Regulation

What is PSD2 SCA rules?

EU/UK PSD2 requirement that EEA-issued cards used at EEA merchants complete SCA unless an exemption applies; enforced by issuers via 3DS challenges.

The Revised Payment Services Directive (PSD2) Strong Customer Authentication (SCA) rules mandate that electronic payments initiated by an EEA cardholder within the European Economic Area (EEA) require multi-factor authentication unless an exemption applies.

This authentication, typically fulfilled by 3D Secure (3DS) 2. x, involves the issuer verifying at least two independent elements from knowledge, possession, or inherence categories before authorising a transaction.

Transactions below €30, or those identified as low risk by the issuer, may be exempted from SCA, with the issuer indicating their decision in the 3DS response (e. g. , `transStatus='Y'` for frictionless flow, or `transStatus='C'` for challenge).

For merchants, PSD2 SCA primarily manifests as a requirement to implement 3DS 2. x for card-not-present transactions where both the card and merchant are EEA-domiciled.

Merchants typically integrate a 3DS Server or utilise their payment gateway's 3DS services to initiate the authentication flow, passing relevant transaction data for the issuer's risk assessment.

A common pitfall is failing to correctly implement 3DS for recurring payments or merchant-initiated transactions (MITs), as these often require specific flags (e. g. , `recurringIndicator`) set during the initial SCA-authenticated transaction to facilitate subsequent exemption.

Related terms

Apply with Cardflo

Ready to improve your payments setup?

Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.

Apply now