On this page
- How SCA works
- 3DS2 and the frictionless/challenge split
- Digital wallet SCA requirements (EBA 2023)
- What qualifies as an SCA knowledge element (EBA Q&A 2024)
- Conversion impact
- SCA exemptions
- Transaction Risk Analysis (TRA)
- Low-value transaction (LVT)
- Recurring fixed-amount transactions
- Merchant-initiated transactions (MIT)
- MOTO
- Trusted beneficiary (merchant whitelisting)
- American Express special case
- PSP exemption optimisation and the frictionless rate lever
- Common exemption programme failure modes
- Liability rules
- PSD3 / PSR (2025–2026 developments)
- Timeline
- SCA changes under PSR
- Verification of Payee (VoP)
- APP fraud and liability
- EBA fraud findings (2024)
- Fraud displacement post-SCA
- UK divergence post-Brexit
- Key terms
- Contradictions
- Benchmarks (as-of 2026-08-01)
- Mobile vs. browser 3DS authentication gap
- SCA coverage asymmetry across payment types (EBA/ECB 2025)
- EMV 3DS Specification Evolution
Strong Customer Authentication (SCA / PSD2)
Strong Customer Authentication (SCA / PSD2)
Strong Customer Authentication (SCA) is a regulatory requirement under the EU's Payment Services Directive 2 (PSD2), mandating multi-factor verification for customer-initiated electronic payments within the European Economic Area. It is the primary mechanism for reducing card-not-present fraud in European ecommerce, but also the leading source of authentication-related checkout friction. Its successor framework — the Payment Services Regulation (PSR), agreed politically in November 2025 and formally published April 2026 — carries SCA into PSD3 / PSR.
How SCA works
SCA requires at least two of three independent elements — knowledge (PIN/password), possession (authenticated device), and inherence (biometric) — for all customer-initiated electronic payments where both the merchant's acquirer and the cardholder's issuer are in the EEA. (Stripe, stripe.com/guides/strong-customer-authentication, undated/current)
One-leg-out transactions — where only one party is inside the EEA — fall outside SCA scope. (Stripe, op. cit.)
3DS2 and the frictionless/challenge split
3D Secure (3DS2) is the primary protocol for SCA compliance on card-not-present transactions. It supports two paths: (Stripe, op. cit.; 3dsecure2.com, undated)
- Frictionless flow: the issuer's Access Control Server (ACS) authenticates the cardholder passively using risk signals (transaction value, new vs. returning customer, transactional history, behavioural history, device data) without requiring customer input
- Challenge flow: the cardholder is prompted to verify identity (OTP, biometric challenge)
The design target of 3DS2 is that the challenge path occurs in only a small percentage of transactions, with the majority resolved frictionlessly. (3dsecure2.com, op. cit.) Web sources indicate that a well-tuned 3DS2 integration should achieve a frictionless rate above 80%; France recorded a 40% increase in frictionless flows in H1 2024 as issuers began approving more exemption requests when enriched data is provided over 3DS rails. (Ravelin, ravelin.com/blog/sca-transaction-optimization-guide-exemptions, 2025-07-24 — as-of 2025-07-24)
Digital wallet SCA requirements (EBA 2023)
EBA issued an opinion on SCA for digital wallet operations (2023-01-31) confirming the following rules for issuers and wallet providers:
- Enrolling a payment card to a digital wallet requires SCA under Art. 97(1)(c) PSD2 — the action implies risk of fraud or abuse (as-of 2023-01-31)
- Initiating payments via a tokenised/digital wallet card requires SCA under Art. 97(1)(b), unless a specific RTS exemption applies (as-of 2023-01-31)
- A phone screen-unlock mechanism (biometric or PIN) is not a valid SCA possession or inherence element for adding a card to a wallet, if that mechanism is not under the card issuer's control (EBA Q&A 6145) (as-of 2023-01-31)
- Issuing a new token to replace a prior one, and binding it to a device or user, requires SCA (EBA Q&A 6464) (as-of 2023-01-31)
