Overview
Strong Customer Authentication is a PSD2 requirement that electronic payments and account access be verified with at least two of three independent factors: something the user knows, something they have, and something they are. In practice it is most often delivered through 3-D Secure 2, with a one-time code or a biometric confirmation in the banking app.
Why It Matters
In the EEA, a payment that skips a required SCA step is simply declined by the customer’s bank, so a badly implemented flow costs real revenue. The regulation allows exemptions — for low-value payments or trusted payees, for example — and handling them well is what separates a smooth checkout from one that asks for a code every time.
How Dotcode Applies It
We implement SCA with step-up authentication and exemption logic from the start, so users are challenged when the risk or the regulation calls for it and not on every transaction.