---
description: Learn what Strong Customer Authentication means for PSPs, product, and payments teams, and how it affects auth rates, exemptions, retries, and checkout...
title: Strong Customer Authentication: Definition &amp; Payments
image: https://cdn.smartretry.com/_next/static/media/og-image.0z0q4_5kazzzo.jpeg
---

[Skip to main content](#main-content)

# “Strong Customer Authentication”

SCA, PSD2 SCA

Published

March 8, 2026

Last updated

July 29, 2026

![Reading time](https://cdn.smartretry.com/cdn-cgi/image/width=3840&quality=75&format=auto&fit=cover/https%3A%2F%2Fcdn.smartretry.com%2F_next%2Fstatic%2Fmedia%2Fclock.337f-cmnyb532.svg)5 min

## Still letting failed transactions slip through?

SmartRetry turns declines into approvals - automatically, intelligently, and without changing your payment provider.

Email address Let’s talk

Table of Contents

Strong Customer Authentication (SCA) is a European regulatory requirement that reduces fraud by verifying a cardholder’s identity through at least two independent authentication factors. Implemented under the Revised Payment Services Directive (PSD2), this protocol requires shoppers to confirm online transactions using a combination of something they know, something they own, or something they are.

Strong Customer Authentication is a security mandate requiring multi-factor authentication for electronic payments initiated by customers within the European Economic Area. It appears during the checkout stage of the [payment processing flow](https://www.smartretry.com/blog/how-payments-work), typically triggering a [3D Secure challenge](https://www.smartretry.com/blog/3d-secure-fraud-friction) before the transaction reaches the issuing bank. This process matters operationally because failing to properly route or authenticate these payments leads to a transaction declined by the issuer, directly impacting a merchant’s [approval rate](https://www.smartretry.com/glossary/approval-rate).

## What is the core mechanism of Strong Customer Authentication?

To satisfy this mandate, a payment must be authenticated using at least two of three distinct categories. These categories ensure that the person initiating the payment is the legitimate cardholder rather than a bad actor with stolen card data.

The three available authentication factors are:

* **Knowledge:** Something only the user knows, such as a password or a PIN.
* **Possession:** Something only the user owns, such as a mobile device or a hardware token.
* **Inherence:** Something the user is, verified through biometrics like a fingerprint or facial recognition.

If a merchant processes a transaction requiring this level of security without gathering these factors, the issuing bank will legally reject the charge. This creates unnecessary payment issues and frustrates customers trying to complete their purchases.

## How does Strong Customer Authentication work in practice?

In the modern payment landscape, the primary tool used to facilitate this authentication is 3D Secure 2.0 (3DS2). This protocol allows merchants and issuers to exchange data in the background to verify the user without relying on outdated static passwords.

Here is a step-by-step look at how this process unfolds during a standard e-commerce transaction:

1. **Checkout initiation:** The customer enters their payment details and submits the order.
2. **Data exchange:** The merchant’s [payment gateway](https://www.smartretry.com/glossary/gateway) sends over 100 data points to the issuer to assess the risk of the transaction.
3. **Frictionless flow evaluation:** If the issuer determines the risk is low, they authenticate the user in the background without any visible interruption.
4. **Challenge flow execution:** If the issuer needs more proof, the customer receives a prompt on their device requesting biometric approval or a one-time password.
5. **Payment authorization:** Once the authentication succeeds, the merchant submits the transaction for final authorization and settlement.

When handled correctly, this flow minimizes checkout issues while ensuring full compliance with regional laws.

## When are payments exempt from Strong Customer Authentication?

Not every transaction requires a multi-factor challenge. To balance security with user experience, regulators established specific exemptions that merchants can request to bypass the friction of a challenge flow.

Low-value transactions are frequently exempt. Payments under 30 Euros generally process without a challenge, provided the customer has not exceeded a specific threshold of consecutive unauthenticated purchases.

[Merchant-initiated transactions](https://www.smartretry.com/glossary/merchant-initiated-transaction) are another critical exception. These are used heavily by software and digital businesses to bill customers on a recurring basis. Because the customer is not actively at the checkout screen, applying a challenge is impossible.

