🎓 CoursesAcceptance & card systemsAdvanced⏱ 60 min

3DS2, SCA, and payment success rates. 7 chapters and a final quiz.

Master strong customer authentication end to end: the PSD2 framework, 3DS2 frictionless and challenge mechanics, the liability shift, every RTS exemption, handling 65/1A soft declines, and managing your payment success rate.

Chapter 1. PSD2 and strong customer authentication: the framework.

PSD2 (Directive (EU) 2015/2366) made SCA (strong customer authentication) a legal requirement for all payer-initiated electronic payments in the European Economic Area. The technical rules are set out in the RTS (Delegated Regulation (EU) 2018/389). The RTS, not the directive itself, define the factors, dynamic linking, and above all the exemptions covered in this course. For an online merchant, SCA is more than a compliance constraint. Handled poorly, it costs several points of conversion. Handled well, it becomes a measurable competitive advantage.

Nov. 2015
PSD2 adopted
Directive (EU) 2015/2366, replacing PSD1 (2007).
Jan. 13, 2018
PSD2 takes effect
Transposition into national law; the SCA RTS do not yet apply.
Sept. 14, 2019
SCA RTS become legally applicable
Delegated Regulation (EU) 2018/389. The EBA allows a gradual migration for e-commerce.
2020–May 2021
French migration plan (OSMP)
Phased rollout overseen by the Banque de France (France’s central bank): 3DS2 and soft declines introduced in stages by transaction amount.
Oct. 2022
3DS1 retired
Visa and Mastercard end support for the 3DS 1.0.2 protocol. EMV 3DS (3DS2) becomes the only version in use.
June 2023
PSD3 / PSR proposal
The Commission proposes moving most SCA rules into a directly applicable regulation; a provisional political agreement was reached on November 27, 2025, and formal adoption is expected in late 2026.

The three authentication factors

  • Knowledge: something only the customer knows, such as a password or PIN. The card number, expiration date, and CVV do not count (they are printed on the card).
  • Possession: something only the customer has, such as an enrolled phone (banking app, SIM), the card itself via a dynamic cryptogram, or a hardware token.
  • Inherence: something the customer is, such as a fingerprint, facial recognition, or behavioral biometrics (accepted by the EBA under certain conditions).
  • SCA requires at least two factors from different categories that are independent: compromising one must not compromise the other (PSD2 art. 4(30) and RTS art. 9). An SMS OTP alone (possession) is not SCA. An SMS OTP plus a password is, but the EBA considers it weak (SIM swap risk).
🔑
Dynamic linking (RTS art. 5)
For remote payments, the authentication code must be dynamically linked to the amount and the payee shown to the payer. Any change to either invalidates the code, so a 3DS2 authentication cannot be replayed on another transaction. You therefore cannot authenticate one amount and then authorize a higher one, except within accepted industry tolerances such as a properly flagged incremental authorization.
CaseLicense typeNotes
E-commerce payment, issuer and acquirer in the EEASubject to SCAUnless the issuer accepts an RTS exemption
In-store contact payment (PIN)In scope, already compliantCard + PIN = possession + knowledge
In-store contactlessArt. 11 exemption≤ €50; counters: €150 cumulative or 5 transactions
MIT (merchant-initiated transaction)Out of scopeNo payer action; the initial mandate transaction, however, requires SCA
MOTO (mail order/telephone order)Out of scopeNot considered electronic under the RTS
One-leg-out (issuer or acquirer outside the EEA)Out of scopeSCA on a “best effort” basis only
Anonymous prepaid cardOut of scopeNo identifiable customer to authenticate
SCA scope for card payments
0,16 %
fraud rate on card-not-present payments in France (2023)
OSMP, 2024 annual report
0,01 %
fraud rate on in-store payments in France, 16 times lower
OSMP, 2024 annual report
≈ 2/3
share of card fraud value from remote sales in France, which account for about a quarter of payment value
OSMP