Strong Customer Authentication, commonly shortened to SCA, is a security method designed to make electronic payments and online account access harder for unauthorized people to abuse.
Instead of relying on a single password or payment-card detail, Strong Customer Authentication generally requires a customer to prove their identity using at least two independent authentication elements.
Those elements come from three categories: something the customer knows, something the customer possesses, and something the customer is.
In European payment regulation, SCA became an important part of the revised Payment Services Directive, commonly known as PSD2. The underlying objective is straightforward: strengthen payment authentication while reducing the risk that stolen credentials alone can be used to impersonate a legitimate customer.
This guide explains what Strong Customer Authentication means, how SCA works, the authentication factors involved, common examples and how it relates to technologies such as 3-D Secure.
What Is Strong Customer Authentication?
Strong Customer Authentication is an authentication process based on two or more independent elements selected from knowledge, possession and inherence.
In simple terms, a payment provider should not have to rely entirely on one piece of information to determine that you are really you.
For example, knowing a password may establish one authentication element. Confirming possession of a registered device may establish another.
Under the EU SCA framework, the authentication elements must also be sufficiently independent so that compromising one does not automatically compromise the reliability of the other.
This distinction is important. Entering two different passwords would not ordinarily provide the same security concept as combining a password with possession of a registered device because both passwords belong to the same general knowledge category.
Strong Customer Authentication in One Sentence
Strong Customer Authentication verifies a user with at least two independent factors from what they know, what they possess and what they are.
What Does SCA Stand For?
SCA stands for Strong Customer Authentication.
The term is commonly used in:
- online banking
- ecommerce payments
- card authentication
- payment applications
- digital wallets
- payment-service-provider systems
- account-access security
You may therefore encounter phrases such as SCA authentication, SCA payment, SCA required, or SCA verification during an online transaction.
Technically, saying "SCA authentication" is somewhat repetitive because the "A" in SCA already stands for authentication, but the phrase is widely used by people searching for information about the process.
What Are the Three Strong Customer Authentication Factors?
SCA authentication factors are divided into knowledge, possession and inherence.
1. Knowledge: Something You Know
A knowledge element is information that should be known only by the legitimate user. Examples can include a qualifying password or PIN.
The important point is that the information must function as a genuine secret. Information printed directly on a payment card, for example, should not automatically be treated as a valid SCA knowledge factor simply because the customer can read it.
2. Possession: Something You Possess
Possession involves proving control over something associated with the customer. This can include a registered mobile device, banking application, authentication device or other securely associated possession element.
Importantly, merely claiming to possess a device is not enough. The authentication system needs a reliable way to establish the relationship between the customer and that possession element.
3. Inherence: Something You Are
Inherence concerns characteristics associated with the individual. Biometric authentication is the most familiar example.
Depending on the implementation, this could involve technologies using fingerprint or facial recognition. Authentication mechanisms should be protected against unauthorized use and designed to minimize false acceptance of an unauthorized person.
How Does Strong Customer Authentication Work?
Consider a customer making an online purchase. After entering the necessary checkout information, the payment may trigger an additional authentication step.
The customer's banking application might ask them to confirm the transaction using a registered device and then verify themselves using another independent authentication element.
If the required authentication succeeds, the issuer can authorize the transaction subject to its normal risk and authorization checks.
Payment initiated -> authentication requested -> independent factors verified -> transaction authenticated -> authorization decision
Authentication and authorization should not be confused.
Authentication asks: "Can we establish that this is the legitimate customer?"
Authorization asks: "Should this particular payment be approved?"
A customer can successfully authenticate and still have a transaction declined for another reason, such as insufficient funds, issuer risk controls or account restrictions.
When Is Strong Customer Authentication Used?
Within the EU PSD2 framework, payment service providers generally apply SCA when a payer accesses a payment account online, initiates an electronic payment transaction or performs certain remote actions that may present a payment-fraud risk, subject to applicable exclusions and exemptions.
Not every payment necessarily results in the customer seeing an authentication challenge. Regulations contain exemptions and other circumstances that can affect when authentication is required. These can depend on the transaction, payment relationship, risk analysis and applicable jurisdiction.
A dedicated supporting article should cover this narrower intent: "When Is Strong Customer Authentication Required? SCA Rules and Exemptions Explained."
