Subscribe to our email and get updates right in your inbox

World Entrepreneurs' Day
Get Flat 26% OFF Webp new

Use code: ENTREPRENEUR26

How Strong Customer Authentication (SCA) Helps Reduce the Chance of Fraudulent Transactions

by Hamza Hanif

August 5, 2026
SUMMARIZE:

ChatGPT

Perplexity

As online payments continue to grow, so does the risk of card-not-present (CNP) fraud, where criminals use stolen card details to make unauthorized purchases without the physical card. Reflecting this growing threat, the global card-not-present (CNP) fraud prevention market was valued at $8.3 billion in 2025 and is projected to reach $18.7 billion by 2034, growing at a 10.8% CAGR.

To address this challenge, European regulators introduced Strong Customer Authentication (SCA) under the Second Payment Services Directive (PSD2).

In this article, you’ll learn how SCA reduces online payment fraud, strengthens payment security, prevents common fraud types, and helps WordPress businesses accept payments more securely. 

What Is Strong Customer Authentication (SCA)?

Strong Customer Authentication (SCA) is a legal requirement introduced under PSD2 that requires most electronic payments in the European Economic Area (EEA) and the UK to use at least two independent authentication factors before a transaction is approved.

SCA strengthens payment authentication by requiring customers to verify their identity with at least two independent authentication factors before an online payment is approved. This extra layer of verification helps prevent unauthorized transactions and improves overall payment security. 

Think of SCA as multiple layers of security. While one lock can fail, combining several independent protections makes unauthorized access far more difficult.

A thief who picks one lock is still stopped by the others. 

SCA works the same way: even if a fraudster steals your card number, they still need something else, your phone, your fingerprint, or a PIN.

Here’s a summarized version:

  • What triggers it: Customer-initiated electronic payments and account access within the EEA/UK
  • Who enforces it: The European Banking Authority, under PSD2’s Regulatory Technical Standards
  • What it requires: Two of three independent factors – something you know, something you have, something you are
  • What it changed: A single-factor checkout (card number + CVV + billing address) is no longer sufficient for most EU/UK transactions

Before SCA vs. After SCA

Before SCAAfter SCA
Authentication factors required1 (card data only)2+ independent factors
Liability for fraudulent CNP transactionsOften fell on the merchantShifts to the card issuer if SCA was correctly applied
Stolen card data aloneSufficient to complete a purchaseInsufficient without possession or biometrics
Transaction tampering in transitNot systematically preventedBlocked via dynamic linking (see below)
Regulatory enforcementInconsistent across the EUHarmonized under EBA technical standards

3 Core Pillars of SCA

Each of the three authentication factors plays a different role in preventing fraud, helping businesses improve security while meeting SCA requirements.

Diagram of the three core pillars of Strong Customer Authentication: knowledge, possession, and inherence factors

Knowledge Factors – Why Passwords Alone Aren’t Enough

Knowledge factors in SCA showing why passwords and PINs alone are not enough to stop card fraud

What it is: PINs, passwords, and security questions – something only the customer knows.

How it reduces fraud: A knowledge factor stops the most basic form of card fraud: an attacker who has only stolen card numbers, expiry dates, and CVVs (often bought from breached databases) and nothing else. Without a password or PIN tied to the account, that stolen data alone is worthless.

Where it falls short: Knowledge factors can be phished, guessed through brute force, or extracted through credential-stuffing attacks that reuse passwords leaked in unrelated breaches. This is precisely why SCA never allows a knowledge factor to stand alone, it’s why we need at least one more, independent factor from a different category.

Possession Factors – The Physical Barrier Against Remote Attacks

Possession factors in SCA using a phone or security token as a physical barrier against remote fraud

What it is: A phone, a hardware security token, a smart card, or a SIM.

How it reduces fraud: This is the factor that neutralizes remote fraud at scale. A fraudster operating from another location can buy stolen card details, but they cannot buy physical possession of the cardholder’s phone. Common implementations include a one-time password (OTP) sent by SMS or a push notification to the customer’s banking app, which the customer must approve in real time.

