What is Strong Customer Authentication (SCA)?

Fintech

Strong Customer Authentication (SCA) is a PSD2 requirement mandating that electronic payments and account access use at least two independent verification factors — something the user knows, has, or is — typically implemented through 3-D Secure 2 with one-time codes or biometric confirmation.

Overview

Strong Customer Authentication is a PSD2 requirement that electronic payments and account access be verified with at least two of three independent factors: something the user knows, something they have, and something they are. In practice it is most often delivered through 3-D Secure 2, with a one-time code or a biometric confirmation in the banking app.

Why It Matters

In the EEA, a payment that skips a required SCA step is simply declined by the customer’s bank, so a badly implemented flow costs real revenue. The regulation allows exemptions — for low-value payments or trusted payees, for example — and handling them well is what separates a smooth checkout from one that asks for a code every time.

How Dotcode Applies It

We implement SCA with step-up authentication and exemption logic from the start, so users are challenged when the risk or the regulation calls for it and not on every transaction.

Work with Dotcode

Seeing payments declined at the authentication step?

Talk to Dotcode about building an SCA flow that keeps conversion up.

From the Blog

Explore expert insights on software development, product strategy, and tech trends.

All Posts