Strong Customer Authentication (SCA)
The EU requirement that electronic payments be authenticated with two independent factors — with a defined set of exemptions.
Industry & DomainSCA requires two of three independent factors: something the customer knows (a passcode), something they have (a device), something they are (a biometric). It is mandated by PSD2 for electronic payments in the European Economic Area, and in card checkout it is usually satisfied through 3-D Secure.
The exemptions are where product decisions live, because each removes friction from a category of traffic: low-value payments under €30 with counters, recurring payments of a fixed amount, merchant-initiated transactions, trusted beneficiaries the customer has whitelisted, and transaction risk analysis for providers with low enough fraud rates. Which exemptions you claim, and whether you build the flows to support them, is a design and configuration question with a direct conversion effect.
In practice
A marketplace applied SCA uniformly, including to €4 top-ups. Those had a 17% failure rate, mostly from users abandoning an SMS challenge for a trivial amount. Applying the low-value exemption with the required counters brought failures on that segment near zero and removed the largest source of support contacts.
Where teams get it wrong
- Not claiming exemptions, so low-risk traffic is challenged unnecessarily.
- Assuming SCA only affects card payments — it applies to account-to-account too.
- No fallback when the customer's device or channel is unavailable.
- Treating it as a payments-team configuration with no design involvement.
- Building flows that cannot support a trusted-beneficiary exemption, which repeat customers would benefit from most.
Learn more
You may ask
Frequently Asked Questions
What counts as strong customer authentication?
Two of three independent factors: knowledge (a passcode), possession (a registered device), or inherence (a biometric). Two of the same kind — a password and a security question — does not qualify.
What are the SCA exemptions?
Low-value transactions with cumulative counters, recurring fixed-amount payments, merchant-initiated transactions, trusted beneficiaries, and transaction risk analysis for providers below defined fraud thresholds.
Related terms
All terms- PSD2The EU payment services directive that mandated strong customer authentication and forced banks to open account access to licensed third parties.
- 3-D SecureThe card-network authentication step that shifts fraud liability from the merchant to the issuer — at a measurable cost in completed checkouts.
- Payment GatewayThe service that takes payment details from a checkout, passes them for authorisation, and returns the result.
- Open BankingA regulatory framework letting licensed third parties access bank account data, and initiate payments, with the account holder's explicit consent.
Defined by Mara Last reviewed .
Let's talk about your product.
Happy to look at what you're building and say where design would move the needle.
Contact Us