CyberTRIZPEDIA

Strong Customer Authentication (SCA) Implementation

Control
PSD2-A30-001
Regulation
PSD2
Category
technical
Priority
critical
Frequency
monthly
Type
technical

What this control requires

Implement SCA using 2+ independent factors (knowledge/possession/inherence) for payment initiation and account access. Apply EBA RTS-approved exemptions with fraud rate monitoring. Implement dynamic linking for payment transactions. Target fraud rate below EBA reference rates.

Other PSD2 controls