Common signs include longer checkout times, higher cart abandonment, and customer frustration at the payment step. If mobile users are especially affected, the issue may be poor factor design or lack of support for wallets and biometric authentication. Merchants should watch both conversion and completion rates to determine whether the control is creating unnecessary friction.
What the checkout pattern is really telling you
When strong customer authentication starts hurting the checkout experience, the warning signs usually show up in the funnel, not in a policy document. Look for a measurable drop between payment initiation and completed order, repeated abandonment on challenge screens, and a widening gap between desktop and mobile outcomes, especially where wallet or biometric options are missing or unreliable.
Checkout friction also tends to cluster around specific journeys. If one issuer, region, device class, or payment method consistently underperforms, the control may be technically compliant but operationally misaligned with how customers actually authenticate. That is often the point where merchants need to separate necessary step-up friction from avoidable user-experience failure.
For teams mapping this to broader access and authentication patterns, the same principle appears in Uber Breach, where authentication burden and user behaviour shaped the practical outcome, and in PCI DSS v4.0, which makes clear that access controls must work in a way that is both secure and usable in production payment flows.
How to tell friction from healthy step-up
The key judgement is whether the extra step is protecting a real risk or simply making payment completion harder. Healthy strong customer authentication should cause a small, explainable drop in conversion at the most sensitive points, not a broad collapse in completed orders or a pattern of repeated failed attempts that customers cannot recover from.
Practical signals include increasing retries, more abandoned sessions after the authentication prompt, and a rising share of support complaints that describe the payment step as confusing, slow, or impossible on certain devices. If mobile traffic is disproportionately affected, the likely issue is not security strength but poor factor design, weak fallback paths, or missing support for biometric and wallet-based flows.
The design lesson is reinforced by NIST SP 800-53 Rev. 5 Security and Privacy Controls, which treats authentication and access control as operational controls that must be implemented well, and by OWASP ASVS, which makes authentication and session handling part of secure application behaviour rather than an afterthought.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack surface, CIS Controls v8 and NIST CSF 2.0 set the technical controls, and PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| PCI DSS v4.0 | 7 — Restrict Access by Business Need to Know | Checkout auth must balance secure access with usable payment completion. |
| 8.6 — System and Application Accounts and Authentication Controls | Authentication controls must work reliably in payment journeys. | |
| Recommendation — Apply least-privilege access to payment flows without adding unnecessary customer friction. Design authentication so payment-step controls remain usable across devices and methods. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Secrets and Credential Lifecycle | Strong authentication depends on reliable credential handling and user-facing auth paths. |
| Recommendation — Review authentication dependencies so customer-facing authentication remains recoverable and low-friction. | ||
| CIS Controls v8 | 6 — Access Control Management | Access controls must enforce security without creating avoidable transaction failure. |
| Recommendation — Tune access controls to protect transactions while preserving successful checkout completion. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication and Access Control | The issue is an authentication control creating measurable friction in an operational flow. |
| Recommendation — Align authentication strength with user experience metrics to avoid harmful checkout friction. | ||
Practitioner Guidance
What to prioritise: Measure conversion, completion, and abandonment separately, because a checkout can look healthy at the top of the funnel while failing at the authentication step. If the issue is concentrated on mobile, treat device-specific usability as the first hypothesis, not an edge case.
What to verify: Confirm whether the customer can complete the payment using the methods actually available to them. A strong control that blocks modern wallets, biometric options, or straightforward retry paths is often a design problem, not a policy success.
Decision rule: If the control materially reduces completed orders without a clear fraud or chargeback benefit, investigate the challenge design, timing, and fallback logic before tightening authentication further. If customers are abandoning at the same point across multiple cohorts, the friction is probably systemic.
Practitioner takeaway: The goal is not maximum authentication friction, it is the smallest authentication step that still preserves trust, approval quality, and checkout completion.
Related resources from NHI Mgmt Group
- How should payment organisations implement strong customer authentication without creating unnecessary checkout friction?
- How should organisations implement CIBA in customer authentication flows that need strong security and good user experience?
- What are the signs that a combined login screen is hurting the authentication experience?
- What are the signs that a slow ecommerce site is hurting customer experience?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 17, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org