This is why possession factors are so effective against organized, large-scale card fraud: they convert an attack that could previously be run from anywhere in the world into one that requires physical access to a specific device tied to a specific person.

Inherence Factors – Biometric Uniqueness Against Identity Spoofing

Inherence factors in SCA using fingerprint and Face ID biometrics to prevent identity spoofing

What it is: Fingerprint, Face ID, voice recognition, or iris scan.

How it reduces fraud: Biometrics solve a problem: passwords can’t: they can’t be reset, reused across accounts, or handed off. A password that leaks in one data breach can be reused everywhere the customer uses it. A fingerprint can’t be “leaked” in the same reusable way, and it can’t be guessed through brute force. This makes inherence factors the strongest defense against account takeover attempts that rely on credential reuse from unrelated breaches.

The drawback is that inherence factors depend on the device’s biometric hardware and liveness detection to prevent spoofing (a printed photo fooling a camera, for instance), which is why banks continue to invest in more advanced liveness detection technology.

Why Combining Independent Authentication Factors Makes Fraud Significantly Harder

The critical design requirement in SCA is that the two factors must come from independent categories, and compromising one must not compromise the others.

For instance: A fraudster steals a customer’s password through a phishing email and later gains access to their phone. They must still satisfy the two independent authentication factors required for that specific authentication flow.

  • Knowledge factor compromised: The fraudster has the customer’s password.
  • Possession factor compromised: The fraudster also has the customer’s phone.
  • Inherence factor remains secure: The fraudster still needs the customer’s fingerprint or facial recognition, which cannot be easily replicated.

This is what independent authentication factors mean in practice. Even if one or two factors are compromised, an attacker must overcome a completely different layer of security, making successful fraud much more difficult.

How SCA Reduces Specific Types of Fraud

Multi-factor authentication and dynamic linking are the mechanisms. Here’s how they translate into measurable reductions across the specific fraud types merchants actually deal with.

  • Card-Not-Present (CNP) Fraud

CNP fraud occurs when a card is used online without being physically present. SCA combats this through 3D Secure 2, requiring an extra verification step so stolen card details alone aren’t enough to complete a purchase.

  • Account Takeover (ATO) Fraud

Account takeover happens when attackers gain access to a customer’s account using stolen credentials. By requiring multi-factor authentication, SCA makes it much harder to access accounts or misuse saved payment methods.

  • Friendly Fraud (Chargeback Abuse)

Friendly fraud occurs when customers dispute purchases they actually authorized. When SCA is correctly applied, liability often shifts to the card issuer, giving merchants greater protection against fraudulent chargebacks.

  • Card Testing Attacks

Criminals test stolen card numbers by making small authorization requests to identify active cards. SCA blocks these attempts by requiring an additional authentication factor, making large-scale testing far less effective.

SCA Exemptions: Where Fraud Can Still Slip Through

SCA isn’t required for every payment. To keep checkout fast, regulators allow certain low-risk transactions to be exempt from authentication. While these exemptions improve the customer experience, they can also create opportunities for fraud.

Common SCA exemptions include:

  • Low-value payments: Transactions under €30 may skip SCA until spending or transaction limits are reached.
  • Low-risk transactions (TRA): Payment providers can exempt transactions that pass real-time fraud checks.
  • Recurring payments: Only the first payment in a fixed subscription usually requires SCA.
  • Trusted merchants: Customers can whitelist merchants with their bank for future purchases.
  • Corporate payments: Many business-to-business corporate card transactions are exempt.

Best Practices for Merchants

Exemptions reduce checkout friction, but they don’t remove fraud risk. To stay protected:

  • Monitor for repeated small transactions, a common sign of card-testing attacks.
  • Use SCA on higher-risk transactions, even when an exemption is available.
  • Keep your payment processor’s fraud detection tools enabled for all transactions.

By combining exemptions with strong fraud monitoring, merchants can balance security with a smooth customer experience.

