SCA optimisation
European checkouts require eligible exemptions to be identified before authentication is requested. SCA exemption management assesses basket value, card type and risk criteria, then sets the relevant TRA, low-value or corporate payment flag in the API payload.
- Category
- Security
- Capabilities
- 10
- Available on
- All plans
Cardflo's SCA optimisation helps merchants navigate Strong Customer Authentication requirements efficiently. We ensure compliance with PSD2 and other regulations while minimising impact on conversion rates.
Our platform intelligently manages authentication flows, promoting frictionless experiences where possible and securing transactions effectively.
PCI scope is minimised through hosted fields and network tokens, and sensitive credentials never touch your servers. Strong Customer Authentication is applied intelligently to keep both regulators and conversion teams happy.
SCA optimisation overview
Strong Customer Authentication (SCA) optimisation refers to the technical management of two-factor authentication requirements mandated under PSD2 in the European Economic Area and the United Kingdom. This process sits between the merchant checkout and the issuer authorisation request, determining when a transaction requires a full 3DS challenge versus when an exemption can be applied.
By analysing transaction data such as the merchant category code (MCC), transaction value, and historical cardholder behaviour, an optimisation engine selects the appropriate SCA path. The goal is to satisfy the regulatory requirements of the issuer while maintaining the lowest possible friction for the payer.
Effective SCA management involves the use of Transaction Risk Analysis (TRA) and other specific exemptions to bypass redundant security steps. This reduces the likelihood of cart abandonment caused by complex authentication procedures, ensuring that the necessary security protocols do not negatively impact the authorisation rates within the payments ecosystem.
How SCA optimisation works
Transaction data analysis
The system evaluates every inbound transaction for specific data points including the merchant category code, transaction amount, and geographic location. This initial assessment determines if the transaction falls within the scope of PSD2 mandates or if it qualifies as an out-of-scope transaction, such as mail order or telephone orders.
Exemption engine application
The engine applies logic to identify eligible exemptions like low-value payments under thirty euros or recurring transactions. If the acquirer supports Transaction Risk Analysis, the platform assesses the real-time risk level to request a friction-free flow, notifying the issuer that the transaction meets the threshold for an exemption.
Protocol version selection
The gateway determines the highest supported version of 3D Secure, preferring EMV 3DS (3DS2) over older protocols. This ensures compatibility with modern mobile banking apps and biometric authentication methods, which provide a significantly better user experience than legacy systems that rely on static passwords or SMS codes.
Dynamic challenge handling
If an issuer rejects an exemption request and returns a soft decline, the system triggers a platform-level retry with a full authentication challenge. This automated step prevents a permanent hard decline, allowing the consumer to complete the two-factor authentication process and facilitating a successful subsequent authorisation.
Why SCA optimisation matters
Authorisation rate preservation
Unoptimised SCA implementations frequently lead to higher decline rates because issuers may reject transactions that lack the necessary flags or authentication data. By correctly categorising transactions and applying the appropriate SCA tags, merchants maintain standing with issuers. This technical precision reduces the risk of soft declines and ensures that legitimate transactions are not blocked by overly aggressive fraud filters or rigid regulatory interpretations by the issuing bank.
Conversion and friction reduction
The primary cause of abandonment during the payment phase is the introduction of additional steps. SCA optimisation focuses on maximising the use of frictionless flows, where the cardholder is not prompted for manual input. By strategically using Transaction Risk Analysis (TRA) and low-value exemptions, businesses can process a significant portion of their volume without a challenge, directly improving the bottom line through reduced churn at the point of sale.
SCA optimisation use cases
LVP exemptions for digital goods
Urban transport operators processing sub-€30 contactless fare payments can request the LVP exemption, but cumulative value and transaction count thresholds still trigger SCA under PSD2. Cardflo configures exemption indicators through its API and helps payment teams monitor issuer outcomes so authentication is requested when the permitted limits are reached.
Lodged corporate card payments
Corporate travel management firms charging centrally lodged cards may qualify for the secure corporate payment exemption when the instrument and process meet PSD2 requirements. Cardflo helps operators pass the appropriate SCA flags and works with its acquirer partners to confirm eligibility, avoiding consumer authentication prompts on approved B2B payment arrangements.
TRA thresholds by basket value
European retailers with low fraud ratios may seek TRA exemptions across eligible basket bands, with permitted thresholds determined by the acquirer partner’s reference fraud rate. Cardflo applies exemption requests according to transaction value and risk rules, then reports issuer acceptance and fraud outcomes so payment managers can adjust exemption policies.
