PSD2 SCA
SCA Exemptions

PSD2 SCA PSDTWO-2: SCA Exemptions and Risk-Based Authentication

Per PSD2 RTS Articles 10-18: SCA exemptions. Requirements include (a) implement Low-Value Exemption for amounts up to EUR 30 cumulative EUR 100 + (b) implement Trusted Beneficiary Exemption for whitelisted payees + (c) implement Recurring Transaction Exemption for subsequent transactions in series + (d) implement Corporate Payment Exemption for B2B payments using secure dedicated processes + (e) implement Transaction Risk Analysis (TRA) Exemption based on real-time risk assessment + fraud rate thresholds + (f) maintain audit trail + fraud rate monitoring per Article 18.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 253 controls across 75 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-04 User application hardening (Essential)
  • ASD37-10 Server application hardening (Very Good)
  • ASD37-11 Operating system hardening (Very Good)
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

NIST SP 800-53 Rev 5 · 8 controls

ISO/IEC 27031:2011 · 7 controls

  • 27031-7.1 IRBC Strategy
  • 27031-7.2 Resource Requirements
  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review
  • 27031-B High availability embedded systems
  • 27031-D Developing performance criteria
  • NIST-CSF-PR.DS-10 The confidentiality, integrity, and availability of data-in-use are protected
  • NIST-CSF-PR.IR-03 Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
  • NIST-CSF-PR.IR-04 Adequate resource capacity to ensure availability is maintained
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

PCI PIN Security · 7 controls

  • PCI-PIN-09 Encryption and key management
  • PCI-PIN-10 Secure configuration standards
  • PCI-PIN-11 Business continuity planning and testing
  • PCI-PIN-12 Disaster recovery procedures
  • PCI-PIN-13 Third-party dependency management
  • PCI-PIN-14 Critical service identification
  • PCI-PIN-15 Communication and escalation procedures

FedRAMP Rev 5 · 6 controls

  • FEDRAMP-CM-1 Configuration Management Policy
  • FEDRAMP-CM-2 Baseline Configuration
  • FEDRAMP-CP-9 System Backup
  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

PCI SSF · 6 controls

  • PCI-SSF-09 Encryption and key management
  • PCI-SSF-10 Secure configuration standards
  • PCI-SSF-11 Business continuity planning and testing
  • PCI-SSF-12 Disaster recovery procedures
  • PCI-SSF-14 Critical service identification
  • PCI-SSF-15 Communication and escalation procedures
  • IM8-CLD.2 Cloud Security Controls
  • IM8-DAT.2 Data Protection
  • IM8-DSS.2 Service Reliability Standards
  • IM8-RES.1 Business Continuity Planning
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing

API 1164 · 5 controls

  • API1164-14 Physical Security
  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • API1164-22 Configuration management for OT systems
  • FFIEC-09 Encryption and key management
  • FFIEC-10 Secure configuration standards
  • FFIEC-11 Business continuity planning and testing
  • FFIEC-12 Disaster recovery procedures
  • FFIEC-14 Critical service identification

IEC 62443 · 5 controls

  • IEC62443-14 System security hardening
  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents
  • IEC62443-22 Configuration management for OT systems

ISO 22316 · 5 controls

  • ISO22316-01 Organizational resilience and security - business continuity policy for building security and resilience
  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities
  • ISO22316-14 Supply chain continuity
  • ISO22316-15 Communication strategy during disruption

ISO/IEC 27019:2024 · 5 controls

  • ISO27019-14 System security hardening
  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents
  • ISO27019-22 Configuration management for OT systems

ISO/IEC 27043:2015 · 5 controls

  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management
  • ISO27043-23 Backup and recovery procedures

ISO/SAE 21434 · 5 controls

  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • ISO21434-19 Certificate management
  • ISO21434-23 Backup and recovery procedures

ISO/TS 22317:2021 · 5 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-11 Continuity strategy development
  • ISO22317-12 Recovery strategy for critical activities
  • ISO22317-14 Supply chain continuity
  • ISO22317-15 Communication strategy during disruption

ISO/TS 22318:2021 · 5 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • ISO22318-13 Alternate site and resource planning
  • ISO22318-14 Supply chain continuity
  • ISO22318-15 Communication strategy during disruption