SCA Compliance Checklist

To make compliance easier, we’ve put together a quick checklist covering the essential steps every merchant should take to meet SCA requirements and reduce payment fraud.

  • unchecked Confirm your payment processor natively supports 3D Secure 2.0 / SCA
  • unchecked Verify your WordPress payment plugin passes authentication data through correctly
  • unchecked Test a live transaction using an EEA-issued test card to confirm the SCA challenge appears
  • unchecked Review which exemptions (low-value, TRA, recurring) your processor applies automatically
  • unchecked Set up fraud monitoring even on exempted transactions
  • unchecked Confirm recurring/subscription forms apply full SCA on the first charge only
  • unchecked Revisit your setup as PSD3/PSR rules take effect over the next 1–2 years

Stay SCA Compliant With WP Easy Pay

Strong Customer Authentication reduces fraud through several layers working together:

  • Independent multi-factor verification that stops attackers who only have partial customer data.
  • Dynamic linking that blocks transaction tampering in transit.
  • A liability shift that changes who bears the cost of successfully authenticated fraud.

Although no security system can eliminate fraud entirely, SCA makes attacks much harder.

Exemptions can still leave some gaps, and fraud tactics continue to evolve, which is why PSD3 introduces additional protections. Even so, these layered security measures have proven highly effective. 

The European Banking Authority reports that SCA-authenticated card transactions consistently experience lower fraud rates than transactions without SCA, reinforcing its role in reducing card payment fraud.

Don’t let fraud slow down your business or put your customers at risk. 

If your WordPress website accepts payments or donations from customers in the EEA or UK, ensure your checkout supports Strong Customer Authentication through 3D Secure 2. WP Easy Pay Pro integrates with Square to help merchants meet PSD2 requirements while maintaining a secure checkout experience.

Get WP Easy Pro and create secure payment and donation forms that meet SCA requirements. 

Frequently Asked Questions

Does SCA apply to US merchants?

Yes. If you sell to EEA or UK customers using cards issued by EEA/UK banks, SCA may apply even if your business is based in the US.

What happens if I don’t comply with SCA?

Non-compliant payments may be declined, leading to lost sales and reduced fraud liability protection.

Is 3D Secure the same as SCA?

No. SCA is the legal requirement, while 3D Secure 2 is the main technology used to meet it.

Can SCA be bypassed by fraudsters?

SCA greatly reduces fraud, but no system is foolproof. Social engineering and certain exemptions can still be exploited.

How does WP Easy Pay handle SCA?

WP Easy Pay uses Square’s built-in 3D Secure 2 support to automatically apply SCA when required.

Does SCA stop all online payment fraud?

No. Strong Customer Authentication (SCA) significantly reduces online payment fraud by requiring customers to verify their identity with at least two independent authentication factors. However, no security measure can eliminate fraud entirely. Social engineering, phishing attacks, and certain SCA exemptions can still create opportunities for criminals. Combining SCA with fraud monitoring and risk-based authentication provides stronger protection.

Are recurring subscriptions exempt from SCA?

In many cases, yes. Under PSD2, the first payment of a fixed recurring subscription usually requires Strong Customer Authentication. After the customer successfully authenticates the initial transaction, subsequent payments of the same amount to the same merchant are typically exempt from SCA. However, if the payment amount changes or the subscription terms are modified, the customer may need to complete SCA again.

Who is responsible if an SCA-protected transaction turns out to be fraudulent?

When Strong Customer Authentication is correctly applied, liability for many fraudulent card-not-present (CNP) transactions often shifts from the merchant to the card issuer. However, liability depends on the specific circumstances, the payment method, and the card network’s rules. Merchants should still use fraud prevention tools and follow their payment provider’s security requirements to reduce risk and maintain compliance.

blog-sideba

Get WordPress payment tips delivered straight to your inbox

Join 8,500+ users who get our weekly newsletter with insider Square payment tips!

Create Your Square Payment Form in Minutes— No Coding Required!

Scroll to Top