Regulation

What is Strong Customer Authentication?

Also: SCA

PSD2 requirement that customer-initiated electronic payments in the EEA and UK be authenticated with two of: knowledge, possession, inherence.

Strong Customer Authentication, or SCA, is a regulatory requirement under the EU's Second Payment Services Directive (PSD2) and retained in UK law. It is designed to make electronic payments more secure and reduce fraud.

The regulation mandates that for customer-initiated electronic payments within the European Economic Area (EEA) and the UK, authentication must be performed using at least two out of three possible independent factors.

These factors are categorised as: Knowledge (something only the user knows, like a password or PIN), Possession (something only the user possesses, like their mobile phone or a hardware token), and Inherence (something the user is, like a fingerprint or facial recognition).

The primary technical solution used to meet SCA requirements for card payments is 3D Secure 2. Issuers are responsible for performing the authentication and will decline authorisation requests for transactions that fall under the SCA mandate but have not been properly authenticated.

However, the legislation includes several important exemptions to avoid adding unnecessary friction to all payments. These include transactions below €30 (up to a cumulative limit), recurring payments after the initial setup, payments to a Trusted beneficiary whitelisted by the customer, and certain corporate payments.

Perhaps the most significant exemption is for low-risk transactions assessed via Transaction Risk Analysis (TRA), which allows payment providers with low fraud rates to bypass SCA on qualifying payments up to €500.

A nuance often missed is that TRA is a privilege granted to acquirers based on their fraud performance, not a right, creating a competitive difference between providers.

Worked example

A shopper in Germany is buying a lamp for €120 from a French e-commerce site. As this is a customer-initiated transaction between two parties within the EEA, it falls under the SCA mandate.

At Checkout, the merchant triggers 3D Secure 2. The shopper receives a push notification on their banking app (Possession factor).

They open the app and confirm the payment using their fingerprint (Inherence factor). Having successfully provided two factors, the transaction is authenticated and approved.

In a different scenario, if the same customer were making a €25 purchase, the merchant could claim a Low-value exemption. The issuer would then decide whether to honour the exemption or still request an SCA challenge based on its own risk assessment.

Scheme notes

SCA is a legal requirement imposed on payment service providers, not a rule created by the card schemes themselves. However, the schemes are essential for its implementation.

Visa and Mastercard have both integrated SCA compliance into their core processing rules and provide the 3D Secure 2 protocol as the primary mechanism for merchants and issuers to comply.

They offer functionality for merchants to flag transactions for specific exemptions, such as low-value or Merchant-Initiated Transactions (MITs). While the regulation itself is uniform, the rigour with which individual European issuers apply it, particularly their willingness to accept exemption requests, can vary.

This makes handling SCA a matter of careful orchestration rather than a simple one-size-fits-all implementation.

Why it matters for merchants

For merchants selling to customers in the EEA and UK, non-compliance with SCA results in declined payments and lost revenue. The main challenge is balancing this legal requirement with providing a smooth customer experience.

Over-using authentication creates friction and cart abandonment, while failing to authenticate leads to hard declines. The strategic use of exemptions is therefore critical to commercial success.

Cardflo's payment orchestration helps merchants navigate this complexity by correctly flagging transactions for available exemptions.

Furthermore, Cardflo's smart routing can direct transactions to acquirers who have earned a TRA exemption, increasing the likelihood that low-risk transactions are processed without a disruptive SCA challenge, thus boosting approval rates.

Frequently asked

How do merchants apply for SCA exemptions to reduce friction?

Merchants can request exemptions via their payment gateway or acquirer by flagging specific transactions in the payment authorisation request. Common exemptions include Low Value Transactions under thirty euros and Transaction Risk Analysis, though the final decision to honour an exemption rests with the issuing bank.

What happens if a transaction requires SCA but 3D Secure is not used?

If a transaction falls within the scope of PSD2 and no valid exemption is applied, the issuing bank is likely to return a Soft decline code.

The merchant must then restart the payment flow using 3D Secure to prompt the customer for the necessary two-factor authentication before the payment can be successfully processed.

Does SCA apply to transactions with customers outside of Europe?

No, SCA rules apply to transactions where both the cardholder's bank (issuer) and the merchant's payment processor (acquirer) are located within the European Economic Area (EEA) or the UK. This is often referred to as a 'two-leg' transaction.

If a US customer is buying from a UK merchant, SCA does not apply. However, if a UK customer is buying from a US merchant using a European acquirer, SCA rules would still be triggered.

How does SCA work for Subscription billing?

For subscriptions and recurring billing, SCA is typically required only for the initial transaction when the customer sets up the payment plan (a Customer-Initiated Transaction, or CIT).

All subsequent scheduled payments are considered Merchant-Initiated Transactions (MITs) and are out of scope for SCA, meaning they can be processed without customer interaction.

It is crucial for the merchant to correctly flag the initial and subsequent transactions so the issuer understands the payment series and does not incorrectly decline the MITs.

What is a Transaction Risk Analysis (TRA) exemption?

Transaction Risk Analysis (TRA) is an important SCA exemption that allows a payment provider (like an acquirer) to request an exemption for transactions it assesses as low risk.

To be allowed to do this, the provider's own fraud rates must be below specific thresholds set by the regulation (e. g. , below 13 basis points to exempt transactions up to €100).

The issuer has the final say and can still demand authentication, but a successful TRA exemption allows for a frictionless payment flow, improving conversion. This exemption is a key competitive differentiator among acquirers.

Are all B2B payments exempt from SCA?

Not all B2B payments are automatically exempt. The SCA regulation provides an exemption for payments made with 'secure corporate payment' methods, such as corporate cards where the use is limited to authorised employees to pay a specific business.

Many virtual cards and lodge cards used in the travel industry fall into this category. However, payments made using standard company credit or debit cards are generally subject to the same SCA rules as consumer payments.

What happens if an SCA challenge fails or the customer abandons it?

If the customer fails to complete the authentication challenge (e. g. , enters the wrong password or closes the window), the authentication fails. The transaction will not be sent for authorisation and the payment is effectively abandoned.

This directly impacts conversion rates. Merchants can mitigate this by ensuring their Checkout is clear and helps guide the user, and by using retry strategies where appropriate, but ultimately a failed SCA attempt means a lost sale for that specific payment attempt.

See how Strong Customer Authentication plays out in practice

Industries and regions where this term drives real acquiring, routing, or dispute decisions.

Related terms

Apply with Cardflo

Ready to improve your payments setup?

Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.

Apply now