Every day, ecommerce businesses process millions of payments where the only proof of identity is a card number, an expiry date, and a CVV. On their own, these details prove almost nothing.
Card-not-present (CNP) fraud is especially tricky to deal with because the physical card never needs to be present for a transaction to go through. Global CNP fraud losses are projected to reach $43.6 billion by 2027.
To help overcome this fraud problem, Strong Customer Authentication (SCA) was built to add another layer of verification, so that stolen card details alone are far less likely to authorize a payment
What Is Strong Customer Authentication?
Strong Customer Authentication (SCA) is a security requirement under PSD2 designed to strengthen the authentication of customers during certain electronic payment transactions.
Instead of relying on a single credential, SCA requires authentication using at least two independent factors from three categories:
| Authentication factor | What it means | Examples |
| Knowledge | Something only the customer knows | Password, PIN |
| Possession | Something only the customer has | Mobile phone, trusted device, security token |
| Inherence | Something the customer is | Fingerprint, facial recognition |
For example, a customer could authenticate a payment using a password and a fingerprint, or a trusted device and a PIN.
The important point is that the two factors must come from different categories. Two pieces of information that both fall under “knowledge,” for example, would not constitute two independent SCA factors.
But SCA doesn’t stop at verifying the customer’s identity; for certain transactions, the authentication must also be tied to the specific payment being authorized.
What Is Dynamic Linking in SCA?
For certain remote electronic payment transactions, SCA also requires the authentication process to be dynamically linked to the specific transaction being authorized.
This means the authentication should be tied to key transaction details, such as the amount and payee, so that an attacker cannot use a valid authentication event to authorize a different transaction.
For example, if a customer is authorizing a $100 payment to a particular merchant, the authentication mechanism should be linked to that transaction rather than simply confirming that the customer has authenticated successfully.
Dynamic linking adds another layer of protection against attacks in which a fraudster attempts to manipulate transaction details between the customer and the payment service provider.
Regulatory note: Strong Customer Authentication (SCA) is primarily associated with the PSD2 requirements applicable to payment service providers in the European Economic Area.
The UK has a separate SCA framework under its own payment-services regulations. If your business operates outside these regions, SCA may not directly apply, although its authentication and risk-based principles remain relevant to payment security.
The EU payment-services framework is also evolving through the Payment Services Regulation (PSR) and the Third Payment Services Directive (PSD3), which are part of the ongoing revision of the EU’s payment-services rules.
How Does Strong Customer Authentication Work?
The basic SCA process can look like this:
- A customer initiates an online payment.
- The payment request is evaluated to determine whether SCA is required.
- If authentication is required, the customer provides two independent authentication factors.
- The issuing bank or authentication provider validates those factors.
- The authentication result is returned to the payment flow.
- The transaction proceeds to authorization or is declined.
For ecommerce merchants, the payment provider, card issuer, and authentication infrastructure handle much of this process rather than the merchant directly. This is where 3D Secure 2 (3DS2) becomes important.
What Is the Role of 3D Secure 2 in SCA?
3D Secure 2 is one of the primary technologies used to authenticate customers during online card payments and support SCA requirements.
A simplified 3DS2 flow looks like this:

One of the major improvements in 3DS2 is that authentication does not necessarily mean displaying an OTP or password challenge to every customer.
Instead, the issuer can evaluate transaction information to determine whether the payment appears low- or high-risk.
A low-risk transaction may be authenticated without requiring an additional customer challenge, while a higher-risk transaction may trigger an authentication step.
This helps address one of the biggest ecommerce concerns around SCA: How do you improve payment security without turning every checkout into a frustrating authentication experience?
What Is a Soft Decline?
A soft decline occurs when an issuer declines a transaction because additional authentication is required before it can be approved.
This can happen when a merchant or acquirer processes a payment without SCA, including when an SCA exemption such as Transaction Risk Analysis (TRA) is requested. The issuer may still decide that authentication is necessary.
A soft decline does not necessarily mean a lost sale. If the payment flow supports it, the payment platform can detect the response and trigger 3DS2 authentication.
The customer then completes SCA, and the payment is resubmitted for authorization.
