Strong Customer Authentication (SCA)
Abbreviation: SCA
Pronunciation: STRAWNG KUS-tuh-mer aw-then-tih-KAY-shun (ESS-SEE-AY)
Also known as: Strong Customer Authentication, SCA
Definition
Strong Customer Authentication is a regulatory and security requirement that generally uses at least two independent authentication elements for specified electronic payments or account access. The elements commonly come from knowledge, possession, and inherence categories and can be combined with dynamic linking to the payment amount and beneficiary. The security effect of Strong Customer Authentication (SCA) depends on the exact contract, credential, policy, and enforcement point.
Overview
Strong Customer Authentication is a regulatory and security requirement that generally uses at least two independent authentication elements for specified electronic payments or account access.
The elements commonly come from knowledge, possession, and inherence categories and can be combined with dynamic linking to the payment amount and beneficiary. The security effect of Strong Customer Authentication (SCA) depends on the exact contract, credential, policy, and enforcement point. When assessing Strong Customer Authentication (SCA), teams should recognize that a warning label or interface setting is insufficient unless the deployed system actually rejects unauthorized actions and records the decision.
SCA is not one authentication technology and does not apply identically to every jurisdiction, transaction, exemption, merchant, payment rail, or cryptocurrency transfer. Threat analysis for Strong Customer Authentication (SCA) should identify the actor, protected asset, required permission, attack path, and evidence available after an incident. A practical review of Strong Customer Authentication (SCA) must account for the following: Controls may involve contract roles, signatures, transaction simulation, allowlists, revocation, rate limits, or independent approval.
Risks include incorrect exemption use, weak element independence, authentication abandonment, inaccessible recovery, fraudulent social engineering, and confusing technical approval with final settlement. For Strong Customer Authentication (SCA), common failure modes include copied contracts, excessive permissions, phishing, compromised administrators, stale policy data, and applications that interpret a successful transaction as an authorized business action.
Payment systems should record applicable regulation, authentication elements, exemption, challenge result, amount and beneficiary binding, provider response, liability, and audit evidence.
Operational analysis of Strong Customer Authentication (SCA) should also consider Access Token and Token Approval.
Strong Customer Authentication is a regulated authentication requirement using independent factors and dynamic linking where applicable, not a name for every MFA implementation.
Key Takeaway
SCA strengthens payment authentication through independent factors and dynamic context, while exemptions, jurisdiction, recovery, user experience, and settlement remain separate.
Sources
- NIST Cryptographic Standards and Guidelines — NIST (2026-08-01)
- OWASP Smart Contract Security — OWASP (2026-08-01)
- IETF RFC 9110 — IETF (2026-07-30)
- OpenAPI Initiative Documentation: V3.2.0 — OpenAPI Initiative (2026-07-30)