- Issuers may contractually outsource the SCA provision to Digital Wallets providers, but SCA compliance responsibility cannot be outsourced — issuers remain fully responsible (as-of 2023-01-31)
(EBA, eba.europa.eu, 2023-01-31)
What qualifies as an SCA knowledge element (EBA Q&A 2024)
EBA Q&A 2024_7286 (submitted 2024-12-18, published 2025-08-29) clarified:
- An API key may constitute a valid SCA knowledge element under PSD2 / Commission Delegated Regulation 2018/389, subject to implementation meeting Art. 6(1) (confidentiality), Art. 9 (independence of elements), and Art. 24(2)(b) (remote association of PSU identity with credentials) of the RTS on SCA (as-of 2025-08-29)
- A user ID does not constitute a valid SCA knowledge element, per EBA Opinion EBA-Op-2018-04 (as-of 2025-08-29)
(EBA, eba.europa.eu/single-rule-book-qa/qna/view/publicId/2024_7286, as-of 2025-08-29)
Conversion impact
SCA challenge friction can cause significant transaction abandonment. (Stripe, op. cit.) Web sources and PSP documentation (2024–2025) suggest up to 30% of 3DS transactions can be lost through the checkout funnel due to user drop-off, challenge failure, and issuer-driven declines; 3DS1's redirect model was the primary cause of friction, while 3DS2's native SDK approach significantly reduces but does not eliminate drop-off. (Multiple PSP sources — Stripe/Adyen/Ravelin, 2024 — as-of 2024)
Stripe analysis of EU/UK regulated markets (2024) shows SCA has prevented approximately €900 million worth of fraud per year, citing a European Commission publication. (Stripe Blog, stripe.com/blog/surprising-findings-from-our-analysis-of-3ds-transactions-in-the-us, 2024-08-05 — as-of 2024-08-05)
From 1 October 2023, Visa raised fees by 0.025% for online purchases in Europe that do not use a Visa network token, 3D Secure authentication, Apple Pay, or Google Pay — creating a direct commercial incentive for SCA adoption beyond regulatory compliance. (Checkout.com, checkout.com/blog/sca-for-ecommerce-businesses, 2023-10-31 — as-of 2023-10-31)
SCA exemptions
Exemptions are requests, not guarantees: the issuer makes the final decision to accept or reject each exemption; if rejected, the PSP receives a soft-decline code and must resubmit with a full SCA challenge. (Stripe, op. cit.)
Transaction Risk Analysis (TRA)
The most commercially significant exemption. A PSP may request exemption if its rolling fraud rate falls below defined EBA thresholds: (Stripe, op. cit.; multiple PSP docs, 2024)
| Transaction threshold | Maximum fraud rate |
|---|---|
| Under €100 / £85 | 0.13% |
| Under €250 / £220 | 0.06% |
| Under €500 / £440 | 0.01% |
| Over €500 | No exemption — SCA always required |
The PSP's fraud rate must be recalculated and refreshed every 90 days to maintain TRA eligibility. (Multiple PSP docs, 2024 — as-of 2024)
Low-value transaction (LVT)
Payments below €30 / £25 are exempt, but the issuer must revert to full authentication once the exemption has been applied five consecutive times or cumulative exempt spend exceeds €100 / £85 since the last full authentication. (Stripe, op. cit. — as-of 2026-07-19)
Recurring fixed-amount transactions
Recurring transactions for the same amount to the same merchant are exempt after the first authenticated payment. This exemption is broadly supported by European banks and is the primary lever for subscription businesses. (Stripe, op. cit.)
Merchant-initiated transactions (MIT)
MITs — where the merchant charges a saved card without the customer present — fall outside SCA scope entirely, provided the card was authenticated at enrolment and a mandate was obtained. Variable-amount MIT may still fall in scope depending on acquirer guidance. (Ravelin, op. cit., 2025-07-24) Under PSD3 / PSR, MIT is explicitly carved out of SCA requirements for subsequent charges following the initial authenticated mandate. (Norton Rose Fulbright, summary cited in web search, 2026)
MOTO
Mail order / telephone order transactions fall outside SCA scope and do not require 3DS, but must be flagged as MOTO in the authorization request; the issuer retains the right to decline. (Stripe, op. cit.)
