Solidgate logo in black and white.

Strong Customer Authentication

What is Strong Customer Authentication?

Strong Customer Authentication (SCA) is a security requirement that verifies a cardholder's identity using two or more independent factors before an electronic payment is approved. It was introduced by the European Union's revised to cut on online transactions.
SCA applies to most electronic payments initiated within the European Economic Area (EEA). Banks, merchants, and payment providers share responsibility for it: the requests authentication, and the merchant's checkout has to support it. When a payment can't be authenticated, the issuer usually declines it, so SCA affects approval rates as well as fraud.

Key requirements

SCA requires at least two of three authentication factors, each drawn from a different category so that compromising one doesn't compromise the others:
  • Knowledge – something the cardholder knows, such as a password or PIN.
  • Possession – something the cardholder has, such as a mobile device or a hardware token.
  • Inherence – something the cardholder is, such as a fingerprint or other .
The two factors must be genuinely independent, so a breach of one doesn't unlock the second. For online card payments, this authentication is usually carried out through , which can trigger a (for example, a one-time code or a biometric prompt) when the issuer wants to confirm the cardholder.

Who it applies to

SCA covers electronic payments the cardholder initiates directly, where both the cardholder's bank and the merchant's payment provider sit in the EEA. It reaches most online card payments and remote account access, but legislators defined exemptions to keep low-risk payments moving without extra friction. Key exemptions include:

Penalties for non-compliance

Non-compliance usually shows up as lost sales rather than direct fines. If a payment that requires authentication is submitted without it, the issuer declines it, so a checkout that doesn't support SCA loses otherwise-valid transactions. National regulators supervising PSD2 can also take enforcement action against banks and payment providers that fail to apply the rules. Authenticating a payment through 3D Secure additionally moves fraud for that transaction from the merchant to the issuer.

Related terms