Frequently Asked Question

Are authentication values from a 3DS transaction considered sensitive authentication data for PCI DSS purposes?

No. PCI DSS sensitive authentication data (SAD) consists of full magnetic-stripe data, card verification codes or values, and PINs or PIN blocks. PCI DSS specifically prohibits storage of SAD after completion of the authorization process.

3DS authentication values are not considered to be SAD from a PCI DSS perspective. Additionally, 3DS sensitive data--as defined in the PCI 3DS Data Matrix in Table 1: 3DSS, DS, and ACS Sensitive Data Elements—is not considered to be SAD from a PCI DSS perspective. PCI DSS does not prohibit any 3DS data from being stored after the authorization process is complete.

Entities performing or providing any of the following 3DS functions: 3DS Server, 3DS Directory Server, and/or 3DS Access Control Server should confirm with the payment brand(s) for which they perform these 3DS functions whether they are required to meet the requirements in the PCI 3DS Core Security Standard.

September 2026
Article Number: 1603

Featured FAQ Articles