Start with Identity
← Glossary
Compliance

Strong Customer Authentication (SCA)

The PSD2 requirement that electronic payment authentication use at least two of: knowledge, possession, inherence. Plus dynamic linking, the auth factor must be tied to the specific transaction amount and payee.

Dynamic linking is what separates SCA from ordinary MFA: the authentication has to be cryptographically tied to the amount and the payee, and the user has to see them. That rules out an approval prompt that just says "confirm sign-in". Exemptions for low-value and recurring payments exist and are where most of the implementation complexity actually sits.

See also: PSD2, MFA, step-up auth, FAPI

Related terms
Last reviewed By SWI Community TeamSuggest a correctionHow we research