Article 98 empowered the EBA to develop Regulatory Technical Standards on SCA + common and secure communication (CSC). The Commission adopted these as Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 on 13 March 2018 (effective 14 September 2019 after the 18-month transition). The RTS specifies: SCA elements + Article 9 independence; Article 10 information on payment accounts exemption; Article 11 contactless low-value (cumulative limits EUR 50 + 5 transactions / EUR 150 cumulative); Article 12 unattended terminals for transport + parking; Article 13 trusted beneficiaries whitelist; Article 14 recurring transactions; Article 15 credit transfers between accounts of the same PSU at the same ASPSP; Article 16 low-value remote (single EUR 30 + cumulative EUR 100 + 5 transactions); Article 17-18 corporate-payment + risk-based Transaction Risk Analysis (TRA) exemption tiered by ASPSP fraud rate; Articles 24-28 credentials + authentication codes; Articles 30-36 common + secure communication interface (the ASPSP option: dedicated interface OR modified PSU interface) including ID + confidentiality + integrity + availability + Article 32 fall-back; Article 33 contingency mechanism; Article 36 data exchange between ASPSP + AISP / PISP.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.