Skip to content
Switching? Move over in an afternoon →
Glossary

What is SCA (strong customer authentication)?

Definition

Strong customer authentication (SCA) is a European requirement that customers confirm certain online payments with two independent proofs of identity, usually through their bank's 3D Secure check.

Share this definition

How SCA works for subscriptions

Under European payment rules, many online card payments need the customer to prove who they are with two of three things: something they know, such as a PIN; something they have, such as their phone; and something they are, such as a fingerprint. In practice this is 3D Secure: the bank shows a check in the payment flow, often a push notification to approve in the banking app.

Subscriptions fit this through merchant-initiated transactions. The customer authenticates when they first subscribe or save their card, agreeing to future charges. Later renewals are started by the merchant while the customer is away, and are generally treated as outside SCA because the customer is not there to take part.

The bank still has the last word. It can ask for authentication on any charge, including a renewal, and when it does, the payment cannot finish until the customer comes back and confirms it. This page is general information; the exact rules depend on the country, the bank and your gateway.

Worked example

A made-up customer in France subscribes to a €49 monthly plan on June 1.

June 1: first payment, customer approves in their banking app
€49.00
July 1: renewal charged while the customer is away, no check
€49.00
August 1: bank asks for authentication, customer emailed a link
€49.00 owed
August 2: customer confirms from the link
Paid

The August charge was never declined. The card was fine; the bank only wanted the customer to confirm it.

Why SCA matters

If the first payment or card setup skips authentication where it is required, the bank may decline it, or later renewals may be challenged more often. Setting up the card properly at signup is what lets renewals run without the customer.

An authentication request on a renewal is easy to mistake for a decline. Retrying it does nothing, because the bank is waiting for the customer, not for time to pass. It needs its own path: tell the customer and give them a link to confirm.

Common mistakes

  • Retrying an authentication request The charge will not succeed until the customer confirms it. Send a link instead of retrying.
  • Saving a card without authenticating it A card saved outside a proper setup flow may not qualify for charges while the customer is away. Use your gateway's setup flow.
  • Assuming SCA is only a European concern The rule is European, but whether it applies depends on where the customer's bank and your payment provider are, so a business outside Europe with European customers may meet it. Ask your gateway how it handles those payments.
Questions

Strong customer authentication, answered

Does every subscription renewal need 3D Secure?

Generally not. Renewals the merchant starts while the customer is away are usually treated as merchant-initiated, relying on the authentication done at signup. The bank can still ask for a check on any charge.

What is the difference between SCA and 3D Secure?

SCA is the requirement: two proofs of identity for certain payments. 3D Secure is the card networks' protocol most commonly used to meet it.

Does SCA apply to businesses outside Europe?

It can. It generally applies when both the customer's bank and the merchant's payment provider are in the regions covered, so check with your gateway for your setup.

Start free. Pick a plan when it is working.