- Full name
- Revised Payment Services Directive — Strong Customer Authentication (PSD2 SCA)
- Region
- European Economic Area (PSD3 / PSR forthcoming)
- Applies to
- Payment service providers operating in the EEA: banks, payment institutions, e-money institutions, account-information service providers (AISPs), and payment-initiation service providers (PISPs).
PSD2 (Directive (EU) 2015/2366) and its Regulatory Technical Standards on Strong Customer Authentication and Common and Secure Communication (Commission Delegated Regulation (EU) 2018/389) set the baseline for customer authentication in EEA payments. PSD3 and the Payment Services Regulation, in the EU legislative pipeline, will tighten the regime further. SCA principles — independence of factors, dynamic linking, exemption logic — are the modern reference for customer-facing identity design.