When processing these recurring charges, flagging them correctly as MITs prevents major subscription payment issues. 

Finally, Acquirer Transaction Risk Analysis (TRA) allows acquirers to bypass authentication for certain low-risk payments if their overall fraud rate remains below a strict regulatory threshold. However, the issuing bank always has the final say in the issuer response and can override any exemption request.

## Why does Strong Customer Authentication matter for operational teams?

For payment engineers and product managers, this authentication requirement acts as a major variable in checkout conversion rates. Finding the right balance between compliance, fraud prevention, and user friction requires continuous payment optimization.

If a merchant routes transactions poorly or fails to apply the correct exemptions, they will experience a sharp increase in false declines. Every time a valid card declined error occurs because of a technical misconfiguration, the business loses revenue and damages customer trust.

Properly categorizing transactions that fall out of scope, such as [cross-border payments](https://www.smartretry.com/blog/the-hidden-mechanics-of-cross-border-card-declines) where the issuer is outside the European Economic Area, helps bypass unnecessary friction. Teams must actively monitor their gateway to catch routing anomalies before they escalate into widespread payment failures.

## How do authentication requirements impact retry strategies?

Even with a highly optimized setup, merchants will inevitably encounter soft declines. A soft decline occurs when the issuer rejects the payment specifically because it lacks Strong Customer Authentication, returning a specific response code indicating that a multi-factor challenge is required.

Handling these soft declines gracefully is a vital part of payment recovery. If a merchant simply tries to push the same charge through again without changing the parameters, the bank will reject it repeatedly.

Instead, platforms like SmartRetry help businesses manage these scenarios by focusing on payment optimization and intelligent retries of declined payment transactions, helping merchants recover revenue and improve transaction approval rates. When an issuer demands authentication on a recurring charge, the system can systematically trigger an email or SMS to the customer, securely bringing them back into session to complete the challenge. 

Effectively managing these issuer demands allows businesses to reduce payment declines and successfully retry failed payments in a way that respects network rules and maximizes revenue.

## Strong Customer Authentication vs 3D Secure?

While often used interchangeably in casual conversations, these two terms represent entirely different concepts within the payment ecosystem.

Strong Customer Authentication is the legal and regulatory requirement governing how electronic payments must be verified in Europe. It dictates the rules, the necessary factors, and the allowed exemptions.

3D Secure is the technical protocol used by the card networks to actually enforce those rules. Think of the regulation as the building code, while 3D Secure is the physical lock on the door. You use the 3D Secure framework to meet the regulation, but the regulatory standard itself remains platform-agnostic.

### Frequently asked questions about this term

What is Strong Customer Authentication in payments?

It is a PSD2 requirement for many electronic payments in the EEA that verifies the cardholder with at least two independent factors.

How does Strong Customer Authentication work at checkout?

It usually runs through 3D Secure 2.0, where merchant and issuer exchange data for a frictionless check or trigger a challenge like biometrics or a one-time passcode.

Is Strong Customer Authentication the same as 3D Secure?

No. SCA is the regulatory requirement, while 3D Secure is the technical protocol commonly used to apply it during card payments.

Which payments can be exempt from Strong Customer Authentication?

Examples include some low-value payments, properly flagged merchant-initiated transactions, and low-risk payments under acquirer transaction risk analysis.

Why does Strong Customer Authentication matter for payment operations?

Incorrect routing, missing exemptions, or failed authentication can cause issuer declines, lower approval rates, add friction, and reduce recovered revenue on retries.