Trusted beneficiary (merchant whitelisting)
Trusted beneficiary has seen slow adoption among European banks, limiting its practical use as an exemption mechanism. (Stripe, op. cit. — as-of 2026-07-19)
American Express special case
All EEA and UK American Express transactions require authentication regardless of whether they would otherwise qualify for an exemption. (Ravelin, op. cit., 2025-07-24)
PSP exemption optimisation and the frictionless rate lever
Moving from 40% to 70% frictionless rate (30 pp improvement) translates to approximately 5–7 pp authorization rate improvement. On $2B annualised TPV, this represents $100M–$140M of additional successfully authorized volume per year. Every 10 pp frictionless rate improvement is worth approximately 1.5–2.5 pp authorization rate. (rzifi.com, rzifi.com/blog/psd2-sca-exemptions-tra-low-value-recurring/, 2026-05-20 — practitioner estimate, not independently verified as-of 2026-05-20)
Stripe reports that merchants using Stripe's AI-powered 3DS optimisations see on average a +1.20% conversion uplift while reducing fraud on all transactions by 7.67%. Stripe's intelligent 3DS trigger is backed by a "multihead model"; early users have seen >30% reduction in fraud on eligible transactions. (Stripe, stripe.com/blog/3ds-trends-in-regulated-markets, 2025-08-26 — first-party Stripe platform data as-of 2025)
Adyen's Dynamic 3D Secure (D3DS) is a rules engine allowing merchants to configure rule-based 3DS routing — applying 3DS selectively based on risk signals, exemptions, and transaction characteristics including issuer country, shopper country, payment method, device type, amount, BIN range, and custom risk rules. Adyen's risk-based exemptions (rolling out from July 2026 to select companies using Protect Premium) use TRA exemptions inside PSD2 markets to skip 3DS for low-risk transactions. Adyen claims authorization rate uplifts of up to 10% from risk-based exemptions. (Adyen, docs.adyen.com/risk-management/dynamic-3d-secure, 2026 — as-of 2026)
Step-up (challenge) recovery flows — including OTP resend, friendly error copy, offline-authentication retry, and fallback to alternative payment methods — recover an estimated 5–15% of transactions that would otherwise be abandoned mid-authentication. These are considered part of the exemption optimisation programme. (rzifi.com, 2026-05-20 — practitioner estimate)
Common exemption programme failure modes
Six production failure modes that break SCA exemption programmes in practice (rzifi.com, rzifi.com/blog/psd2-sca-exemptions-tra-low-value-recurring/, 2026-05-20):
- Stale per-issuer scoring — issuers change risk models without notice; exemption eligibility must be re-scored every 30 days, not set-and-forget
- Low-value counter desynchronisation — issuer and acquirer track the LVT cumulative counter independently; acquirer cannot see the issuer's counter, so an exemption request may be rejected without warning
- Recurring-amount drift — any amount change (including rounding differences, currency conversion, or tax) resets the recurring-exemption cycle and triggers SCA on the next charge
- MIT flag at capture rather than authorisation — the MIT indicator must be sent at authorisation, not at settlement/capture; late flagging results in the authorisation being treated as a CIT (SCA required)
- Scheme TRA reporting lag — schemes' published fraud rate (used to determine TRA eligibility tier) lags real-time internal data by 7–10 days, creating a gap between what the PSP sees internally and what the scheme enforces
- Cross-border exemption rules — issuers outside the EEA are under no obligation to honour exemption requests from EEA acquirers; transactions routed cross-border may trigger full authentication regardless of exemption eligibility
Liability rules
When a 3DS challenge is completed successfully, liability for fraudulent chargebacks shifts to the issuer. When an SCA exemption is applied (whether via 3DS rails or direct authorisation), fraud dispute liability stays with the merchant/acquirer. (Stripe, op. cit.)
