Wallester
FreelancersNew
Business
White‑Label
Company
Log inStart freeTry demo
  1. Home
  2. Blog
  3. Resources
  4. Business tools
  5. Strong Customer Authentication (SCA) Guide: How It Works and Why It Matters

04 August 20267 min read

Strong Customer Authentication (SCA) Guide: How It Works and Why It Matters

Inspired by
Dmitri Bezsonov
Dmitri Bezsonov
Strong Customer Authentication (SCA) Guide: How It Works and Why It Matters

This guide explains strong customer authentication (SCA) under the PSD2 regulation, covering authentication factors, key exemptions, and electronic payment security. It details how card payment authentication functions and how implementing a compliant card programme protects transactions for modern e-commerce merchants.

Secure electronic payments protect modern commerce, shielding commercial entities and consumers from financial crime. Strong customer authentication (SCA) is the primary mechanism for confirming identities during online card payments and is a core standard of the Second Payment Services Directive (PSD2). By demanding multiple verification layers, this rule forms the foundation of modern payment authentication, making digital transactions safer for businesses and buyers alike.

What is strong customer authentication (SCA)?

SCA is a regulatory safety standard in the European Economic Area (EEA) and the UK requiring payment service providers to perform multi-factor verification on digital transactions.

Under the Payment Services Directive (PSD2), payment service providers must verify at least two independent factors before approving electronic payments. This protocol protects transactions by verifying that the person initiating a payment is the actual cardholder, curbing online financial crime. Verification draws from three categories: knowledge, possession, and inherence. If an unauthorised third party intercepts one factor, the other remains secure, preventing unauthorised transfers.

FactorDescriptionExample
KnowledgeSomething the user alone knowsPassword or PIN
PossessionSomething the user alone ownsMobile phone or token
InherenceSomething the user biologically isFingerprint scan

Q&A: Is two-factor authentication always required under SCA?

Two-factor verification is mandatory for payer-initiated electronic payments in Europe. However, specific low-value transactions, recurring payments, and low-risk sales can bypass these checks using regulatory exemptions approved by the cardholder’s payment service provider, maintaining swift and secure transaction flows.

When does SCA apply, and which exemptions exist?

SCA applies to payer-initiated electronic payments within the European Economic Area and the United Kingdom, though transactions meeting specific criteria can claim exemptions to bypass multi-factor checks.

Card payment authentication is required when a buyer accesses an online payment account or initiates an electronic transaction. To maintain a convenient payment process, PSD2 SCA rules define specific SCA exemptions that allow card issuers and acquirers to bypass multiple checks. When a transaction qualifies, the provider can skip the secondary step, creating a frictionless path for the user.

  • Low-value transactions: Payments under €30 are exempt, provided cumulative exempt payments do not exceed €100.
  • Transaction risk analysis (TRA): Processors can skip SCA if real-time monitoring shows risk is below regulatory thresholds.
  • Recurring transactions: For subscription payments, only the first transaction requires full SCA; subsequent payments remain exempt.
  • Trusted beneficiaries: Customers can add merchants to a whitelist, allowing future purchases to bypass checks.
  • Corporate payment systems: Payments processed through corporate systems, such as virtual cards, are exempt from authentication.

UK Finance Annual Fraud Report 2026 data shows that financial institutions prevented £1.68 billion in unauthorised fraud attempts during 2025. This high volume highlights why structured verification rules remain a necessary safeguard for commercial transactions.

Q&A: Can every online payment qualify for an exemption?

No payment is guaranteed to skip verification. Even if a transaction fits an exemption category, the card issuer holds final authority and can demand full authentication if they detect unusual spending patterns or suspicious login indicators on the account during the transaction.

How does 3D Secure support SCA compliance?

3D Secure is the primary technology protocol that card networks use to execute strong customer authentication and exchange verification data between merchants and card issuers.

In online payment security, EMV 3-D Secure serves as the communication protocol. It allows the acquirer and issuer to share rich data points about each electronic payment, verifying the identity of the cardholder before final approval.

The system supports frictionless authentication and challenge flows. When a merchant submits a payment, the 3DS engine evaluates risk parameters like device IDs. If the risk is low, the payment goes through frictionless authentication, requiring no manual action. Risky transactions enter the challenge flow, where customers provide a password, input an SMS code, or use biometrics to complete verification.

FlowCustomer actionExpected outcome
FrictionlessNo extra verification steps requiredInstant transaction approval
ChallengeEnters code or performs biometric checkApproval upon verification
Out-of-bandApproves via a separate mobile appSecure validation outside the merchant

This technology connects stakeholders in the payment cycle. Standardisation guarantees that banks can implement their preferred verification methods, whether they use dedicated apps, hardware devices, or physical readers, preventing payment disruptions.

Q&A: Does 3D Secure eliminate merchant liability for fraud?

When a transaction completes the 3D Secure flow, the liability for fraudulent chargebacks moves from the merchant to the cardholder’s bank. This protection applies even if the customer bypasses active verification through a frictionless flow approved by the card issuer during checkout.

How does Wallester White-Label support strong customer authentication?

Wallester White-Label provides a fully compliant card issuing platform with built-in 3D Secure capabilities, allowing businesses to launch custom card programmes with automated regulatory adherence.

Setting up secure payment infrastructure requires a card management platform that integrates with regulatory standards. Wallester White-Label offers a comprehensive Visa card programme infrastructure, handling the complexities of issuer-side authentication so businesses can focus on user experience.