Handling soft declines correctly helps prevent transactions that could succeed after authentication from appearing as simple payment failures.
Is Strong Customer Authentication Required for Every Ecommerce Payment?
The simple answer is no. SCA applies to certain electronic payments within the relevant regulatory scope, but not every payment automatically requires a customer challenge. There are exemptions and transaction scenarios that can affect whether SCA is required.
The exact applicability can depend on factors such as:
- Where the merchant is located
- Where the customer’s payment account is located
- The type of transaction
- Transaction value
- Whether the payment is recurring
- Whether the customer has established a trusted beneficiary
- The transaction’s fraud risk
- Whether an applicable exemption is available
This is why merchants should avoid implementing SCA as a simple rule of always challenge the customer.
Instead, SCA should be part of a broader payment decisioning strategy.
Common SCA Exemptions Ecommerce Businesses Should Understand
Exemptions can help merchants reduce unnecessary authentication friction while still operating within the applicable regulatory framework.

Common categories include:
Low-Value Transactions
Certain low-value payments may qualify for an exemption, subject to applicable limits and conditions.
For ecommerce businesses with a high volume of small transactions, this can be particularly important because forcing additional authentication on every low-value purchase can introduce unnecessary friction.
Transaction Risk Analysis
A transaction may qualify for a risk-based exemption when the payment meets the applicable conditions, and the relevant payment provider or issuer determines that the transaction falls within an acceptable fraud-risk threshold.
This creates an important connection between fraud detection and authentication.
The better a payment ecosystem can evaluate transaction risk, the better it can determine when additional authentication is necessary.
Note: TRA can be claimed by the issuer or by the acquirer/payment provider, depending on the payment flow, and whichever party claims the exemption also assumes the liability if the transaction later turns out to be fraudulent.
Recurring Transactions
Certain recurring or subscription payments can receive different treatment depending on the transaction pattern and applicable requirements.
For subscription businesses, it is important to distinguish between:
- The initial customer-initiated payment
- Subsequent recurring payments
- Changes to payment details
- New payment instruments
Treating every recurring transaction identically can lead to unnecessary authentication attempts or unexpected payment failures.
Trusted Beneficiaries
Customers may be able to designate certain merchants or beneficiaries as trusted, subject to the applicable rules and issuer capabilities.
This can reduce friction for repeat payments while maintaining the required authentication framework.
Important: Exemptions are not simply switches that a merchant can activate. Their availability and application depend on the payment flow, regulatory requirements, payment provider, issuer, and transaction circumstances. Merchants should work with their payment providers to understand which exemptions they can request and how those decisions are handled.
SCA vs. 3D Secure: What Is the Difference?
SCA and 3D Secure are related, but they are not the same thing. SCA is a regulatory authentication requirement.
3D Secure is a payment authentication protocol commonly used to support online card authentication. Below is a quick table to understand it better.

This distinction matters because simply “having 3D Secure” does not mean that every transaction will necessarily receive the same authentication experience.
What SCA Means for Ecommerce Fraud Prevention
SCA can make unauthorized payment fraud more difficult, but it should not be treated as a complete fraud prevention solution.
Authentication answers an important question: Can this customer be authenticated?
Fraud detection asks a broader question: Does this transaction actually look legitimate?
Those are not always the same thing.
A legitimate customer’s credentials can be compromised. A fraudster may also gain control of a legitimate account, device, email address, or authentication method.
This creates scenarios where a transaction can successfully pass an authentication step but still present significant fraud risk.
For example, consider an account takeover scenario:
- A fraudster gains access to a customer’s ecommerce account.
- The account contains a saved payment method.
- The fraudster changes account or delivery information.
- A transaction is initiated.
- Authentication is successfully completed.
- The order is shipped to a location controlled by the fraudster.
The authentication event alone does not provide enough context to understand the entire transaction. This is why merchants should combine authentication with broader fraud signals.
How SCA and Risk-Based Authentication Work Together
SCA and risk-based authentication work together to help merchants apply the right level of security to each transaction.
Instead of treating every transaction the same way, merchants can assess signals such as the customer’s device, location, transaction history, and behavior. The resulting risk assessment can help determine whether a transaction can proceed with a frictionless flow, qualify for an exemption, or require additional authentication.