Frictionless 3DS liability ownership is card-scheme-specific and complex. Stripe states frictionless 3DS success (without exemption) results in issuer liability but notes this depends on "3DS challenge indicator" and network rules. Ravelin states each card scheme will have different rules on whether liability shifts to issuer or acquirer when an exemption is accepted or delegated authentication is used. Sources do not disagree but both acknowledge practitioners should verify scheme-specific rules rather than assuming frictionless = issuer liability. (Stripe, op. cit.; Ravelin, ravelin.com/blog/sca-transaction-optimization-guide-exemptions, 2025-07-24)
PSD3 / PSR (2025–2026 developments)
Timeline
Provisional political agreement on PSD3 and the Payment Services Regulation (PSR) was reached on 27 November 2025. (OneSpan, onespan.com/blog/psd3-psr-updates-2025, 2025-12-16) The EU Council published the final compromise texts on 23 April 2026. Formal adoption and publication in the Official Journal is expected late spring/early summer 2026; full application anticipated H1 2028 after a 21-month transition period. (Clifford Chance, impact-of-psd3-are-you-ready.pdf, 2026-04-28 — as-of 2026-04-28)
Most ecommerce businesses should aim to have systems fully PSR-compliant by late 2027 or early 2028. (Mollie, mollie.com/growth/guide-to-psd3-psr, updated 2026 — as-of 2026-04)
After the PSR enters into force, the EBA will develop new RTS for SCA and fraud detection — meaning the full PSR SCA ruleset will not be final until EBA RTS are published, likely 2027+. (OneSpan, op. cit., 2025-12-16)
SCA changes under PSR
- Authentication factor rules: The PSR redefines SCA to allow two elements from the same category only for the inherence (biometric) category — e.g., physiological biometric + behavioural biometric. Two elements from possession or knowledge categories are NOT permitted. (OneSpan, op. cit.; narrowed from the European Commission's June 2023 draft, which proposed allowing same-category two-factor across all three categories)
- EUDI Wallet: PSPs must accept European Digital Identity (EUDI) Wallets for SCA. EU Member States must offer at least one EUDI Wallet to all citizens by end-2026 under eIDAS 2.0. The EBA is mandated to update SCA RTS to account for EUDI wallets. (Clifford Chance, op. cit., 2026-04-28)
- Contactless NFC: Dynamic linking requirements extended to contactless NFC payments (e.g., smartphone wallets) unless an SCA exemption applies. (Clifford Chance, op. cit.)
- Transaction monitoring: New mandatory requirements including device intelligence (device fingerprint, malware/remote-access-tool detection) and behavioural intelligence (typing patterns, touch behaviour, speed between operations). (OneSpan, op. cit.)
- Accessibility: New SCA accessibility obligations requiring PSPs to provide SCA methods accessible to elderly or disabled users and those without smartphones, free of charge. (Clifford Chance, op. cit.)
- TSP liability: Technical service providers (TSPs) are now liable for direct financial damage caused by failure to support SCA application, capped at the transaction amount. (Clifford Chance, op. cit.)
- Biometrics preferred: PSR SCA 2.0 framework favours biometrics (Face ID, fingerprint) as the preferred factor due to phishing resistance; robust SCA required at digital wallet enrolment to prevent fraudulent device binding. (Mollie, op. cit.)
Verification of Payee (VoP)
Under the PSR, Verification of Payee (VoP) (IBAN/name matching) becomes mandatory for all credit transfers — instant and non-instant, euro and non-euro — extending beyond the Instant Payments Regulation (EU) 2024/886 scope (which covers only euro instant payments). See also SEPA Instant. (OneSpan, op. cit.)
APP fraud and liability
The PSR's Authorised Push Payment (APP) Fraud framework: the payer is liable by default for authorised fraud losses. The PSP is only liable if the fraud involved impersonation of the PSP itself, or if the PSP failed to apply VoP, transaction monitoring, or blocking controls correctly. (OneSpan, op. cit.)
Revolut data cited by OneSpan indicates approximately 75% of authorised (APP) fraud originates on social media platforms (Facebook, Instagram, WhatsApp, Telegram); the PSR allows PSPs to transfer liability to electronic communications providers in such cases. (OneSpan, op. cit., citing Revolut — as-of 2025-12-16)
The PSR also introduces cooling-off periods for changes to spending limits, making it harder for fraudsters to coerce victims into raising limits. (OneSpan, op. cit.)
