Per PSD2 RTS Articles 4-9 + EBA Opinions: authentication methods. Requirements include (a) implement biometric authentication using device + cloud biometric meeting EBA guidance + (b) implement device binding for possession factor + (c) implement secure mobile payment + e-commerce flows + (d) implement out-of-band authentication where appropriate + (e) maintain authentication credential lifecycle + revocation + (f) align with FIDO2 + WebAuthn + similar standards.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.