EBA Strong Customer Authentication RTS
Sectors
Articles (38)
Article 1 — Subject matterArticle 2 — General authentication requirementsArticle 3 — Review of the security measuresArticle 4 — Authentication codeArticle 5 — Dynamic linkingArticle 6 — Requirements of the elements categorised as knowledgeArticle 7 — Requirements of the elements categorised as possessionArticle 8 — Requirements of devices and software linked to elements categorised as inherenceArticle 9 — Independence of the elementsArticle 10 — Payment account informationArticle 11 — Contactless payments at point of saleArticle 12 — Unattended terminals for transport fares and parking feesArticle 13 — Trusted beneficiariesArticle 14 — Recurring transactionsArticle 15 — Credit transfers between accounts held by the same natural or legal personArticle 16 — Low-value transactionsArticle 17 — Secure corporate payment processes and protocolsArticle 18 — Transaction risk analysisArticle 19 — Calculation of fraud ratesArticle 20 — Cessation of exemptions based on transaction risk analysisArticle 21 — MonitoringArticle 22 — General requirementsArticle 23 — Creation and transmission of credentialsArticle 24 — Association with the payment service userArticle 25 — Delivery of credentials, authentication devices and softwareArticle 26 — Renewal of personalised security credentialsArticle 27 — Destruction, deactivation and revocationArticle 28 — Requirements for identificationArticle 29 — TraceabilityArticle 30 — General obligations for access interfacesArticle 31 — Access interface optionsArticle 32 — Obligations for a dedicated interfaceArticle 33 — Contingency measures for a dedicated interfaceArticle 34 — CertificatesArticle 35 — Security of communication sessionArticle 36 — Data exchangesArticle 37 — ReviewArticle 38 — Entry into force