
What Is SCA?
SCA began in September 2019 as part of PSD2, setting stricter rules for payment security. The directive requires banks and firms to respond to certain complaints within 15 days and to improve how issues are resolved.
SCA also means online businesses must add extra security steps at checkout. Customers now need to provide two out of three elements:
-
Something they know (like a password)
-
Something they have (like a phone)
-
Something they are (like a fingerprint)
As of 2025, SCA still applies to most online payments across the EU, EEA, and the UK. The rules are becoming more consistent as new regulations roll out, making security standards stricter for everyone involved.
Businesses must now use stronger authentication methods, often requiring customers to verify payments with biometrics or secure codes. For those without smartphones, banks and merchants have to offer alternative ways to authenticate.
Companies are updating their checkout systems to make these security steps as smooth as possible, aiming to protect users without making payments difficult. With online shopping and mobile banking more popular than ever, staying ahead of these requirements is essential for both security and customer trust.
Our guide on Customer Identity Access Management (CIAM) can be incredibly useful to you, as it discusses the means to create and manage online identities securely.

Exemptions to SCA
Low-value transactions
Payments under €30 or £25 can be exempt from SCA. However, if more than five consecutive low-value payments are made or the total exceeds €100/£85, authentication is required.
Recurring payments
After the first transaction is authenticated, regular payments of the same amount to the same merchant (like subscriptions) are generally exempt from SCA.
Merchant-initiated transactions
Payments started by the merchant without the customer present (such as variable subscriptions or delayed charges) are usually exempt, as long as the card was authenticated when first saved and the customer agreed to future charges.
Trusted beneficiaries
Customers can whitelist trusted merchants after authenticating once, making future payments to those merchants exempt, unless the bank suspects fraud.
Low-risk transactions (Transaction Risk Analysis)
If the payment provider’s fraud rates are very low and the transaction is considered low risk after real-time analysis, SCA can be skipped for certain payments.
Secure corporate payments
Payments made by businesses through secure, dedicated payment systems can be exempt if strict security protocols are followed.
Other exemptions
-
Contactless payments at physical terminals below the national threshold
-
Unattended terminals for transport or parking
-
Credit transfers between accounts held by the same person
Important notes:
-
Banks and payment providers decide whether to accept an exemption and may still require SCA if they detect risk.
-
Some payments, like mail/telephone orders and certain cross-border transactions, are out of SCA’s scope entirely.
A robust software licensing solution can play a key role in supporting compliance with SCA and PSD2 requirements. By managing access to payment systems and sensitive customer data, a licensing solution ensures that only authorized users and applications can interact with critical payment infrastructure.
Book a demo with 10Duke to see how our cloud-based software licensing solution can simplify license management, enhance security, and improve your customer experience.
Are you a software developer looking to sell more? Learn more from our guides:
Should You Build Or Buy a Licensing System?
How to Monetize Software Products?
Guide to Software Licensing – Basics Explained
Software Licensing Models – Ultimate Guide
What Is Software License Management?
Customer Identity and Access Management – What should a good CIAM solution provide?
The Licensing Lab Blog
SCA first came into being in September 2019* as a response to the European Second Payment Services Directive (PSD2). These plans detail a list of requirements that banks and building societies and certain firms must abide by – chief of these being that providers must respond to certain kinds of complaints within a fifteen day window, helping to improve issue resolution problems that have plagued the industry to close to a decade.









