Skip to main content
Back to the wiki
Account Security

What Is Strong Customer Authentication (SCA)?

Last updated on August 4, 2026

Strong Customer Authentication (SCA) is the requirement under the EU's revised Payment Services Directive (PSD2) that electronic payments and account access in the European Economic Area be confirmed with at least two independent authentication factors, drawn from knowledge (a PIN or password), possession (a phone or card), and inherence (a fingerprint or face). For remote card payments the rule adds dynamic linking: the authentication code must be cryptographically tied to the specific amount and payee, so a confirmation captured for one transaction cannot bless another. In practice, SCA is why European online purchases so often end in a banking-app prompt: the regulation rebuilt the checkout's last step around the cardholder's bank.

How the flow works

The merchant does not see the factors. The technical vehicle is 3-D Secure (3DS2): the checkout hands the transaction to the cardholder's issuing bank, which decides how to authenticate, typically an app confirmation bound to the displayed amount and merchant. Because a mandatory challenge on every purchase would be commercially brutal, the regulation defines exemptions the ecosystem leans on heavily: low-value transactions, recurring payments after the first, trusted beneficiaries the customer has allowlisted, and transaction risk analysis (TRA), which lets low-risk payments skip the challenge as long as the acquirer's fraud rates stay under regulatory thresholds. Most European checkout traffic flows through these exemptions: frictionless when risk assessment says so, challenged when it does not.

What SCA did to fraud

The intent was to squeeze card-not-present fraud, and measured effects followed: European payment authorities have reported substantially lower fraud rates on SCA-authenticated remote transactions than on unauthenticated ones. The pressure redistributed the problem rather than deleting it. Fraud shifted toward the paths SCA does not cover: social engineering that talks victims into authenticating fraudulent payments themselves, MFA bypass techniques against the confirming factor, and probing of the exemption machinery, where automation tests which amounts, merchants, and patterns sail through unchallenged. The exemption logic is exactly a risk-based authentication system, and like every such system its weakest input is traffic whose nature it misjudges.

The merchant's remaining share

SCA moved authentication to the banks, but merchants still own the surfaces around it. Checkout endpoints remain targets for automated card testing that burns authorization fees and poisons the very fraud metrics TRA exemptions depend on; account pages, stored cards, and one-click flows remain targets for account takeover. Human verification such as CaptchaFox in front of checkout and account endpoints keeps scripted traffic out of the payment flow before 3DS ever engages, which protects conversion twice: bots stop consuming authorizations, and clean traffic keeps exemption thresholds low so genuine customers see fewer challenges. Under SCA, a merchant's bot hygiene is quietly part of its checkout friction budget.

About CaptchaFox

CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.

To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.

Related terms

What Is Two-Factor Authentication (2FA)?

Two-factor authentication secures logins by requiring a second, independent proof of identity beyond the password, whether knowledge, possession, or biometrics.

Read more
What Is a Datacenter Proxy?

A datacenter proxy routes traffic through servers in commercial hosting facilities: fast and cheap, but recognizable by its network of origin.

Read more
What Is a DDoS Attack?

A DDoS attack floods a service with traffic from many sources at once to make it unavailable, from raw bandwidth floods to stealthy application-layer attacks.

Read more
What Is a False Positive Rate?

The false positive rate is the share of legitimate users a security system wrongly flags as threats, the metric that decides what protection really costs.

Read more

Fight bots and protect your users' data.

Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.

CaptchaFox protecting websites on desktop and mobile devices