What Is Dynamic Linking in SCA?
For certain remote electronic payments, SCA includes an important security concept known as dynamic linking.
Dynamic linking connects authentication with the specific payment the customer intends to authorize. The authentication process should make the payer aware of the transaction amount and payee, and the generated authentication code should be specific to those transaction details.
Why does this matter? Authentication that only confirms "this person is logged in" says something about the user, but it does not necessarily prove that the user approved a particular payment to a particular recipient. Dynamic linking helps connect authentication to the transaction itself.
Strong Customer Authentication Example
Suppose Maria buys an item online. Her card information is entered during checkout. Her bank determines that additional authentication is required.
Maria receives a request inside her registered banking application. The application displays information about the purchase and asks her to authenticate using two qualifying factors.
After authentication succeeds, the bank continues processing the authorization request.
This illustrates why SCA is more than simply typing additional card information. The objective is to establish customer identity using independent authentication elements rather than treating static payment credentials as sufficient proof that the person presenting them is the legitimate cardholder.
Is SCA the Same as Two-Factor Authentication?
SCA and two-factor authentication (2FA) are closely related, but the terms are not completely interchangeable.
Two-factor authentication is a broad security concept used across many types of accounts and services. Strong Customer Authentication is a more specific payment-regulatory concept with requirements concerning the authentication elements, their independence and, for applicable remote electronic transactions, transaction-specific protections such as dynamic linking.
SCA is a form of multi-factor authentication, but not every generic 2FA implementation necessarily meets SCA requirements.
Is an SMS Code Strong Customer Authentication?
An SMS one-time password can potentially function as a possession element, provided the relevant regulatory and security requirements are satisfied.
But an SMS code by itself does not automatically create Strong Customer Authentication. SCA requires the appropriate combination of independent authentication elements.
This is why it is misleading to define SCA simply as "receiving an OTP." The authentication architecture matters more than the presence of a particular code.
What Is the Relationship Between SCA and 3-D Secure?
3-D Secure, including modern EMV 3-D Secure implementations, is commonly involved in authenticating ecommerce card payments. A shopper may recognize it when a card issuer requests additional verification during checkout.
But 3-D Secure and SCA are not synonyms.
SCA describes authentication requirements. 3-D Secure is a protocol that can support the authentication process for card-not-present payments.
What matters is the actual authentication method and factors used. This distinction is useful for merchants who assume that merely enabling a technology automatically means every transaction satisfies every SCA requirement.
Why Was Strong Customer Authentication Introduced?
Online payments created enormous convenience, but they also created situations where criminals could attempt transactions without physically presenting a payment card.
Traditional static credentials are problematic because credentials can potentially be copied, exposed through phishing, leaked in data breaches or otherwise compromised.
Strong Customer Authentication attempts to reduce reliance on static information. If one piece of information is compromised, an attacker should still face another independent authentication barrier.
Does SCA Prevent All Payment Fraud?
No. Strong Customer Authentication is an important security control, but it should not be treated as a complete fraud-prevention system.
Fraud can involve many different scenarios, including social engineering, account takeover, phishing, compromised credentials, malicious software, authorized push-payment scams, merchant abuse and other forms of deception.
Authentication primarily helps establish whether the person interacting with a payment system can satisfy the required identity checks. Payment providers and merchants still need additional controls such as transaction monitoring, behavioral analysis, risk scoring, secure account recovery, device intelligence and appropriate fraud-response procedures.
SCA should therefore be viewed as one layer within a broader payment-security strategy.
SCA and Card-Not-Present Fraud
Strong Customer Authentication is particularly relevant to card-not-present (CNP) payments, where the merchant does not physically handle the customer's card.
Examples include many ecommerce purchases and remote digital transactions. Because a physical card and customer are not standing at a checkout terminal, online payment systems need other mechanisms to establish trust.
SCA can strengthen this process by requiring authentication beyond static card credentials.
Recommended supporting article: "Card-Not-Present Fraud Explained: Meaning, Examples, Risks and Prevention."
Strong Customer Authentication for Merchants
From a merchant's perspective, SCA can affect the checkout experience. Poorly implemented authentication may create unnecessary friction, while weak payment controls may increase exposure to fraud.
