PSD2 & SCA
Strong Customer Authentication requires an extra layer of authentication during checkout. SCA is mandatory in the EU and banks will decline payments that require SCA and don’t meet the criteria.
Last updated
Was this helpful?
Strong Customer Authentication requires an extra layer of authentication during checkout. SCA is mandatory in the EU and banks will decline payments that require SCA and don’t meet the criteria.
Last updated
Was this helpful?
Authentication is required when a payment isn’t eligible for an exemption or when the customer’s bank denies an exemption request. Authentication must occur while the customer is on-session, or using your website or app, so this step needs to happen on order confirmation.
Strong Customer Authentication requires an extra layer of authentication during checkout. Limiting verification to card number, address, and CVV is no longer enough. Now, sellers are required to verify the buyer’s identity according to at least two of the following three factors:
Possession: Something the user possesses, like a payment card.
Knowledge: Something the user knows, like a 3-D Secure code attached to an account.
Inherence: Something the user inherently is, like a fingerprint or other biometric impression.
To comply with SCA, at checkout, we collect 2 of the following 3 elements:
There are a number of types of Authentication, these are: Passive, biometric, and two-factor authentication.
This means the customer can be authenticated using either a one-time passcode or biometric ID, depending on what their bank supports.