Aug 05, 2026
No image
A PA-DSS-Compliant Payment Gateway with 3D Secure Authentication
Completed

A PA-DSS-Compliant Payment Gateway with 3D Secure Authentication

$100,000+
more 1 year
Germany
10+
view project
Service categories
Service Lines
Software Development
DevOps
IT Services
Web Development
Domain focus
Banking & Financial Services
Commerce
Retail and Restaurants
Programming language
HTML
Java
JavaScript
Frameworks
Angular.js
Spring
Subcategories
Software Development
Enterprise Software
IT Services
Cybersecurity

Challenge

A European fintech software product company offering cloud and on-premises solutions for banks, payment service providers, and ecommerce merchants wanted to build a multi-component payment gateway enabling ecommerce payments with 3D Secure payer authentication, aimed primarily at banks helping their ecommerce customers adopt secure digital payments. The core was a white-label gateway hosted on the bank's server, providing ready-to-use APIs for integration with banking systems and merchant apps, with customizable checkout so banks could express their brand, while back-end 3D Secure components would authenticate payers to the latest card-network protocols. The company's in-house developers lacked specialized experience in large-scale payment gateways and 3D Secure compliance, so it needed seasoned payment-software expertise it could rely on.

Solution

After studying the requirements, the team assembled Java engineers with strong track records in large-scale financial software and compliant payment solutions and was ready to start within a week. It helped architect the gateway and 3D Secure components with a service-oriented approach for a flexible, modular, scalable solution and recommended container-based development to restrict access to critical components and streamline PA-DSS controls and DevOps. The engineers coded every major server-side component: a merchant-side 3D Secure client handling checkout generation, payment processing, message routing, status reporting, and merchant account management; a 3D Secure server initiating cardholder authentication; a directory server validating and routing authentication requests; and an access control server storing enrollment data and running real-time risk assessment for frictionless payments. Implementations were certified against EMVCo 3DS v1 and v2 using an approved lab toolkit, with ready-to-use APIs to integrate the components with core banking systems, HSMs, and fraud tools. To meet PA-DSS, the team designed compliant data storage and retention policies, implemented JSON Web Encryption for data at rest and in transit, set up logging and monitoring with role-based access, and enforced secure coding backed by OWASP ASVS. It was built with Java, Spring, Hibernate, Oracle, AngularJS, and Docker.

Results

Over nearly three years, the Java engineers helped the company obtain a robust payment product that protects cardholder data and complies with EMVCo 3DS v2. The easy-to-deploy, EMVCo-approved solution offering secure, convenient checkout quickly gained traction among banks worldwide, helping the company win a larger market share and generate strong revenue. The team continues to help the company's customers deploy the gateway components on cloud and on-premises servers, integrate directory servers with local card networks, and pass 3DS certifications, while refactoring code, removing redundant features, and upgrading the product to keep pace with EMVCo's evolving standards. Satisfied with the outcome, the company expanded the cooperation to evolve another of its fintech products.