#### Share this article

[![Share on X](https://cdn.smartretry.com/cdn-cgi/image/width=3840&quality=75&format=auto&fit=cover/https%3A%2F%2Fcdn.smartretry.com%2F_next%2Fstatic%2Fmedia%2Ftwitter.21z6yr9njnznr.svg)](https://twitter.com/intent/tweet?text=Strong%20Customer%20Authentication&url=https%3A%2F%2Fwww.smartretry.com%2Fglossary%2Fstrong-customer-authentication "Share on X")[![Share on Facebook](https://cdn.smartretry.com/cdn-cgi/image/width=3840&quality=75&format=auto&fit=cover/https%3A%2F%2Fcdn.smartretry.com%2F_next%2Fstatic%2Fmedia%2Ffacebook.3sbfjbsxa26qg.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.smartretry.com%2Fglossary%2Fstrong-customer-authentication "Share on Facebook")[![Share on LinkedIn](https://cdn.smartretry.com/cdn-cgi/image/width=3840&quality=75&format=auto&fit=cover/https%3A%2F%2Fcdn.smartretry.com%2F_next%2Fstatic%2Fmedia%2Flinkedin.09sdc8tnlrn4a.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.smartretry.com%2Fglossary%2Fstrong-customer-authentication "Share on LinkedIn")

## Join our newsletter!

Real strategies to recover lost revenue - straight to your inbox

Email address Subscribe

---

## You might also find interest in those terms:

[View all](/glossary)

["Customer-Initiated Transaction"](/glossary/customer-initiated-transaction) ["CAVV"](/glossary/cavv) ["False Decline Transaction Solutions for Better Payment Performance"](/glossary/false-decline) ["3D Secure"](/glossary/3d-secure) 

## Articles you may find interesting:

[View all](/blog)

[![How issuer money-flow intelligence improves approvals and recurring payment recovery](https://cdn.smartretry.com/cdn-cgi/image/width=3840&quality=75&format=auto&fit=cover/https%3A%2F%2Fcdn.smartretry.com%2Fuploads%2F2026%2F06%2Fimage-10.jpg) June 4, 2026 When Issuers Build Around Customer Money Flows, Authorization Performance Improves This article explains how issuers use deposit timing, recurring behavior, and better signals to approve more payments. For operators, the payoff is fewer false declines, smarter retries, and stronger recurring revenue retention.](/blog/issuer-money-flow-approvals)[![Issuer response code 43 and why merchants must stop stolen card retries](https://cdn.smartretry.com/cdn-cgi/image/width=3840&quality=75&format=auto&fit=cover/https%3A%2F%2Fcdn.smartretry.com%2Fuploads%2F2026%2F03%2Fimage-86.jpg) March 8, 2026 Issuer Response Code 43: Why Merchants Must Stop Retries on Stolen Cards This article explains why Code 43 is a terminal decline, how to remove dead credentials from retry logic, and how disciplined handling protects approval rates, margin, and customer recovery.](/blog/response-code-43-stolen-card)[![3D Secure strategies that reduce declines and improve payment conversion](https://cdn.smartretry.com/cdn-cgi/image/width=3840&quality=75&format=auto&fit=cover/https%3A%2F%2Fcdn.smartretry.com%2Fuploads%2F2026%2F03%2Fimage-62.jpg) March 8, 2026 The Invisible Logic of 3D Secure: How Payment Teams Balance Fraud, Friction, and Revenue This article explains how payment teams can use 3D Secure, exemptions, and soft-decline handling to cut false declines, protect conversion, and improve recurring revenue performance.](/blog/3d-secure-fraud-friction)

