Home  /  News  /  Payments & Risk
Payments & RiskDecember 24, 2025

3-D Secure in iGaming: Build, Buy or Outsource?

Operators weighing 3-D Secure adoption face a critical build-buy-outsource decision. Here is what the choice means for compliance, conversion and cost.

3-D Secure in iGaming: Build, Buy or Outsource?

3-D Secure 2 (3DS2) is no longer a nice-to-have layer in iGaming payments; it is a regulatory baseline in most regulated markets and a practical necessity for card scheme compliance. Yet many operators still lack a clear strategy for how to implement it, and the build-versus-buy-versus-outsource question carries real consequences for conversion rates, chargeback ratios and operational overhead.

Why 3DS2 Matters More in iGaming Than in General Retail

iGaming transactions attract disproportionate fraud scrutiny from card schemes and acquiring banks. High average transaction values, repeat deposits within short windows and the cross-border nature of most player bases all push operators toward elevated risk categories. 3DS2 addresses this through richer authentication data: device fingerprinting, behavioural signals and transaction history replace the clunky static password of the original protocol. The result, when implemented correctly, is frictionless authentication for low-risk transactions and step-up challenges only where genuinely needed.

Critically, 3DS2 shifts chargeback liability from the acquirer to the issuing bank when authentication succeeds. For operators managing thin margins on payment processing, that liability shift is a meaningful financial protection.

The Build Option: Control at a High Price

Building a proprietary 3DS2 stack means integrating directly with an Access Control Server (ACS) or constructing your own 3DS Server component. The appeal is complete control over authentication logic, data flows and the user experience within the challenge window.

In practice, building is rarely advisable for iGaming operators outside the largest tier. The reasons are straightforward:

  • EMVCo certification and ongoing compliance audits require dedicated technical and legal resource.
  • Protocol updates, such as the shift toward 3DS2.3 features, demand continuous engineering investment.
  • Data sovereignty obligations in markets like Germany and Sweden add infrastructure complexity.
  • Internal fraud model training requires large, clean transaction datasets that smaller operators do not possess.

Build is appropriate only when an operator processes at sufficient volume to justify the fixed cost and has genuine strategic reasons to own the authentication data layer outright.

The Buy Option: Licensing a Certified Platform

Purchasing a licensed 3DS Server or MPI (Merchant Plug-In) from a certified vendor moves the certification burden off the operator while keeping authentication logic partially in-house. Several payment technology vendors offer white-label 3DS components that operators can embed into their existing payment orchestration layer.

The buy model suits mid-tier operators who have internal payment engineering capacity but want to avoid the full certification overhead. Key considerations before licensing include:

  • Confirm the vendor holds current EMVCo Level 2 certification.
  • Assess how quickly the vendor has historically shipped updates following protocol version changes.
  • Clarify data processing agreements, particularly where player authentication data flows across jurisdictions.
  • Understand how the vendor's fraud model is trained and whether iGaming transaction patterns are represented in that data.

The Outsource Option: Managed Authentication Within a Broader Stack

Outsourcing 3DS2 to a payment service provider or managed-services partner means authentication is handled end-to-end by a third party, typically bundled with acquiring, fraud scoring and reporting. This is the most common route for small to mid-sized operators and, increasingly, for larger operators who recognise that payment infrastructure is not a competitive differentiator.

The outsource model delivers faster time-to-market, predictable per-transaction pricing and access to network-level fraud intelligence that individual operators cannot replicate. The trade-offs are reduced visibility into authentication outcomes and dependency on a vendor's prioritisation decisions when problems arise.

What Operators Should Negotiate in Any Outsource Agreement

  • Granular reporting on authentication rates, frictionless ratios and step-up challenge outcomes, segmented by BIN range and geography.
  • SLA commitments on ACS availability, because authentication downtime equals lost deposits.
  • Clear ownership of authentication data for audit and AML purposes.
  • Contractual rights to switch providers without losing historical transaction data.

The OnlineShine Perspective

Operators rarely fail at 3DS2 because they chose the wrong technical architecture. They fail because authentication outcomes are not connected to player lifecycle data. A high step-up rate for a specific BIN group is a retention signal, not just a payment metric.

Connecting 3DS2 outcome data to CRM and player risk profiling is where real operational value is created. Whether you build, buy or outsource the authentication layer, the integration point with your broader compliance and retention stack is where the decision ultimately gets judged.

FAQ

Frequently asked questions

What is 3-D Secure 2 and why is it relevant to iGaming operators?

3-D Secure 2 (3DS2) is an authentication protocol developed under EMVCo standards that verifies a cardholder's identity during online transactions using device and behavioural data rather than static passwords. For iGaming operators, successful 3DS2 authentication shifts chargeback liability from the acquirer to the card issuer, reducing financial exposure. It is also a compliance requirement under many regulated market frameworks and a card scheme mandate for merchants operating in higher-risk categories.

What is the difference between building, buying and outsourcing a 3DS2 solution?

Building means constructing and certifying a proprietary 3DS Server or ACS component, which provides maximum control but requires significant engineering and compliance investment. Buying involves licensing an EMVCo-certified component from a third-party vendor and embedding it into your own payment stack. Outsourcing hands the entire authentication process to a payment service provider or managed partner, bundling 3DS2 with acquiring and fraud services for a per-transaction fee. Most iGaming operators at small to mid-scale benefit most from the outsource model due to lower fixed costs and faster deployment.

How does 3DS2 affect player conversion rates in online casinos and sportsbooks?

3DS2 is designed to allow most low-risk transactions to proceed as frictionless authentication, meaning the player sees no challenge step at all. When implemented with a well-trained fraud model that includes iGaming transaction patterns, frictionless rates above 80 percent are achievable. Step-up challenges, where a player must complete an OTP or biometric verification, carry dropout risk and should be monitored as a conversion metric alongside payment-specific reporting.

What data should operators request from their 3DS2 provider to manage risk and compliance effectively?

Operators should require granular reporting that breaks down authentication outcomes by BIN range, geography, device type and transaction value band. Key metrics include frictionless authentication rate, step-up challenge completion rate and authentication decline reasons. This data supports AML transaction monitoring by providing context for unusual payment patterns and helps CRM teams identify player friction events that may drive churn, making 3DS2 reporting operationally relevant beyond the payments function.

Keep reading

Related articles

Show us one brand.
We will find the leaks.

Book a 30-minute teardown. We walk through one of your brands and show you exactly where revenue, retention or compliance is slipping, no obligation.