Confidential by defaultEstablished 201072 Jurisdictions

Strong Customer Authentication (SCA)

Strong customer authentication is the PSD2 requirement to verify a payer using two independent factors drawn from knowledge, possession and inherence. It applies to electronic payments and account access in the EEA, subject to a defined set of exemptions — and the exemptions are where the work is.

Also called: two-factor authentication

SCA requires two factors from different categories: something the user knows (a password or PIN), something they possess (a device or a card), and something they are (a fingerprint or face). The factors must be independent, so that compromising one does not compromise another. The detail sits in the regulatory technical standards on strong customer authentication and common and secure communication, Commission Delegated Regulation (EU) 2018/389, which also defines dynamic linking — the authentication code must be tied to the specific amount and payee.

The exemptions are what make the regime workable and what make it complicated: low-value transactions, contactless payments below defined limits with cumulative counters, transaction risk analysis below defined fraud rates, merchants the customer has whitelisted, recurring transactions of the same amount to the same payee, and corporate payment processes using dedicated secure protocols. Exemptions are applied by the payment service provider, not chosen by the merchant, and applying one shifts liability.

Account access has its own position. The RTS were amended by Commission Delegated Regulation (EU) 2022/2360, applying from 25 July 2023, which introduced a mandatory exemption for access to balance and recent transactions through an AISP and extended the re-authentication period for account access from 90 days to 180.

In practice

This is an EEA regime and the details move. The UK maintains its own version through the FCA, which has diverged; PSD3 and the Payment Services Regulation were agreed in trilogue in November 2025 and were close to formal adoption as at September 2026, with application expected around 21 months after publication. Treat any specific exemption threshold as current-as-at-a-date, not as permanent.

Example

A cardholder buys online. The issuer applies transaction risk analysis and lets the payment through with no challenge; the same cardholder, buying a larger amount the next day, is challenged in their banking app. Both are compliant — the difference is an exemption the issuer applied, and with it the liability.

Commonly confused with

TermHow it differs
Two-factor authentication2FA is a general security practice. SCA is a legal requirement with prescribed factor categories, independence, dynamic linking and named exemptions. Not all 2FA satisfies SCA.
3-D SecureA card-scheme protocol commonly used to deliver SCA on card payments. It is a mechanism; SCA is the obligation, and 3-D Secure is not the only way to meet it.
PSD2PSD2 is the directive. SCA is one requirement within it, elaborated by a separate delegated regulation.

See also

Go deeper

Regulatory information checked: 23/Sep/2026

← All glossary terms

Page Last Updated: 23/Sep/2026