Strong Customer Authentication

Directive European Union / United Kingdom · 2019

Strong Customer Authentication (SCA) is the security requirement mandated by PSD2's Regulatory Technical Standards, requiring multi-factor authentication (two of knowledge, possession, and inherence) for electronic payments and account access in the EU and UK. It is the regulatory backbone of the FAPI-grade security stack that open-banking APIs implement, and the reason bank-grade auth is the floor in European open finance rather than a premium tier.

Sectoral regime. It binds the industries below; companies outside them generally fall outside it.

Countries

Where this binds. Each links to the providers apis.io has catalogued there.

Regions

Industries

Each links to that industry as a scored cohort — so the question "how ready is this sector for the regime that governs it?" becomes one you can actually look at.

Implemented by these standards

A regulation is the law; a standard is the machine-readable contract that satisfies it. Almost every regime in this catalog restricts an interface rather than requiring one — where a standard exists, it is the part a provider can actually publish.