EBA fraud findings (2024)
The EBA confirmed in April 2024 that SCA requirements under PSD2 have been successful in significantly reducing fraud involving credential theft, but fraudsters have adapted to more complex social-engineering techniques that SCA alone does not prevent. (EBA press release, eba.europa.eu, 2024-04-29)
Fraud displacement post-SCA
Forter transaction data from 2021 found that following SCA implementation, alternative payment method fraud (gift cards and similar) rose 60% in 2021 vs the pre-SCA period; Item Not Received (INR) fraud increased 30%; 33% of ecommerce decision-makers reported overall fraud rates increased under PSD2. The interpretation is that SCA hardened the card-at-checkout attack surface, displacing fraud to account-takeover, alternative payment channels, and post-purchase refund abuse. (Forter, forter.com/blog/the-real-impact-of-psd2/, 2021 — as-of 2021)
SCA's net fraud impact: EBA/ECB Joint Report on Payment Fraud (December 2025) confirms SCA "remains effective" at reducing card CNP fraud, and card fraud volumes grew only 4% YoY in 2024 vs 24% for credit transfer fraud. Forter (2021) found 33% of merchants reported fraud rates INCREASED under PSD2, attributed to displacement from card channels to alternative payment methods and post-purchase fraud. These are not necessarily contradictory — SCA reduced in-scope card fraud while fraud migrated to out-of-scope channels — but the operational implication differs by merchant type. (EBA/ECB EBA/REP/2025/40, 2025-12-15; Forter, 2021)
UK divergence post-Brexit
The UK Government confirmed in the King's Speech (13 May 2026) plans to fold the Payment Systems Regulator into the FCA as part of simplifying the UK's financial regulatory framework, and will begin removing SCA requirements from relevant technical standards to enable the FCA to incorporate aspects into its rules and guidance — moving toward more agile and outcome-based SCA regulation in the UK. (A&O Shearman, financial-services-horizon-report-2026 / King's Speech, 2026 — as-of 2026-05-13)
UK Finance published industry guidance on SCA in July 2025 covering requirements since 14 September 2019. (UK Finance, ukfinance.org.uk, 2025-07 — as-of 2025-07)
Key terms
| Term | Meaning |
|---|---|
| SCA | Strong Customer Authentication — the PSD2/PSR multi-factor authentication requirement |
| PSD2 | Payment Services Directive 2 — the EU directive mandating SCA |
| PSR | Payment Services Regulation — the PSD2 successor regulation (final texts April 2026) |
| 3DS2 | 3D Secure version 2 — the primary SCA protocol for card-not-present payments |
| ACS | Access Control Server — the issuer's SCA decision engine within 3DS2 |
| TRA | Transaction Risk Analysis — the primary SCA exemption for PSPs with low fraud rates |
| MIT | Merchant-Initiated Transaction — charges where the customer is not present; outside SCA scope |
| MOTO | Mail Order / Telephone Order — outside SCA scope but must be flagged |
| LVT | Low-Value Transaction — payments under €30/£25 can be exempt (with rolling limits) |
| VoP | Verification of Payee — mandatory IBAN/name matching under PSR |
| EUDI | European Digital Identity Wallet — mandated as an SCA factor under PSR |
| APP fraud | Authorised Push Payment fraud — social-engineering fraud where victim initiates the payment |
| EBA | European Banking Authority — the regulator that sets SCA RTS under PSD2/PSD3 |
Contradictions
PSR SCA same-category factors: The European Commission's June 2023 draft proposed allowing two authentication factors from the same category across all three categories (possession, knowledge, inherence). The final political agreement of November 2025 narrowed this: only the inherence (biometric) category permits two same-category factors. This narrowing from the original proposal was widely reported during the early legislative process. (OneSpan, onespan.com/blog/psd3-psr-updates-2025, 2025-12-16)
Benchmarks (as-of 2026-08-01)
| Metric | Value | Source | As-of |
