Boolean and Beyond
ServicesWorkAboutInsightsCareersContact
Boolean and Beyond

Building AI-enabled products for startups and businesses. From MVPs to production-ready applications.

Company

  • About
  • Services
  • Solutions
  • Industry Guides
  • Work
  • Insights
  • Careers
  • Contact

Services

  • Product Engineering with AI
  • MVP & Early Product Development
  • Generative AI & Agent Systems
  • AI Integration for Existing Products
  • Technology Modernisation & Migration
  • Data Engineering & AI Infrastructure

Resources

  • AI Cost Calculator
  • AI Readiness Assessment
  • AI-Augmented Development
  • Download AI Checklist

Comparisons

  • AI-First vs AI-Augmented
  • Build vs Buy AI
  • RAG vs Fine-Tuning
  • HLS vs DASH Streaming
  • Single vs Multi-Agent
  • PSD2 & SCA Compliance

Legal

  • Terms of Service
  • Privacy Policy

Contact

contact@booleanbeyond.com+91 9952361618

© 2026 Blandcode Labs pvt ltd. All rights reserved.

Bangalore, India

Boolean and Beyond
ServicesWorkAboutInsightsCareersContact
Solutions/Payment Solutions Europe/PSD2 & Strong Customer Authentication Guide

PSD2 & Strong Customer Authentication Guide

Complete guide to PSD2 compliance: SCA requirements, exemptions, 3D Secure 2 implementation, and liability shifts.

What is PSD2 and why does Strong Customer Authentication matter?

PSD2 (Payment Services Directive 2) is EU regulation requiring Strong Customer Authentication (SCA) for electronic payments. SCA mandates two-factor authentication using something the user knows (password), has (phone), or is (biometric). Non-compliance results in declined transactions and potential fines.

Understanding PSD2 and SCA

PSD2 fundamentally changed European payments when SCA requirements became mandatory. Understanding these requirements is essential for any business accepting payments in Europe.

Strong Customer Authentication (SCA) requires two independent authentication factors from three categories:

  • Knowledge: Password, PIN, security question
  • Possession: Phone, hardware token, smart card
  • Inherence: Fingerprint, face recognition, behavioral biometrics

The factors must be independent—compromising one doesn't compromise the other. A password stored on a phone doesn't count as two factors.

When SCA Applies

SCA is required for customer-initiated electronic payments within the European Economic Area (EEA).

Transactions requiring SCA: - Online card payments (e-commerce) - Bank transfers initiated online - Adding new payment methods - First payment of a recurring series - Accessing payment account information

Transactions NOT requiring SCA: - Merchant-initiated transactions (after initial setup) - Mail order/telephone order (MOTO) - One-leg transactions (payer or payee outside EEA) - Anonymous prepaid cards under €150 - Unattended terminals for transport/parking

Understanding scope helps you know which transactions need SCA flows and which don't.

SCA Exemptions

Exemptions allow transactions to proceed without SCA, reducing friction for low-risk payments.

Low-value transactions: - Under €30 per transaction - Cumulative limit: €100 or 5 transactions since last SCA - Issuer may decline if limits exceeded

Recurring payments: - Same amount to same merchant - SCA required for initial setup - Subsequent payments exempt

Trusted beneficiaries: - Customer whitelists specific merchants - SCA required to add to whitelist - Future payments to whitelisted merchants exempt

Low-risk transactions (Transaction Risk Analysis): - Merchant fraud rate below thresholds - Exemption amounts: €100 (0.13% fraud), €250 (0.06% fraud), €500 (0.01% fraud) - Requires real-time fraud analysis

Corporate payments: - B2B payments using dedicated corporate cards - Secure corporate payment processes

Request exemptions through your payment provider. The issuing bank makes the final decision whether to honor the exemption.

3D Secure 2 Implementation

3D Secure 2 (3DS2) is the primary protocol for implementing SCA on card payments.

How 3DS2 works: 1. Merchant submits payment with enriched data 2. Card network routes to issuer's ACS 3. Issuer assesses risk using provided data 4. Low-risk: frictionless approval 5. High-risk: challenge (OTP, biometric, etc.)

Frictionless vs challenge flow: - Frictionless: No customer action, instant approval - Challenge: Customer completes authentication step

Data that improves frictionless rates: - Shipping address matching billing address - Device fingerprint and behavioral data - Previous transaction history - Account age and purchase patterns

Implementation approaches: - Redirect: Customer sent to issuer authentication page - Embedded: Authentication within merchant checkout - Native (mobile): In-app SDK authentication

Payment providers (Stripe, Adyen) handle 3DS2 automatically. Focus on providing rich transaction data to maximize frictionless approvals.

Liability Shifts and Risk

SCA compliance affects fraud liability allocation between merchants and issuers.

Traditional liability (no SCA): Merchant bears liability for fraudulent transactions. Chargebacks come from merchant's revenue.

With successful SCA: Liability shifts to issuer. If authenticated transaction is fraudulent, issuer (not merchant) bears the loss.

Exemption liability: If merchant requests exemption and fraud occurs, merchant may bear liability. Balance conversion improvement against fraud risk.

Implementation recommendations: - Always attempt SCA for first-time customers - Use exemptions judiciously for returning customers - Monitor fraud rates by exemption type - Adjust strategy based on actual fraud experience

The goal is optimizing the trade-off between checkout friction (fewer completions) and fraud protection (liability shifts).

Related Articles

Stripe Subscriptions & Billing Implementation

Technical guide to implementing Stripe Billing: products, prices, subscriptions, webhooks, and the customer portal.

Read article

Payment Webhooks & Reconciliation

Building reliable webhook handlers and reconciliation systems for payment data integrity.

Read article
Back to Payment Solutions Europe Overview

How Boolean & Beyond helps

Based in Bangalore, we help fintech companies, SaaS businesses, and marketplaces build payment systems that work reliably across European markets.

Provider Selection

We help you choose between Stripe, MangoPay, Adyen, and others based on your specific use case, geography, and compliance needs.

Compliance Implementation

We build PSD2-compliant payment flows with proper SCA handling, exemption strategies, and GDPR-compliant data processing.

Operations & Monitoring

We set up webhook processing, reconciliation systems, and monitoring to keep your payment infrastructure running smoothly.

Ready to start building?

Share your project details and we'll get back to you within 24 hours with a free consultation—no commitment required.

Registered Office

Boolean and Beyond

825/90, 13th Cross, 3rd Main

Mahalaxmi Layout, Bengaluru - 560086

Operational Office

590, Diwan Bahadur Rd

Near Savitha Hall, R.S. Puram

Coimbatore, Tamil Nadu 641002

Boolean and Beyond

Building AI-enabled products for startups and businesses. From MVPs to production-ready applications.

Company

  • About
  • Services
  • Solutions
  • Industry Guides
  • Work
  • Insights
  • Careers
  • Contact

Services

  • Product Engineering with AI
  • MVP & Early Product Development
  • Generative AI & Agent Systems
  • AI Integration for Existing Products
  • Technology Modernisation & Migration
  • Data Engineering & AI Infrastructure

Resources

  • AI Cost Calculator
  • AI Readiness Assessment
  • AI-Augmented Development
  • Download AI Checklist

Comparisons

  • AI-First vs AI-Augmented
  • Build vs Buy AI
  • RAG vs Fine-Tuning
  • HLS vs DASH Streaming
  • Single vs Multi-Agent
  • PSD2 & SCA Compliance

Legal

  • Terms of Service
  • Privacy Policy

Contact

contact@booleanbeyond.com+91 9952361618

© 2026 Blandcode Labs pvt ltd. All rights reserved.

Bangalore, India