Trusted beneficiary checkout
Account-based merchants may offer customers the option to add a payee to an issuer-managed trusted beneficiary list, reducing SCA prompts on later eligible purchases. Cardflo supports the relevant exemption indicator in the payment request and records authentication and authorisation outcomes for compliance analysis under PSD2 and UK FCA rules.
SCA optimisation by the numbers
This represents the typical percentage of transactions that can bypass manual authentication prompts through strategic exemption management within the European market.
Merchants often observe this range of improvement in successful authorisations when moving from basic 3DS implementation to an optimised SCA strategy.
The additional technical overhead for evaluating exemptions and selecting the optimal 3DS version is generally minimal and does not impact page load times.
Methodology: these figures are illustrative ranges drawn from published industry data and observed merchant cohorts, not guarantees. Actual results depend on your risk profile, card mix, geography and acquiring setup, and are confirmed only in your own pricing and approval terms.
Related terms
Talk to our team about a live rollout across our acquirer partners' rails.
What you get with SCA optimisation
- Automatic identification of transactions eligible for Transaction Risk Analysis exemptions under PSD2 guidelines.
- Dynamic routing between 3DS versions to ensure compatibility with all global issuing bank infrastructures.
- Categorisation of out-of-scope transactions to prevent unnecessary authentication prompts for cardholders.
- Management of trusted beneficiary status to allow repeat customers a streamlined checkout experience.
- Real-time analysis of soft decline codes to automate the step-up authentication process for users.
- Verification of cardholder-initiated transaction flags to maintain regulatory compliance for first-time payments.
- Technical support for low-value payment exemptions to minimise friction for small ticket transactions.
- Integration with network tokens to improve the security profile of stored credential transactions.
- Logging of all SCA interaction data for audit trailing and regulatory reporting requirements.
- Optimisation of 3DS data packets to include additional context for improved issuer risk scoring.
A short scoping call, then a written plan for your MIDs.
Questions about SCA optimisation
How does SCA optimisation handle transactions where the acquirer and issuer are in different regions?
SCA requirements generally apply to 'one-leg-out' transactions with varying degrees of enforcement. An optimisation engine identifies the location of both the acquirer and the issuer via the Bank Identification Number (BIN).
If the transaction is one-leg-out, such as a UK merchant and a US cardholder, the system can determine whether to bypass SCA entirely or apply it as a best practice to reduce fraud risk,
depending on the specific risk profile and current issuer behaviour trends in that region.
What is the role of Transaction Risk Analysis in lowering friction?
Transaction Risk Analysis (TRA) is an exemption that allows PSPs and acquirers to bypass SCA for transactions up to five hundred euros, provided their overall fraud rates remain below specific thresholds.
SCA optimisation enables merchants to utilise the PSP's TRA exemption by providing high-quality data that supports a low-risk assessment. This allows the transaction to proceed in a frictionless flow, meaning the customer is never prompted for a 3DS challenge, significantly improving the checkout conversion rate.
What happens if an issuer ignores an exemption request?
If an issuer receives an authorisation request with an exemption flag but decides that a challenge is necessary, they will return a soft decline (often using code 65).
An optimised system recognises this specific response code in real-time and immediately restarts the transaction flow with a mandatory 3DS challenge.
This prevents the transaction from failing completely, giving the cardholder the opportunity to authenticate and proceed with the purchase without having to re-enter their card details.
Are recurring payments and subscriptions exempt from SCA?
Only the initial transaction in a subscription series, which is a cardholder-initiated transaction (CIT), requires SCA.
Subsequent payments are classified as merchant-initiated transactions (MIT) and are technically out of scope for SCA, provided the first transaction was correctly authenticated and the subsequent ones contain the appropriate original transaction ID references.
Optimisation ensures these links are maintained across the payment lifecycle so that renewal payments are not declined for lack of authentication.
How does the low-value payment exemption work in practice?
The low-value payment (LVP) exemption applies to transactions under thirty euros. However, the regulation includes counters; once a cardholder reaches five consecutive exempt transactions or a total spend of one hundred euros, the issuer must challenge the next payment.
An optimisation layer manages these requests but must be prepared for the issuer to refuse the LVP exemption once these thresholds are met, requiring a seamless transition to a full 3DS flow.
Does SCA optimisation affect PCI DSS compliance requirements?
SCA optimisation is a layer that interacts with 3D Secure protocols and does not directly change the merchant's PCI DSS scope, provided the merchant continues to use a secure gateway or vaulting system.
By handling the 3DS payloads and exemption flags, the optimisation engine operates within the existing secure environment, ensuring that sensitive cardholder data remains protected while the metadata related to authentication and exemptions is managed.
Related features.
Related guides.
See how Cardflo compares.
Ready to improve your payments setup?
Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.