---

```json
{"@context":"https://schema.org","@type":"DefinedTerm","@id":"https://www.smartretry.com/glossary/strong-customer-authentication","name":"Strong Customer Authentication","termCode":"strong-customer-authentication","description":"Strong Customer Authentication requires two-factor verification for many EEA online payments. Getting exemptions, 3D Secure flows, and retries right helps reduce false declines and protect conversion.","url":"https://www.smartretry.com/glossary/strong-customer-authentication","alternateName":["SCA","PSD2 SCA"],"inDefinedTermSet":{"@type":"DefinedTermSet","name":"SmartRetry Glossary","url":"https://www.smartretry.com/glossary"}}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://www.smartretry.com/glossary/strong-customer-authentication#webpage","url":"https://www.smartretry.com/glossary/strong-customer-authentication","name":"Strong Customer Authentication: Definition & Payments","description":"Strong Customer Authentication requires two-factor verification for many EEA online payments. Getting exemptions, 3D Secure flows, and retries right helps reduce false declines and protect conversion.","datePublished":"2026-03-08T13:09:53.000Z","dateModified":"2026-07-29T08:01:20.000Z","author":{"@type":"Organization","@id":"https://www.smartretry.com/#organization","name":"SmartRetry","url":"https://www.smartretry.com","logo":{"@type":"ImageObject","url":"https://cdn.smartretry.com/logo.png","width":{"@type":"QuantitativeValue","value":175,"unitCode":"PX"},"height":{"@type":"QuantitativeValue","value":29,"unitCode":"PX"}},"description":"SmartRetry is a smart payment recovery platform that helps businesses save revenue from failed payment transactions and reduce false declines.","sameAs":["https://x.com/smartretry","https://www.facebook.com/smartretry","https://www.instagram.com/smartretry","https://www.linkedin.com/company/smartretry","https://www.youtube.com/@smartretry"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","availableLanguage":["Hebrew","English"],"url":"https://www.smartretry.com/contact"},"address":{"@type":"PostalAddress","streetAddress":"Menachem Begin","addressLocality":"Tel Aviv-Yafo","addressCountry":"IL"}},"isPartOf":{"@type":"WebSite","@id":"https://www.smartretry.com/#website","name":"SmartRetry","url":"https://www.smartretry.com","description":"Payment recovery guides, tools and reference data from SmartRetry - failed payment recovery, false decline prevention and authorization rate optimization.","inLanguage":"en","publisher":{"@type":"Organization","@id":"https://www.smartretry.com/#organization","name":"SmartRetry","url":"https://www.smartretry.com","logo":{"@type":"ImageObject","url":"https://cdn.smartretry.com/logo.png","width":{"@type":"QuantitativeValue","value":175,"unitCode":"PX"},"height":{"@type":"QuantitativeValue","value":29,"unitCode":"PX"}},"description":"SmartRetry is a smart payment recovery platform that helps businesses save revenue from failed payment transactions and reduce false declines.","sameAs":["https://x.com/smartretry","https://www.facebook.com/smartretry","https://www.instagram.com/smartretry","https://www.linkedin.com/company/smartretry","https://www.youtube.com/@smartretry"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","availableLanguage":["Hebrew","English"],"url":"https://www.smartretry.com/contact"},"address":{"@type":"PostalAddress","streetAddress":"Menachem Begin","addressLocality":"Tel Aviv-Yafo","addressCountry":"IL"}}},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".term-definition"]}}
{"@context":"https://schema.org","@type":"FAQPage","author":{"@type":"Organization","@id":"https://www.smartretry.com/#organization","name":"SmartRetry","url":"https://www.smartretry.com","logo":{"@type":"ImageObject","url":"https://cdn.smartretry.com/logo.png","width":{"@type":"QuantitativeValue","value":175,"unitCode":"PX"},"height":{"@type":"QuantitativeValue","value":29,"unitCode":"PX"}},"description":"SmartRetry is a smart payment recovery platform that helps businesses save revenue from failed payment transactions and reduce false declines.","sameAs":["https://x.com/smartretry","https://www.facebook.com/smartretry","https://www.instagram.com/smartretry","https://www.linkedin.com/company/smartretry","https://www.youtube.com/@smartretry"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","availableLanguage":["Hebrew","English"],"url":"https://www.smartretry.com/contact"},"address":{"@type":"PostalAddress","streetAddress":"Menachem Begin","addressLocality":"Tel Aviv-Yafo","addressCountry":"IL"}},"mainEntity":[{"@type":"Question","name":"What is Strong Customer Authentication?","acceptedAnswer":{"@type":"Answer","text":"Strong Customer Authentication requires two-factor verification for many EEA online payments. Getting exemptions, 3D Secure flows, and retries right helps reduce false declines and protect conversion."}}]}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.smartretry.com/"},{"@type":"ListItem","position":2,"name":"Glossary","item":"https://www.smartretry.com/glossary"},{"@type":"ListItem","position":3,"name":"Strong Customer Authentication","item":"https://www.smartretry.com/glossary/strong-customer-authentication"}]}
```