Low-risk transaction
A returning customer:
- Uses a recognized device
- Logs in from a consistent location
- Uses a trusted payment method
- Has a positive transaction history
- Places a typical-value order
A transaction with these signals may be suitable for a frictionless 3DS flow or, where applicable, an SCA exemption.
Medium-risk transaction
A transaction may require more scrutiny when the customer:
- Uses a new or unfamiliar device
- Changes their shipping address
- Makes a purchase that is significantly larger than usual
The merchant or issuer may require additional authentication or verification before approving the payment.
High-risk transaction
A transaction may be considered high risk when it shows signals such as:
- Suspicious device activity
- Unusual IP behavior
- High transaction velocity
- Multiple failed authentication attempts
- Account changes shortly before checkout
- Previous associations with fraud
These transactions may require stronger controls, additional authentication, or rejection.
The goal is not to add authentication to every transaction. It is to apply stronger security when the risk justifies it while keeping low-risk payments as frictionless as possible.
Managing Customer Experience Problem
Additional authentication can improve security, but every extra step can also increase the chance that a customer abandons checkout.
Customers may:
- Fail to receive an OTP
- Enter an incorrect authentication code
- Lose access to their authentication device
- Get confused by a bank’s authentication page
- Abandon checkout because authentication takes too long
- Face an authentication failure despite being legitimate
For this reason, merchants should track authentication performance alongside fraud and conversion metrics.
A payment strategy that reduces fraud but significantly increases checkout abandonment may still hurt the business. The objective is to find the right balance between security, authentication success, and customer experience.
What Ecommerce Businesses Should Measure
Risk teams should avoid measuring SCA only by the number of transactions authenticated. Instead, monitor the complete payment funnel.
Important measurable metrics include:
- Authentication rate: How many transactions enter an authentication flow?
- Challenge rate: How frequently are customers actually challenged? A high challenge rate can indicate unnecessary friction in the payment ecosystem.
- Authentication success rate: How many customers complete authentication?
- Authentication failure rate: How many transactions fail during authentication?
- Checkout abandonment: How many customers leave after being presented with an authentication challenge?
- Fraud rate: How much fraud occurs among authenticated and non-authenticated transactions?
- False-positive rate: How many legitimate customers are unnecessarily challenged, declined, or blocked?
- Conversion rate: How does authentication affect completed purchases?
- Chargeback rate: Are successfully authenticated transactions still generating chargebacks or disputes?
Looking at these metrics together gives risk teams a much more accurate picture of whether their authentication strategy is actually working.
| Metric | What to measure | Action if it’s high/low |
| Authentication rate | % of transactions sent for authentication | Review whether authentication is being triggered unnecessarily |
| Challenge rate | % of transactions requiring customer interaction | Investigate excessive challenges and friction |
| Authentication success rate | % of customers who complete authentication | Identify and fix failed or confusing authentication flows |
| Authentication failure rate | % of transactions failing authentication | Check issuer, 3DS, OTP, and integration issues |
| Checkout abandonment | % of customers leaving after a challenge | Reduce unnecessary challenges and simplify the flow |
| Fraud rate | Fraud among authenticated vs. non-authenticated payments | Compare which flows provide better fraud protection |
| False-positive rate | Legitimate transactions challenged or declined | Tune risk rules to avoid blocking good customers |
| Conversion rate | Completed purchases before and after authentication | Measure the impact of authentication on sales |
| Chargeback rate | Chargebacks from authenticated transactions | Check whether authentication is actually reducing disputes |
How Ecommerce Businesses Can Build a Stronger SCA Strategy

1. Map Your Payment Flows
Start by identifying:
- Where your customers are located
- Where your business is located
- Which payment methods you support
- Which payment providers you use
- Which transactions may fall within SCA requirements
- Which exemptions are available to your payment flows
This gives your risk and payment teams a clear view of where authentication needs to occur.
2. Use 3DS2 Where Appropriate
Work with your payment provider to ensure your checkout supports the appropriate 3D Secure implementation.
The goal should not be to challenge every transaction.
