SardineCon SF/2026

Learn More
Card & payment fraud4 min de leitura

O que é Strong customer authentication (SCA)?

SUBSCRIBE

Strong customer authentication is a rule, best known from PSD2 in Europe, that payers be verified with at least two independent factors drawn from three types. Those types are something you know, something you have, and something you are, and combining them is meant to cut online card fraud.

What is SCA, in plain English?

Strong customer authentication is a regulatory requirement that a payer prove who they are using more than one kind of evidence. Instead of a single password, the customer must satisfy at least two independent factors, and those factors must come from different categories, so stealing one is not enough to get through.

The three categories are knowledge (something you know, like a PIN), possession (something you have, like a phone or token), and inherence (something you are, like a fingerprint or face). Requiring two from different buckets means an attacker who phishes a password still lacks the device or the biometric.

SCA is best known from PSD2 in Europe, where it became mandatory for many electronic payments. In practice, 3-D Secure is the most common way merchants meet it online, and the rules include defined exemptions, for low-value, recurring, or low-risk transactions, so not every payment has to carry the friction.

The three authentication factors

Factor type

What it is

Example

Knowledge

Something only the payer knows

A PIN, password, or passphrase

Possession

Something only the payer has

A phone, hardware token, or app that receives a one-time code

Inherence

Something the payer is

A fingerprint, face, or other biometric

The rule

One factor alone is not enough

At least two, from two different categories

What it looks like in practice

In practice

An online shopper in Europe checks out and is prompted to approve the payment in their banking app with a fingerprint. That single step satisfies SCA: possession of the phone plus the biometric are two factors from two categories, and the transaction is routed through 3-D Secure to record the authentication.

The same merchant applies an exemption to a small, low-value repeat purchase, letting it through without the prompt to protect conversion. The fraud team watches that exemption bucket closely, because if too many risky payments slip through under a loosely applied exemption, they reopen exactly the fraud gap SCA was built to close.

Why it matters to operators

SCA is a balancing act between security and conversion. Every authentication step cuts fraud but also adds friction that costs sales, so teams decide how widely to apply it and lean on exemptions to keep low-risk payments smooth. Tune it too tight and you lose good customers; too loose and the protection evaporates.

The exemptions are where the real risk lives. A poorly applied exemption, one that waves through payments that should have been challenged, reopens the very fraud gap SCA was meant to close. Watching for exemption abuse, and for fraud concentrating in the un-authenticated bucket, is what keeps the rule from becoming a checkbox that criminals route around.

What to watch in the data

  • Exemption concentration. Fraud clustering in transactions that skipped authentication under an exemption is a warning the exemption is too loose.
  • Authentication drop-off. High abandonment at the SCA step can mean friction is costing conversion or that flows are misconfigured.
  • Weak factor pairing. Two factors from the same category do not satisfy SCA and leave a real gap.
  • Exemption abuse. Payments engineered to stay just under low-value thresholds may be gaming the exemption rules.
  • Liability mismatches. Un-authenticated flows may not carry the liability shift, so fraud losses can land on the merchant.

Quick questions

What counts as strong customer authentication?

At least two independent factors from two of three categories: knowledge, possession, and inherence. A password plus a code sent to a phone qualifies; two passwords do not.

Is SCA the same as 3-D Secure?

No. SCA is the regulatory requirement; 3-D Secure is the most common technical way to meet it for online card payments. 3DS is a means to satisfy SCA, not the rule itself.

What are SCA exemptions?

Defined cases where authentication can be skipped to reduce friction, such as low-value, recurring, or low-risk transactions. They keep smooth checkout for payments judged unlikely to be fraud.

Why can exemptions be dangerous?

Because a poorly applied exemption lets risky payments through without a challenge, reopening the fraud gap SCA was meant to close. Fraud tends to migrate toward the un-authenticated bucket.

Does SCA apply everywhere?

It is most associated with PSD2 in Europe, but similar strong-authentication requirements exist in other regions. Teams need to know the specific rules and exemptions in the markets they serve.

How does SCA relate to the liability shift?

Authenticating a payment, often via 3DS, can shift fraud liability to the issuer. Skipping authentication under an exemption may leave the merchant carrying the loss, so the two interact directly.

Go deeper

O que saber junto com Strong customer authentication (SCA)