PSD2 SCA
SCA Core

PSD2 SCA PSDTWO-1: Strong Customer Authentication (SCA) Core Requirements

Per PSD2 Regulatory Technical Standards (RTS) on SCA + Common and Secure Communication: implement SCA. Requirements include (a) implement Strong Customer Authentication using two or more independent elements from knowledge (password + PIN) + possession (mobile + token + card) + inherence (biometric) for (i) account access + (ii) electronic payment initiation + (iii) any action involving risk of fraud or other abuse + (b) maintain element independence - compromise of one does not compromise others + (c) implement dynamic linking for electronic payment transactions binding amount + payee to authentication code + (d) maintain SCA mechanism resilience against replay + interception + (e) document SCA implementation + risk assessment.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.