Merchants therefore need payment providers and checkout systems capable of supporting modern authentication flows without unnecessarily disrupting legitimate customers.
This means considering payment-provider compatibility, 3-D Secure support, transaction data quality, mobile usability, accessibility and how failed authentication is handled.
Merchants should not attempt to manipulate transactions merely to avoid authentication. The goal should be to build a checkout experience that properly supports the payment provider's authentication and risk requirements.
Strong Customer Authentication for Consumers
For consumers, SCA often appears as an extra identity-confirmation step. You might be asked to approve a transaction through your bank's application, provide another qualifying authentication element or complete another secure verification process.
An additional verification request does not necessarily mean your account is compromised. It can simply be part of the payment provider's security requirements.
However, consumers should remain cautious about unexpected authentication requests. If you receive an authentication prompt for a payment you did not initiate, do not approve it simply because the notification appears to come from your bank. Contact the financial institution using a trusted method.
Strong Customer Authentication in the EU and UK
SCA became a major component of payment authentication under Europe's PSD2 framework.
The EU requirements are supported by Commission Delegated Regulation (EU) 2018/389, which contains regulatory technical standards governing Strong Customer Authentication and secure communication.
The United Kingdom has its own SCA technical standards under its payments framework following Brexit. Businesses operating across jurisdictions should verify the rules applicable to their payment services rather than assuming one implementation automatically satisfies every country's regulatory requirements.
Strong Customer Authentication vs Password-Only Security
A password-only payment system depends heavily on one secret. If that password is stolen, guessed or exposed, an attacker may have the same credential as the legitimate user.
SCA aims to reduce that weakness by requiring independent evidence.
- Password compromised: the attacker may still lack the registered possession factor.
- Device compromised: the attacker may still lack the required knowledge or inherence factor.
This separation is why independence between authentication elements is central to the SCA concept. Breaking one authentication element should not automatically defeat the entire authentication process.
Frequently Asked Questions
What is Strong Customer Authentication?
Strong Customer Authentication is a security process that authenticates a customer using at least two independent elements from the categories of knowledge, possession and inherence.
What does SCA mean in banking?
In banking and payments, SCA means Strong Customer Authentication. It is used to strengthen identity verification for activities such as electronic payments and online account access where the applicable rules require it.
What are the three SCA authentication factors?
The three categories are knowledge - something the customer knows; possession - something the customer possesses; and inherence - something associated with who the customer is.
Does SCA require all three factors?
No. Strong Customer Authentication generally requires two or more qualifying independent elements, not necessarily all three categories.
Is SCA the same as 3-D Secure?
No. SCA describes authentication requirements, while 3-D Secure is a protocol commonly used to support cardholder authentication in ecommerce.
Is an OTP enough for SCA?
Not by itself. A one-time password may participate in an SCA process, but the result depends on the authentication factors used and whether the applicable independence and security requirements are satisfied.
What does "SCA required" mean?
It generally means that the payment provider requires the customer to complete qualifying Strong Customer Authentication before proceeding with the relevant action or transaction.
Why does my bank ask me to authenticate an online purchase?
The bank may require additional authentication to establish that the person attempting the payment is the legitimate customer and to comply with applicable payment-security requirements.
Can SCA stop stolen-card fraud?
SCA can make unauthorized use of compromised credentials more difficult, but it cannot prevent every form of payment fraud. It works best as one component of a broader fraud-prevention system.
Is Strong Customer Authentication only used in Europe?
The specific term is strongly associated with European and UK payment regulation, although multi-factor and risk-based authentication technologies are used globally.
Final Thoughts
Strong Customer Authentication represents an important shift away from treating static payment credentials as sufficient proof of identity.
Instead, SCA uses multiple independent authentication elements to establish greater confidence that a customer requesting access or initiating a payment is legitimate.
The key concepts to remember are simple: knowledge + possession + inherence, with at least two qualifying independent elements used where SCA applies.
For remote electronic payments, additional protections such as dynamic linking can connect authentication to the specific amount and recipient being approved.
For consumers, that can mean an additional verification step. For merchants and payment providers, it means authentication must be built into the payment experience thoughtfully. And for payment security as a whole, SCA should be understood as an important layer of protection rather than a complete solution to every type of fraud.



