PSD2 Strong Customer Authentication Explained for Merchants and Shoppers
The European Union’s second Payment Services Directive, known as PSD2, reshaped how online payments are authenticated across Europe. At its heart is a requirement called Strong Customer Authentication (SCA), designed to cut fraud by proving that the person making a payment is really the account holder. For merchants and shoppers alike, understanding SCA clarifies why checkout sometimes asks for that extra verification step.
The Two-Factor Foundation
SCA requires that most electronic payments be authenticated using at least two of three independent factors:
- Knowledge: something only the user knows, such as a password or PIN.
- Possession: something only the user has, such as a phone or hardware token.
- Inherence: something the user is, such as a fingerprint or face scan.
Crucially, the factors must be independent, so that compromising one does not compromise another. A password typed into a phone that also receives the confirmation is not truly two independent factors unless the channels are properly separated.
How SCA Appears at Checkout
For online card payments, SCA is typically delivered through 3-D Secure, the protocol behind Visa Secure and Mastercard Identity Check. When you pay, your bank may prompt you to confirm through its app or with a biometric, satisfying the two-factor requirement.
The goal is not to add friction for its own sake, but to shift liability and dramatically reduce unauthorized transactions.
SCA applies to more than just card payments. It also governs actions like accessing your account information online and initiating credit transfers, wherever the payer is in scope of the rules. This broad reach is deliberate, closing the gaps that fraudsters exploit when only some channels are protected.
The Exemptions That Keep Checkout Fast
Regulators recognized that authenticating every single payment would frustrate users. PSD2 therefore allows exemptions where risk is low:
- Low-value transactions: Payments under a set threshold may skip SCA, subject to cumulative limits.
- Transaction risk analysis: Providers with sufficiently low fraud rates can exempt payments they assess as low risk.
- Trusted beneficiaries: Users can whitelist merchants they trust to avoid repeated challenges.
- Recurring payments: Fixed-amount subscriptions require SCA only on the first payment.
Who Decides on an Exemption
An important nuance is that exemptions are requested but not guaranteed. A merchant or its payment provider may flag a transaction as eligible for an exemption, but the cardholder’s bank makes the final call. If the issuer is not comfortable, it can still demand a full challenge. This shared responsibility encourages both sides to keep fraud rates low.
What Merchants Should Do
Merchants benefit from designing checkout flows that request exemptions where appropriate while smoothly handling the cases that require a challenge. Passing rich data to the issuer improves the odds of a frictionless approval, and a well-implemented 3-D Secure integration shifts fraud liability away from the merchant. Testing the full range of outcomes, including declined and challenged transactions, prevents nasty surprises at launch.
Conclusion
SCA under PSD2 represents a deliberate balance between security and convenience. By requiring two independent factors while carving out sensible exemptions for low-risk payments, the framework has reduced fraud without grinding commerce to a halt. For shoppers, that occasional app prompt is the visible edge of a system working to keep their money safe.