Skip to content

Compliance matrix

PSD2 Strong Customer Authentication

European Union / EEA · Updated 2026-07-19

Applies to: Payment service providers and merchants handling EEA electronic payments and account access.

Requirements mapped to CIAM

Two-factor strong authentication

Authentication must combine two independent factors from knowledge, possession, and inherence.

CIAM controls

  • MFA combining independent factors
  • Possession (passkey / device) plus inherence (biometric) options
  • Independence between factors

Evidence

  • SCA authentication policy
  • Factor configuration

Ask the vendor

  • Can you enforce two independent factors, and which combinations are supported?

Dynamic linking

For payments, the authentication code must be dynamically linked to the exact amount and payee, and any change invalidates it.

CIAM controls

  • Transaction-bound challenge (amount + payee)
  • Invalidation on any change to the transaction

Evidence

  • Dynamic linking flow documentation

Ask the vendor

  • Do you support transaction-bound (dynamically linked) authentication challenges?

Risk-based exemptions

Exemptions (low value, trusted beneficiary, transaction risk analysis) require a risk engine to apply safely.

CIAM controls

  • Adaptive / risk-based authentication
  • Configurable exemption policies

Evidence

  • Risk engine configuration
  • Exemption policy

Ask the vendor

  • Does your risk engine support SCA exemptions such as transaction risk analysis?

Take this into procurement

Turn these requirements into vendor questions.

The vendor questions above map directly into an RFP or an evaluation checklist you can share with security and procurement.

Go deeper

Where it bites hardest

FAQ

Do passkeys satisfy PSD2 SCA?
A passkey provides a possession factor and, when unlocked with a device biometric, can supply an inherence factor too, which can satisfy the two-factor requirement. For payments you still need dynamic linking that binds the authentication to the specific amount and payee, so confirm the vendor supports transaction-bound challenges.

Source

EBA regulatory technical standards on SCA (PSD2)

This matrix is practitioner guidance, not legal advice, and does not establish an attorney-client relationship. Confirm your obligations with qualified counsel. See our disclaimer.