Definition:
Strong Customer Authentication (SCA) is a security requirement under European payment rules that requires a user’s identity to be verified through at least two independent elements. Those elements must belong to different categories: knowledge, possession and inherence.
Table of contents
SCA applies when a payment service provider needs to verify that an authorized person is accessing an account, initiating an electronic payment or carrying out a remote action that involves a risk of fraud. In online payments, it helps reduce unauthorized transactions, but it does not by itself make every type of fraud impossible.
How Strong Customer Authentication works
For authentication to qualify as strong, it must combine at least two of these three factors:
- Knowledge: something only the user knows, such as a password or PIN.
- Possession: something the user controls, such as a registered phone or device whose possession can be verified.
- Inherence: something inherent to the user, such as a fingerprint, facial recognition or another biometric characteristic.
The factors must be independent: compromising one must not undermine the reliability of the others. Entering two passwords therefore does not constitute SCA because both belong to the knowledge category.
For remote electronic payments, authentication must also be dynamically linked to the amount and payee. If either changes, the authentication code generated for the transaction is no longer valid. This does not mean that every SCA process depends on an SMS or one-time passcode; the experience depends on the bank, device and available authentication method.
When SCA applies
Within the European Economic Area, a payment service provider must generally apply SCA when a customer:
- Accesses a payment account online.
- Initiates an electronic payment transaction.
- Carries out another action through a remote channel that may involve a risk of fraud or abuse.
In ecommerce, SCA commonly takes place during payment authorization. The merchant and its payment gateway submit transaction information, but the issuer of the payment instrument normally authenticates the customer and decides whether to authorize, decline or request additional verification.
SCA is not a specific method or product. Nor is it synonymous with 3-D Secure: 3-D Secure is a protocol used in card payments to exchange data and support authentication. The regulatory requirement is to meet SCA standards when applicable, using 3-D Secure or another valid implementation.
Exemptions and transactions outside its scope
The rules provide exemptions to reduce friction when the risk or type of transaction allows it. The main exemptions include:
- Low-value contactless payments: individual transactions of up to EUR 50, provided that the cumulative amount since the last SCA does not exceed EUR 150 or no more than five consecutive transactions have been made. The issuer may require authentication earlier.
- Low-value remote payments: transactions of up to EUR 30, provided that the cumulative amount since the last SCA does not exceed EUR 100 or no more than five consecutive transactions have been made.
- Recurring payments: after the series is created or changed using SCA, subsequent payments for the same amount to the same payee may be exempt.
- Trusted beneficiaries: a user can add a beneficiary to a trusted list using SCA; later payments to that recipient may be exempt.
- Transaction risk analysis: certain payments may be processed without a user challenge if they meet the applicable value, fraud and risk-assessment thresholds.
- Secure corporate processes: certain payments initiated through dedicated protocols may be exempt when the competent authority considers their security equivalent.
- Unattended terminals: payments at terminals used for transport fares or parking fees may be exempt.
An exemption is not a right held by the merchant or customer. The relevant provider may request one, but the issuer can require SCA when it identifies risk. Some transactions are also outside the scope of the requirement, which is not the same as being exempt. Classification depends on who initiates the payment, where the providers are located and how the mandate was given.
The limits for contactless and remote payments are not the same. The type of transaction must therefore be identified before applying a threshold.
SCA in online payments and 3-D Secure
In a card purchase, the flow may work as follows:
- The merchant sends the payment provider details about the purchase and its available context.
- The 3-D Secure protocol allows that information to be shared with the issuer for risk assessment.
- The issuer may apply an exemption, authenticate without additional interaction when the solution permits it, or present a challenge to the cardholder.
- If challenged, the user confirms with valid factors, such as a registered device and a fingerprint or PIN.
- The issuer returns the authentication result and decides whether to authorize the payment.
A payment without an extra screen does not necessarily mean that security was bypassed. An exemption or data-based assessment may have been used. Likewise, successful authentication does not guarantee authorization: funds, limits, expiry, fraud controls and other criteria also affect the decision.
Benefits and limitations of SCA
Strong Customer Authentication provides several improvements but also requires careful implementation:
- Reduces the use of stolen credentials: knowing a password is generally not enough to complete the transaction.
- Links authentication to the payment: in remote transactions protected by dynamic linking, the amount and payee are part of the verification.
- Supports different methods: banks and providers can use apps, biometrics, registered devices and other compatible solutions.
- Introduces friction: a poorly designed challenge, incomplete data or lack of access to the device can increase abandonment and failed payments.
- Does not eliminate all fraud: phishing, social engineering and manipulation of the user may overcome technical controls if the person authorizes a fraudulent transaction.
Merchants and providers should submit accurate data, keep integrations current, offer an accessible recovery path, and measure challenges, abandonment, declines and fraud separately. The European Commission places SCA within PSD2 and its technical security standards for payment services.
