
The 3D Secure protocol adds an authentication step when making an online purchase with a credit card. Largely mandated by the European DSP2 directive, this mechanism sends a code via SMS or notification on the banking app before validating the transaction. Some merchants do not activate this verification, either because they use a payment provider that does not require it, or because the transaction falls under an exemption provided by the regulations.
DSP2 Exemptions: Why Some Transactions Bypass 3D Secure
3D Secure is not a binary choice for merchants. The DSP2 outlines several cases where strong authentication is not mandatory, and it is often this mechanism that explains the absence of verification rather than a simple refusal of the protocol.
Transactions deemed low risk by the card issuer may be exempted. Payment providers use real-time analysis algorithms (Transaction Risk Analysis) to assess each operation. If the provider’s fraud rate remains below a threshold defined by the regulations, they can request an exemption for low-value payments.
- Recurring payments (subscriptions) only trigger 3D Secure on the first transaction, not on subsequent ones.
- Purchases below a certain threshold may be exempted if the acquirer maintains a sufficiently low fraud rate.
- Trusted beneficiaries, manually added by the cardholder with their bank, bypass strong authentication.
In other words, the absence of 3D Secure does not mean the absence of security. It often reflects a favorable risk analysis conducted in the background, invisible to the buyer.
To explore this topic in detail, a list of sites without 3D Secure catalogs the platforms where this verification is not systematically triggered.
![]()
Credit Card Fraud in France: What the Latest Figures Show
The credit card fraud rate in France fell to about 0.048% in the first half of 2025, according to the Payment Means Security Observatory (OSMP) of the Bank of France. In value, this represents 211 million euros, down nearly 10% year-on-year.
This decline is partly explained by the widespread adoption of 3D Secure. The card remains the least fraud-prone payment method proportionally.
The paradox lies elsewhere. Fraud across all payment methods has increased by about 7%, reaching 618 million euros during the same period. Fraud is not disappearing; it is shifting. Social engineering techniques (fake bank advisor, targeted phishing) accounted for about 32% of payment fraud in 2024, and this proportion rose to about 40% in 2025.
Paying on a site without 3D Secure is therefore not the main risk for a cardholder today. The real danger comes from human manipulations, not from the absence of an SMS code.
Payment Without 3D Secure: What the Merchant Assumes
When a merchant chooses not to trigger 3D Secure authentication, they assume the risk of disputes. In the case of proven fraud, it is the merchant (not the cardholder’s bank) who bears the financial loss under the liability shift mechanism.
This transfer of responsibility explains why some large international platforms voluntarily disable 3D Secure. Their calculation is simple: the cost of abandoned carts exceeds that of absorbed fraud. An additional authentication step leads to significant cart abandonment, and for a high-volume site, every lost conversion point represents a considerable loss of revenue.
Sites making this choice generally have sophisticated internal anti-fraud systems. They analyze the IP address, browser fingerprint, purchase history, and dozens of other signals before accepting a transaction. The absence of visible 3D Secure does not mean the absence of filtering.
Types of Affected Sites
Digital service platforms (streaming, cloud storage, certain mobile apps) are among the most common. Travel and hotel booking sites also use exemptions, particularly for recurring payments or low-risk prepayments.
Some e-commerce merchants specializing in low amounts also bypass 3D Secure thanks to the exemption thresholds provided by the DSP2.
![]()
Protecting Your Credit Card Without Relying on 3D Secure
Relying solely on 3D Secure to secure online purchases would be a mistake. Several complementary measures offer more robust protection, regardless of the site used.
- Single-use virtual cards, offered by most online banks, generate a temporary card number linked to a specific amount and duration.
- Activating real-time notifications for each transaction allows immediate detection of unauthorized operations and blocking the card from the banking app.
- Checking the HTTPS protocol and the merchant’s reputation before any purchase remains a basic reflex, more effective than an SMS code sent afterward.
- Never sharing your banking details over the phone, even with someone claiming to be from your bank, limits exposure to social engineering fraud that is skyrocketing in 2025.
3D Secure is a layer of protection among others, not an absolute shield. Sites that do not use it generally compensate with real-time risk analysis systems on the server side. The cardholder, in turn, maintains control over the security of their data by activating the tools provided by their bank.