Strong Customer Authentication
Strong Customer Authentication (SCA) is a European regulatory requirement intended to make online and certain contactless payments more secure and to help reduce fraud. It generally asks that a customer confirm their identity using more than one type of verification when making a payment. It is a rule set by regulation rather than a specific technology.
Strong Customer Authentication (SCA) is a requirement of the EU Revised Directive on Payment Services (PSD2) applicable to payment service providers within the European context, intended to enhance the security of payments and limit fraud during the authentication process. It became a requirement for businesses processing online payments in Europe on September 14, 2019, and is intended to add additional layers of security to online and contactless offline payments. SCA is a regulatory obligation, not a single technical control; practitioners should note that its scope, applicable exemptions, and enforcement timelines vary by jurisdiction and have differed in practice, and that SCA is distinct from underlying authentication mechanisms such as 3-D Secure or multi-factor authentication, which may be used to help satisfy it but are governed separately. Readers should confirm current obligations against the applicable regulator's published rules, as regional requirements and effective dates differ.
Why it matters
Strong Customer Authentication represents a shift from voluntary or contractual security expectations to a binding regulatory obligation for payment service providers operating within the European context. Because SCA is grounded in the EU Revised Directive on Payment Services (PSD2) rather than in a card brand rule or a single technical standard, it changes how businesses processing online and certain contactless offline payments in Europe must approach the authentication step of a transaction. For merchants, acquirers, and processors, non-compliance can mean declined transactions or increased friction, since a payment that does not meet the applicable authentication requirement may be rejected by the customer's bank.
SCA is intended to enhance the security of payments and to help reduce fraud during the authentication process. It does this by generally requiring more than one type of verification when a customer makes a payment, rather than relying on a single credential that could be compromised. It is important to understand that SCA is a rule, not a mechanism: it defines an outcome and leaves the specific implementation to underlying tools such as 3-D Secure or multi-factor authentication, which are governed separately. No single control eliminates fraud, and SCA should be understood as one regulatory layer within a broader payment security posture.
Who it's relevant to
Inside SCA
Common questions
Answers to the questions practitioners most commonly ask about SCA.