Strong Customer Authentication (SCA)

Strong Customer Authentication (SCA) is a requirement of the EU Revised Directive on Payment Services (PSD2) on payment service providers within the European Economic Area.

It requires authentication to be based on the use of two or more independent factors: Knowledge (something only the user knows, e.g., password), Possession (something only the user possesses, e.g., mobile phone), and Inherence (something the user is, e.g., fingerprint). 3D Secure 2.0 is the primary protocol used to enforce SCA.