PSD2 SCA
Payment Services Directive 2 Strong Customer Authentication requirements
PSD2 SCA is a compliance framework from European Union with 11 domains and 28 controls that map to 146 other frameworks. The largest domains are Exemptions from Strong Customer Authentication (9 controls), General Authentication Requirements (7 controls), Confidentiality and Integrity of Credentials (3 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (11)
Authentication Methods
| Code | Title |
|---|---|
| PSDTWO-5 | Customer Authentication Methods, Biometric Controls, Device Binding |
Common and Secure Open Standards of Communication
Common and Secure Open Standards of Communication
Confidentiality and Integrity of Credentials
Confidentiality and Integrity of Credentials
Exemptions from Strong Customer Authentication
Exemptions from Strong Customer Authentication
| Code | Title |
|---|---|
| RTS-A10 | Exemption: Information on Payment Accounts |
| RTS-A11 | Exemption: Contactless Low Value |
| RTS-A12 | Exemption: Unattended Terminals for Transport or Parking Fares |
| RTS-A13 | Exemption: Trusted Beneficiaries |
| RTS-A14 | Exemption: Recurring Transactions |
| RTS-A15 | Exemption: Credit Transfers Between Accounts of the Same Person |
| RTS-A16 | Exemption: Low Value Remote Transactions |
| RTS-A18 | Transaction Risk Analysis Exemption |
| RTS-A20 | Cessation of Exemption Use |
Fraud Monitoring and Reporting
Fraud Monitoring and Reporting
| Code | Title |
|---|---|
| RTS-A19 | Fraud Rate Calculation and Reporting |
Fraud and Incident Reporting
| Code | Title |
|---|---|
| PSDTWO-4 | Fraud Reporting and Incident Management |
General Authentication Requirements
General Authentication Requirements
| Code | Title |
|---|---|
| RTS-A1 | General Authentication Requirements |
| RTS-A2 | Authentication Code Properties |
| RTS-A4 | Dynamic Linking |
| RTS-A6 | Requirements of Knowledge Elements |
| RTS-A7 | Requirements of Possession Elements |
| RTS-A8 | Requirements of Inherence Elements |
| RTS-A9 | Independence of Elements |
Governance and Compliance
| Code | Title |
|---|---|
| PSDTWO-6 | Governance, Risk Management, Compliance Monitoring |
Open Banking APIs
| Code | Title |
|---|---|
| PSDTWO-3 | Common and Secure Communication, API Access for AISPs and PISPs |
SCA Core
| Code | Title |
|---|---|
| PSDTWO-1 | Strong Customer Authentication (SCA) Core Requirements |
SCA Exemptions
| Code | Title |
|---|---|
| PSDTWO-2 | SCA Exemptions and Risk-Based Authentication |
Your Compliance Coverage
If you comply with PSD2 SCA, you already cover:
EMV 3‑D Secure (3DS) - Payment Authentication Protocol
14%
4 controls mapped
Compare →FTC GLBA Safeguards Rule (16 CFR Part 314)
14%
4 controls mapped
Compare →Vietnam PDPD
14%
4 controls mapped
Compare →+ 143 more: US Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements (14%), US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements (14%)
See all 146 mapped frameworks ↓Maps to 146 other frameworks
What is PSD2 SCA and who does it apply to?
PSD2 SCA is a compliance framework from European Union with 11 domains and 28 controls. Payment Services Directive 2 Strong Customer Authentication requirements It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does PSD2 SCA actually require?
PSD2 SCA has 28 controls organised across 11 domains. The largest domains are Exemptions from Strong Customer Authentication (9 controls), General Authentication Requirements (7 controls), Confidentiality and Integrity of Credentials (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of PSD2 SCA do I already cover?
PSD2 SCA maps to 146 other compliance frameworks. The top mapping partners are EMV 3‑D Secure (3DS) - Payment Authentication Protocol (14% coverage), FTC GLBA Safeguards Rule (16 CFR Part 314) (14% coverage), Vietnam PDPD (14% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement PSD2 SCA?
Start your PSD2 SCA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about PSD2 SCA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 28 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required