Instead, use the capabilities of modern authentication flows to support appropriate frictionless and challenge-based experiences.
3. Evaluate Exemption Opportunities
Understand which exemptions your payment provider supports and when they can be requested.
Monitor how frequently exemptions are:
- Requested
- Accepted
- Rejected
- Followed by fraud
- Followed by legitimate transactions
This can help risk teams refine their payment strategy.
4. Add Risk Signals Beyond Authentication
Authentication should be combined with broader fraud signals such as:
- Device intelligence
- IP intelligence
- Behavioral analytics
- Account history
- Transaction velocity
- Payment history
- Geographic signals
This is particularly important for detecting fraud scenarios where the fraudster can successfully authenticate.
5. Monitor Authentication and Conversion Together
Do not optimize authentication in isolation. A lower fraud rate is valuable, but so is a healthy checkout conversion rate. Your objective should be to find the right balance between security, compliance and conversion.
Common Mistakes Businesses Make With SCA
Below are listed some of the common mistakes that businesses tend to make with SCA:
Assuming SCA Means Every Transaction Requires an OTP
SCA does not necessarily mean that every customer must manually enter an OTP or complete the same challenge. Authentication can happen through different factors and flows, and exemptions may apply.
Treating 3D Secure as a Complete Fraud Solution
3DS2 is an important part of payment authentication, but it does not replace broader fraud detection. Merchants still need visibility into devices, accounts, behavior, transaction patterns, and other risk indicators.
Ignoring False Positives
A legitimate customer who repeatedly encounters unnecessary authentication challenges may eventually abandon the purchase. Risk teams should therefore measure legitimate customer friction alongside fraud reduction.
Applying the Same Rules to Every Customer
A first-time customer making an unusually large purchase presents a different risk profile from a long-term customer using a familiar device and payment method. Risk decisions should reflect that difference.
Focusing Only on Payment Authentication
Fraud can happen before and after the payment itself. Account takeover, fake account creation, promotion abuse, refund fraud, and suspicious delivery behavior may not be solved by payment authentication alone.
A More Effective Ecommerce Payment Security Model
A modern payment security strategy can be thought of as multiple layers where each layer contributes different information.
For example:
Account layer: Is the account behaving normally?
Device layer: Is this a trusted device?
Network layer: Does the IP or network present risk?
Transaction layer: Is the purchase consistent with historical behavior?
Authentication layer: Can the customer successfully prove their identity?
Decision layer: Should the transaction be approved, challenged, reviewed, or declined?
Post-transaction layer: Does activity after payment indicate fraud?
This layered model is more resilient than relying on a single authentication event.
Conclusion
SCA is a solid layer of defense, but it was never designed to catch everything. Fraudsters who compromise an account or a device can often sail right through authentication, which is why the strongest setups pair SCA and 3DS2 with device intelligence, behavioral analysis, transaction monitoring, and real-time risk scoring.
The goal isn’t more security checks. It’s the right check, on the right transaction, at the right moment, so risky payments get stopped, and legitimate customers have a smooth experience.
Sensfrx brings together device, IP, behavioral, and transaction intelligence so you can spot suspicious activity and make risk decisions in real time, not after the chargeback lands. Explore Sensfrx today.
Frequently Asked Questions (FAQs)
They are closely related, but they are not identical concepts. SCA requires at least two independent authentication factors from the knowledge, possession, and inherence categories when SCA applies. General two-factor authentication is a broader security concept that can be used across many applications and services.
No. SCA is designed to strengthen customer authentication and reduce certain types of unauthorized payment fraud. It does not eliminate fraud, particularly when fraudsters compromise legitimate accounts, devices, or authentication methods.
3D Secure 2 is widely used to support SCA for online card payments, but SCA and 3D Secure are not interchangeable terms. The exact authentication mechanism depends on the payment flow and applicable requirements.
It can introduce friction if customers are unnecessarily challenged or encounter authentication failures. Modern payment authentication and applicable exemptions are designed in part to reduce unnecessary challenges while maintaining security.
Yes. Authentication and fraud detection address different parts of the payment risk problem. Combining authentication with device, IP, behavioral, account, and transaction signals gives merchants broader visibility into risk.