The system includes direct API integration for seamless communication with card management systems. Businesses can deploy physical and virtual cards with configurable controls to set transaction limits, restrict spending, and monitor activities. Through built-in 3D Secure support, Wallester White-Label executes issuer-side authentication, supporting tokenisation and modern verification.

Businesses planning to launch their own payment card programme can explore how Wallester White-Label supports PSD2-compliant authentication, secure card transactions, and modern payment infrastructure.

Explore Wallester White-Label
Frequently asked questions
Does SCA apply outside the European Economic Area?
This regulatory standard operates on a one-leg-out principle, meaning it applies to transactions where only one of the payment service providers is within the European Economic Area or the United Kingdom. If a consumer in Europe purchases goods from an international merchant, the European issuer will generally demand multi-factor checks. If both the cardholder’s bank and the merchant’s payment processor are located outside Europe, these specific regulatory requirements do not apply to the transaction.
Can businesses choose their own authentication methods?
Commercial entities do not select verification protocols independently, as the cardholder’s bank decides which security measures are acceptable. Businesses must implement technical solutions like EMV 3-D Secure to support the transfer of authentication data. This allows the bank to present various validation options, including biometrics, password prompts, or mobile app notifications. Merchants can adjust their checkout flow to support these methods, but the final choice of verification mechanism rests with the card issuer.
Does SCA affect subscription payments?
This regulatory policy impacts subscription payments selectively depending on the transaction initiator. The initial transaction requires complete multi-factor verification when the customer signs up for the service. Subsequent billing cycles qualify as merchant-initiated transactions and skip secondary verification, provided the payment amount remains identical. If the business changes the subscription fee, the customer must complete a new card payment authentication process to validate the updated billing agreement directly with their card issuer.
Why do some payments skip authentication?
Specific transactions bypass verification checks through regulatory exemptions meant to balance security with client convenience. Low-value payments under thirty euros and low-risk transactions verified by real-time risk analysis systems are common categories that bypass checks. The cardholder’s bank allows these payments to proceed without multiple verification layers if the fraud risk remains below strict legal limits. This frictionless flow is approved on a case-by-case basis by the cardholder’s designated payment service provider.
What happens if an SCA check fails?
If verification checks fail during a transaction, the cardholder’s bank declines the payment immediately to prevent fraud. The merchant receives a declined transaction notification, prompting them to display an error message on the checkout screen. Customers must restart the payment process and complete verification using valid credentials or alternative authentication methods. If issues persist, the cardholder must contact their financial institution to verify their details or check for potential card blocks on their account.
Share article
Press contactdanielle.coimbra@wallester.com
Follow us
Wallester

Interested in Wallester?

Our sales team can help you get set up with the right solution to meet your business needs.

Contact sales

Find more articles

Optimising Cash Flow with Strategic AP Scheduling
Business tools

Optimising Cash Flow with Strategic AP Scheduling

By Dmitri Bezsonov06 August 20267 min read
team budgets
Business tools

What Counts as a “Team” When You’re Managing Company Money?

By Justin Zehmke05 August 20265 min read
Accounts Receivable Process: Steps, KPIs, and Practical Examples
Business tools

Accounts Receivable Process: Steps, KPIs, and Practical Examples

By Dmitri Bezsonov30 July 20267 min read
Vendor Management: Onboarding, Communication, and Payment Methods
Business tools

Vendor Management: Onboarding, Communication, and Payment Methods

By Dmitri Bezsonov29 July 20266 min read
FreelancersNew

Something new is coming, be the first to know!

Visa card in colors
Explore
Business
Cards
  • Corporate cards
  • Virtual cards
  • Payroll cards
  • Platinum cards
Features
  • Expense management
  • Accounting integration
  • Budget analytics
Industries
  • Media buying
  • Online retail
  • Yacht management
  • Transport and logistics
  • Fleet management
  • Travel and hospitality
Others
  • Pricing
  • API solutions
  • Help Center
White‑Label
Payment cards
  • Virtual card
  • Prepaid card
  • Debit card
  • Credit card
  • White‑Label card
Platform overview
  • White‑Label solutions
  • Card issuing
  • BIN sponsorship
  • Payment processing
Services
  • Tokenization
  • 3D Secure
  • Fraud monitoring
  • KYC/KYB and AML
  • PSD2
  • Mobile app
  • Apple Pay
  • Google Pay
Solutions across industries
  • Banks
  • Business loan providers
  • Consumer loan providers
  • Digital assets & exchange platforms
  • E-commerce marketplaces
  • Employers & gig platforms
  • FinTech companies
  • Gift & rewards cards
  • Insurance companies
  • Membership & loyalty cards
  • Peer-to-peer loan providers
  • Streaming platforms
Developers
  • API documentation
  • Card issuing API
  • Open-source example
Company
  • About us
  • Why Wallester
  • Affiliate Program
  • Visa Principal membership
  • Media Pack
  • Contact us
  • Careers
  • Wallester blog
  • FAQ
  • Legal notice
  • Privacy policy
  • Cookie policy
  • Annual reports
  • Complaints handling procedure
  • Business account & card agreement
  • Your rights when making payments in Europe
  • Visa partner
  • Accessibility statement

© 2026 Wallester AS All rights reserved.Wallester AS is a Payment Institution, authorized by the Finantsinspektsioon (Estonian Financial Supervision and Resolution Authority), and an official Visa Principal Member. Registration code: 11812882.