🌍 Countries with the Least 3D Secure in 2026

Investor

Professional
Messages
187
Reaction score
139
Points
43

A detailed analysis of countries with lower 3D Secure requirements, mandates, and practical implications for payment processing.​

Bro, this is about a very practical topic. The answer is: there's no single country with "no 3DS," but there is a clear division between mandated and non-mandated markets, as well as countries with lower frictionless rates. Let's break it down.

🏛️ Countries with 3DS Mandates vs. No Mandates​

3DS Mandated Countries (High 3DS)​

3DS is mandatory in these countries. There are generally more regulatory requirements and fewer gaps for bypass:
Region/CountryMandate Description
European Economic Area (EEA)PSD2/SCA mandates 3DS for all customer-initiated online payments where both acquirer and issuer are in the EEA. Countries include: Austria, Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden.
United KingdomEquivalent SCA requirements under FCA guidance.
JapanMandated EMV 3DS 2.0 for all e-commerce transactions from April 1, 2025 (response to record fraud losses of $370M USD in 2024).
IndiaRBI mandate for two-factor authentication on domestic online transactions; 3DS 1 deprecated in November 2023.
Bangladesh3DS 2 required for domestic transactions following scheme deprecations.
FranceTightened issuer restrictions in March 2025 — non-3DS authorisation exemptions above €100 per cardholder per day are soft-declined.

Countries with No 3DS Mandate​

In these countries, 3DS is a commercial decision, not a regulatory requirement. But note: this doesn't mean no 3DS ever, just that it's not mandated by law:
Region/CountryStatus
United StatesNo SCA mandate. Visa/Mastercard incentivize 3DS adoption through fraud liability structures, but it's voluntary.
AustraliaRisk-based framework. Merchants above a fraud threshold must implement 3DS, but no universal mandate.
SingaporeNo formal mandate, but major banks historically required OTP; now shifting toward tokenisation.
MalaysiaNo central bank mandate, but issuer-side BIN configurations often require 3DS for acceptable authorisation rates.
MexicoHistorically lagged on 3DS 2.0 migration; slower issuer upgrades from 3DS 1.0 infrastructure.
BrazilNo formal mandate, but industry has coordinated issuer-side 3DS 2.0 rollout; high adoption among top-tier merchants.
South AfricaEarly mover (2014), but formal mandate status varies.
China, CanadaEnhanced security practices, but not mandatory.

📊 Frictionless Rates: Where 3DS Happens Less Often​

Even in mandated countries, a certain percentage of transactions pass without a challenge. Ravelin's 2026 data shows:
RegionFrictionless RateNote
Europe~62%Frictionless rates have dropped globally
North America~54%Frictionless rates have dropped globally
Global Average~58%Frictionless authentication has fallen in 76% of countries
UKTops charts for authentication performanceFrictionless rates improved by 7%

Frictionless rate = the percentage of authentication attempts that are approved without a 3DS challenge.

Key takeaway: Even in the EEA, ~62% of transactions pass without challenge. The trick is that the issuer decides whether to challenge, and that depends on fraud score.

đźš« When 3DS Doesn't Apply (Exemptions)​

Even in mandated countries like the EEA, certain scenarios legally bypass SCA. These are set out in regulatory exemptions :
Exemption ScenarioDescription
Low ValueTransaction under €30.
Low Risk (TRA)Merchant maintains a fraud rate below 13 bps (0.13%) for transactions under €100, 6 bps for €100-250, 1 bps for €250-500.
Merchant Initiated Transactions (MIT)Recurring payments where the customer isn't present; no 3DS for subsequent payments.
MOTO (Mail/Telephone Order)Customer initiates via phone or mail.
One Leg Out (OLO)Either the issuing bank or the acquirer is outside the EEA.
Corporate PaymentsVirtual corporate cards.
Whitelisted MerchantsCardholder whitelists a merchant to avoid future 3DS checks.

For carding purposes: The "One Leg Out" exemption is critical — if your acquirer is outside the EEA, you may avoid SCA. This is commonly exploited.

đź’ˇ Practical Implications​

  1. Non-mandated markets are lower 3DS — the US, Australia, Mexico, Brazil, South Africa, Malaysia, and Singapore all lack formal mandates. However, this doesn't mean "no 3DS" — merchant risk policies, BINs, and fraud scores still trigger challenges.
  2. USA sees rapid improvement — frictionless rates in the US are rising, but US merchants remain a weak point for 3DS adoption historically. A 47% increase in 3DS success rate in the US was observed in 2026.
  3. 3DS is still triggered by fraud score, not location. Even in non-mandated countries, issuers implement 3DS based on risk analysis and chargeback liability. Factors like BIN, location mismatch, transaction amount, and IP score determine whether you see OTP.
  4. The "best" countries for bypass are where mandate is weaker, but also where merchant and issuer policies are less aggressive. Developing countries often lag in 3DS 2.0 implementation, creating gaps.
  5. Exemptions are a better path. In the EEA, leveraging exemptions like TRA (Low Risk) or MOTO can bypass 3DS without breaking rules. Many merchants use this method.

đź“‹ Summary Table​

CategoryCountriesPractical 3DS Risk
Mandated with strong enforcementEEA, UK, Japan, India, FranceHigh — almost always 3DS
Mandated with scheme deprecationBangladeshMedium — issuer readiness varies
No mandate but high fraud adoptionBrazil, South Africa, MalaysiaMedium — depends on merchant and issuer
No mandate, lower adoptionAustralia, Mexico, SingaporeLow — but growing
No mandate, voluntaryUnited States, Canada, ChinaLow to Medium — depends on merchant risk policy

đź’Ž Conclusion​

Bro, the countries with the least 3D Secure in 2026 are those without formal mandates: the United States, Australia, Mexico, Singapore, and Brazil. However, real-world "3DS avoidance" depends more on BIN quality, merchant risk policy, and leveraging exemptions like TRA or OLO than on geography. Even in the EEA, 62% of transactions pass frictionless, so 3DS is not about location — it's about fraud score.

Key takeaways:
  1. No mandate ≠ no 3DS — but risk is lower in non-mandated markets.
  2. Frictionless rates are dropping globally — more challenges are expected in 2026.
  3. Leverage exemptions: In the EEA, MIT, MOTO, TRA, and One-Leg-Out are your legal bypass routes.
  4. The USA is improving — but still historically a weak 3DS market, which is exactly what you want.

If you're looking to avoid 3DS, focus on countries with weaker mandates and use high-quality BINs with good fraud scores.
 
Top