NIST SP 1800-32 · 5 controls

PCI P2PE · 5 controls

  • PCI-P2PE-09 Encryption and key management
  • PCI-P2PE-10 Secure configuration standards
  • PCI-P2PE-11 Business continuity planning and testing
  • PCI-P2PE-12 Disaster recovery procedures
  • PCI-P2PE-14 Critical service identification
  • 4.3.2 Legal and Other Requirements
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • 4.4.2 Competence, Training, and Awareness
  • 4.4.8 Business Continuity and Recovery

BSI IT-Grundschutz · 4 controls

  • BSI-08 Cryptographic protection of data
  • BSI-23 Baseline configuration establishment
  • BSI-24 Configuration change control
  • BSI-26 System component inventory
  • NFPA1600-4.1 Leadership and Commitment
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.2 Crisis Management and Communications
  • NFPA1600-6.4 Continuity and Recovery

NIST SP 800-190 · 4 controls

South Korea ISMS-P · 4 controls

  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-01 System Hardening and Patch Management
  • ISMSP-SYS-02 Encryption Implementation
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery
  • OB-API.4 MI Reporting Specification
  • OB-OPS.1 API Availability Requirements
  • OB-SEC.2 Transport Layer Security
  • OB-SEC.4 Certificate Management
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection
  • AWWA-4.3 Configuration Management
  • CJIS-7 Configuration Management
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • 62351-12 Resilience and security recommendations for DER
  • 62351-13 Cyber-physical generation and storage resilience
  • 62351-9 Cyber security key management
  • ISO-22313-5.2 Policy
  • ISO-22313-6.2 Business continuity objectives and plans to achieve them
  • ISO-22313-6.3 Planning changes to the BCMS

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements
  • PICERL-C2 System Backup
  • PICERL-R1 System Restoration
  • PICERL-R2 Security Verification

APRA CPS 234 · 2 controls

  • CPS234-14 Definition of Information Security Roles and Responsibilities
  • CPS234-15 Information Security Capability
  • BS65000-RM-02 Integrated Approach
  • BS65000-RM-03 Leadership and Culture
  • CAT-D3-3 Corrective controls
  • CAT-D5-4 Resilience planning and testing
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning

ISO 27799:2025 · 2 controls

  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-16 Transmission security and encryption

ISO/IEC 20000-1:2018 · 2 controls

  • ISO20000-03 Capacity and availability management
  • ISO20000-10 Configuration management

ISO/IEC 27010:2015 · 2 controls

  • 27010-10.1 Cryptographic Protection
  • 27010-17.1 Compliance

ISO/IEC 27011:2024 · 2 controls

  • 27011-8.3 Cryptography and key management
  • 27011-8.6 Data protection and backup

ISO/IEC 27400:2022 · 2 controls

  • 27400-6.2 Device Identity and Authentication
  • 27400-6.4 Default Configuration Security

ITIL 4 · 2 controls

  • ITIL4-03 Capacity and availability management
  • ITIL4-10 Configuration management

OWASP SAMM · 2 controls

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management

PTES · 2 controls

  • PTESPHASE-2 Intelligence Gathering (OSINT)
  • PTESPHASE-3 Threat Modeling

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • CPS230-26 Critical Operations Register, Continuity Plan and Activation
  • AS9100D-8.1 Operational Planning and Control

Bahrain PDPL · 1 control

COBIT 2019 · 1 control

  • COBIT-BAI04 Managed availability and capacity
  • CA-ITSG33-SC-01 Security Control Catalogue
  • DIQ-1 Data Integration and Interoperability

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • ISO-15189-7.8 Continuity and emergency preparedness

ISO 22320:2018 · 1 control

  • ISO-22320-5.2 Incident management process
  • ISO-26262-8-7 Configuration management
  • ISO28001-PC-04 Supply Chain Continuity Planning
  • ISO-25012-4.13 Availability

ISO/IEC 27007:2020 · 1 control

  • 27007-5.4 Establishing the Programme Resources
  • 29115-7.4 Level of Assurance 4 (LoA4)
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • PSPF24-2 Information Security, Cybersecurity Maturity, Essential Eight

Qatar DPL · 1 control

  • QATAR-5 Security of Processing
  • SAPAIA-2 Right of Access and Request Processes
  • KRCSAP-1 CSAP Certification Tiers (IaaS, SaaS, DaaS, AI)

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • CERT-1 RRA Certification to EPA

Vietnam PDPD · 1 control

  • VIETNAMPDP-2 Consent and Notice

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 253 it maps to, and the evidence behind each claim, over MCP and REST.