Strong Customer Authentication (SCA)
Strong customer authentication is the PSD2 requirement to verify a payer using two independent factors drawn from knowledge, possession and inherence. It applies to electronic payments and account access in the EEA, subject to a defined set of exemptions — and the exemptions are where the work is.
Also called: two-factor authentication
SCA requires two factors from different categories: something the user knows (a password or PIN), something they possess (a device or a card), and something they are (a fingerprint or face). The factors must be independent, so that compromising one does not compromise another. The detail sits in the regulatory technical standards on strong customer authentication and common and secure communication, Commission Delegated Regulation (EU) 2018/389, which also defines dynamic linking — the authentication code must be tied to the specific amount and payee.
The exemptions are what make the regime workable and what make it complicated: low-value transactions, contactless payments below defined limits with cumulative counters, transaction risk analysis below defined fraud rates, merchants the customer has whitelisted, recurring transactions of the same amount to the same payee, and corporate payment processes using dedicated secure protocols. Exemptions are applied by the payment service provider, not chosen by the merchant, and applying one shifts liability.
Account access has its own position. The RTS were amended by Commission Delegated Regulation (EU) 2022/2360, applying from 25 July 2023, which introduced a mandatory exemption for access to balance and recent transactions through an AISP and extended the re-authentication period for account access from 90 days to 180.
In practice
This is an EEA regime and the details move. The UK maintains its own version through the FCA, which has diverged; PSD3 and the Payment Services Regulation were agreed in trilogue in November 2025 and were close to formal adoption as at September 2026, with application expected around 21 months after publication. Treat any specific exemption threshold as current-as-at-a-date, not as permanent.
Example
A cardholder buys online. The issuer applies transaction risk analysis and lets the payment through with no challenge; the same cardholder, buying a larger amount the next day, is challenged in their banking app. Both are compliant — the difference is an exemption the issuer applied, and with it the liability.
Commonly confused with
| Term | How it differs |
|---|---|
| Two-factor authentication | 2FA is a general security practice. SCA is a legal requirement with prescribed factor categories, independence, dynamic linking and named exemptions. Not all 2FA satisfies SCA. |
| 3-D Secure | A card-scheme protocol commonly used to deliver SCA on card payments. It is a mechanism; SCA is the obligation, and 3-D Secure is not the only way to meet it. |
| PSD2 | PSD2 is the directive. SCA is one requirement within it, elaborated by a separate delegated regulation. |
See also
- PSD2PSD2, the Second Payment Services Directive, is the EU law governing payment services. It sets the authorization categories for payment firms, opened bank account access to licensed third parties, and required strong customer authentication for electronic payments.
- Account Information ServiceAn account information service is a regulated open banking service that reads a customer's payment account data, with their consent, and presents it back to them. PSD2 defines it as an online service providing consolidated information on one or more payment accounts. It reads; it cannot move money.
- Payment Initiation ServiceA payment initiation service instructs a payment from a customer's own bank account on their instruction. PSD2 requires that the provider must not hold the payer's funds at any time in connection with the service — which is the whole distinction between a PISP and a firm that handles money.
- Open BankingOpen banking is regulated access to bank account data and to payment initiation through APIs, with the account holder’s consent. In the European Union and the United Kingdom it is a licensed activity under payment services law, not a private arrangement between a fintech and a bank.
- European Economic AreaThe European Economic Area is the EU's 27 member states plus Iceland, Liechtenstein and Norway. It is the area across which a payment or e-money authorisation can be passported — which is why it, rather than the EU, is usually the right boundary in a licensing conversation.
- ChargebackA chargeback is a forced reversal of a card payment, initiated by the cardholder’s bank rather than by the merchant. The money is taken back out of the merchant’s account under the card scheme’s dispute rules, whether or not the merchant agrees.
Go deeper
Regulatory information checked: 23/Sep/2026