|---|---|---|---|
| TRA fraud threshold (under €100) | 0.13% | Stripe / multiple PSPs | 2024 |
| TRA fraud threshold (under €250) | 0.06% | Stripe / multiple PSPs | 2024 |
| TRA fraud threshold (under €500) | 0.01% | Stripe / multiple PSPs | 2024 |
| LVT exemption limit | €30 / £25 | Stripe | 2026-07-19 |
| LVT consecutive-use limit | 5 uses or €100 cumulative | Stripe | 2026-07-19 |
| SCA fraud prevented (EU/UK, annual) | ~€900M | Stripe citing EC data | 2024-08-05 |
| PSR expected full application | H1 2028 | Clifford Chance | 2026-04-28 |
| Target frictionless rate | >80% | Ravelin (market guidance) | 2025-07-24 |
| France frictionless uplift H1 2024 | +40% | Ravelin | 2024 |
| EU total payment fraud 2024 | €4.2bn (+17% YoY) | EBA/ECB EBA/REP/2025/40 | 2025-12-15 |
| Card fraud rate outside EEA vs inside | 17× higher | EBA/ECB EBA/REP/2025/40 | 2025-12-15 |
| SCA coverage — credit transfers by value | ~77% | EBA/ECB EBA/REP/2025/40 | 2025-12-15 |
| SCA coverage — card transactions by number | ~40% | EBA/ECB EBA/REP/2025/40 | 2025-12-15 |
| Browser 3DS success rate | 77% | MultiSafepay | 2022-11 |
| Mobile app 3DS success rate | 52% | MultiSafepay | 2022-11 |
Mobile vs. browser 3DS authentication gap
MultiSafepay data from November 2022 found a material authentication success-rate gap by device context:
- Browser-based journeys: 77% 3DS success rate
- Mobile app journeys: 52% 3DS success rate
The gap is attributed to mobile app handling of OTP flows, push notification redirects, and banking app handoffs. (MultiSafepay, multisafepay.com/blog/how-psd2-strong-customer-authentication-affect-your-payment-success-rates, March 2024 citing November 2022 data — as-of 2022-11)
SCA coverage asymmetry across payment types (EBA/ECB 2025)
The EBA/ECB 2025 Joint Report on Payment Fraud (December 2025) reveals that SCA coverage rates differ markedly between payment types in 2024:
- SCA applied to approximately 77% of credit transfers by value in 2024 (as-of 2025-12-15)
- SCA applied to approximately ~40% of card transactions by number in 2024 (as-of 2025-12-15)
The gap reflects the higher prevalence of Merchant-Initiated Transactions (MIT), MOTO, one-leg-out, and exempt card transactions vs. credit transfers, where SCA exemption frameworks are less mature. (EBA/ECB, Joint Report on Payment Fraud EBA/REP/2025/40, eba.europa.eu, 2025-12-15)
EMV 3DS Specification Evolution
EMVCo maintains the EMV 3-D Secure specification. Current and recent versions (as-of 2026-08-01):
EMV 3DS v2.3.1 (2022-09-29): Introduced Secure Payment Confirmation (SPC) data elements enabling FIDO Alliance / W3C collaboration; new out-of-band (OOB) authentication flows allowing challenge via a separate channel; UI enhancements for high-risk transactions; Bridging Message Extension enabling v2.1 and v2.2 products to use selected v2.3.1 features. (EMVCo, emvco.com, 2022-09-29 — as-of 2022-09-29)
Draft EMV 3DS v2.4.0.0-1.0 (June 2026): EMVCo published Draft 1 of the Protocol and Core Functions Specification v2.4.0.0-1.0 on 2026-06-03; comment period closed 2026-07-01; subscriber-only access. Specification Bulletins SB 279 and SB 280 (covering v2.2.0 through v2.3.1.1) were published publicly on 2025-08-11. (EMVCo, emvco.com/emv-technologies/3-d-secure/, as-of 2026-06-29)
EUDI Wallet integration: EMVCo published "Use of the EUDI Wallet in EMV 3-D Secure Payment Authentication" (2025-06-23) addressing how EUDI Wallet will integrate with 3DS flows under PSD3 / PSR. (EMVCo, op. cit., as-of 2025-06-23)
PCI 3DS Core Security Standard v2.0: PCI SSC conducted an RFC on draft PCI 3DS Core Security Standard v2.0 and PCI 3DS Data Matrix v2.0 (RFC period 2023-12-06 to 2024-01-19) in response to updated EMVCo specs and the new Split-SDK architecture. The standard covers security controls for ACS, DS, 3DS Server, and Split-SDK Server. Final publication status as of 2026-08-01 was not confirmed from publicly available pages. (PCI SSC, blog.pcisecuritystandards.org, as-of 2023-12-06)