Tip from SmartRetry If the subsequent authorization triggers an SCA soft decline despite the ECI 06 exemption, immediately escalate the transaction to a full cardholder challenge rather than retrying the frictionless payload. Ensure the downstream authorization is submitted immediately, as reusing or delaying the use of this authentication token will trigger hard issuer rejections.
Mastercard
Mastercard ECI Code 06: Acquirer Exemption Applied (EMV 3DS Only)
Last updated: September 25, 2026
About 06 - "Acquirer exemption applied (EMV 3DS only)"
Key details
- 06
- ECI Codes
- 06
- Acquirer exemption applied (EMV 3DS only)
What it means
Mastercard ECI 06 is an EMV 3-D Secure authentication result indicating that the issuer has granted an acquirer-requested exemption, such as a PSD2/SCA Low-Risk exemption. This results in a frictionless authentication flow where no cardholder challenge is required. It is not a payment decline code, but rather a success signal to proceed with the payment authorization using the supplied authentication token.
Classification & retryability
Do not retry the transaction merely because ECI 06 is returned, as it indicates a successful exemption request, not a transient failure. However, if the subsequent payment authorization is declined because the issuer mandates Strong Customer Authentication (SCA), you must initiate a new 3DS authentication requiring a payer challenge and resubmit the payment.
Why does code 06 occur?
- The merchant or acquirer requested a PSD2/SCA exemption, such as Low-Risk or Transaction Risk Analysis (TRA), during the 3DS process.
- The issuer accepted the exemption request and allowed a frictionless flow without a payer challenge.
- In EMV 3DS 2.2, this outcome is specifically triggered when the authentication system returns acsEci=06 alongside a transactionStatus of I (Authentication Exempt).
- In EMV 3DS 2.1, this result is identified by transactionStatus=N, reason code 81, and an AAV leading indicator of kN.
How to solve 06?
Evaluate the surrounding 3DS fields (such as transactionStatus=I for 3DS 2.2) and the gateway recommendation. If the gateway recommends proceeding, submit the payment authorization request containing the unaltered EMV 3DS authentication token supplied by the gateway. Ensure you do not request the exemption again during the authorization step itself.
Solving as a merchant
Verify that your payment gateway captures the authentication token and forwards it unaltered in the authorization request. Monitor the subsequent authorization response closely; if the issuer declines the authorization requiring SCA, configure your system to step up the user to a mandatory 3DS challenge and resubmit the payment with the new authentication details.
Solving as a customer
No action is required from the customer, as this code indicates a frictionless checkout experience without an authentication challenge. If the issuer ultimately declines the payment and demands authentication, the customer will then be prompted to complete a standard 3D Secure challenge.
Frequently asked questions about this topic
Author
Kyle Regacho
Focused on payment recovery, decline codes, and authorization optimization at SmartRetry. Helps payment teams turn failed transactions into recovered revenue
Read all articles >Articles you may find interesting:
View all
Turning Payment Declines into Revenue with Context-Aware Retry Logic
Blind retries waste fees and damage issuer trust. By analyzing decline codes and timing reattempts around payroll cycles, payment teams can successfully salvage recurring revenue without customer disruption.

Why Payments Fail: Decoding Decline Codes and Modernizing Retry Logic
Surface-level decline messages conceal critical issuer signals. Discover how intelligent retries, network tokens, and behavioral timing protect MID health and systematically recover lost recurring revenue.

Decoding Payment Declines: Turning Authorization Failures into Recovered Revenue
Blindly retrying failed transactions hurts authorization rates and risks network fines. Discover how decoding issuer responses turns card declines into recovered revenue.

The Real Cost of Payment Declines and How to Recover Lost Revenue
Payment failures cost merchants billions in uncaptured revenue and customer churn. Discover how data-driven retries and response code intelligence help teams recover failed transactions and protect conversion.