain language: what they are and why they protect you

PCI DSS is the global security standard for anyone who handles card data; 3-D Secure is the extra verification step where your customer confirms an online payment. One protects the data, the other the transaction. As a business you do not have to build either yourself: what you mostly notice is that card data does not touch your own systems and that fraud and chargebacks go down.

PCI DSS: the lock on the card data

PCI DSS (Payment Card Industry Data Security Standard) is the standard the card industry itself drew up for securely handling, storing and sending card data. Picture a building where that data sits: PCI DSS prescribes the walls, the locks, the cameras and the key register, and decides who may enter and how it is logged. Everyone in the chain who touches card data, from terminal to payment provider to acquirer, must meet it. The standard has also grown considerably more mature recently: where compliance used to be mainly an annual check, the current version calls for continuous security, all year round. And here is the pleasant part for you: the less your own systems touch card data, the smaller your part of that obligation. Pay online through a hosted checkout and your customer enters their details on the secure, certified payment page, not in your webshop; at the counter the secure terminal handles the payment and your till only exchanges amount and status. The heavy side of PCI DSS then sits where it belongs: with the certified payment infrastructure.

3-D Secure: your customer's signature

Where PCI DSS protects the data, 3-D Secure protects the transaction itself. It is the extra step your customer knows from almost every online purchase: a quick confirm in the bank app, and the payment goes through. That step proves the real cardholder is making the payment, not someone who obtained the card details. The modern version also works smartly in the background: on payments that are clearly fine, the check often runs invisibly, so the extra step only appears where it is really needed. For you it has two direct benefits. Less fraud, because stolen card details fail at the verification. And less pain from the fraud that is still attempted: on a successful 3-D Secure verification, liability for an unauthorised payment usually shifts to the cardholder's bank rather than to you.

PCI DSS keeps card data off the street; 3-D Secure ensures a payment really comes from your customer.

Why together they are your protection

The two complement each other precisely. PCI DSS keeps card data off the street; 3-D Secure ensures a payment really comes from your customer. Together they form the foundation of any serious payment solution, and for high-risk businesses they are extra valuable: less fraud and fewer chargebacks means a healthier dispute ratio, which is exactly what the payment chain judges you on.

What you have to arrange here

Little, and that is the point. Choose a payment setup where a hosted checkout or a secure terminal keeps card data outside your own systems, and where 3-D Secure is on by default. The law that makes this verification mandatory in Europe, PSD2 with its strong customer authentication requirement, we explain in the next article.