---
title: The New Strong Customer Authentication Rules for Online Purchases
description: Strong Customer Authentication (SCA) became compulsory for services taking all types of electronic payment transactions from the European Economic Area (EEA) on the 31st of December, 2020.
image: https://csacyber.com/hubfs/stong-auth1.png
---

[Skip to content](https://csacyber.com/blog/the-new-strong-customer-authentication-rules-for-online-purchases#main-content)

[![CSA Cyber - Cyber Security Solutions to Protect your People](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=300&height=108&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber - Cyber Security Solutions to Protect your People")](https://csacyber.com/)

- Services 
    - [Offensive Security Services](https://csacyber.com/offensive-security-services) 
          - [Penetration Testing](https://csacyber.com/penetration-testing)
          - [Red Teaming and attack simulations](https://csacyber.com/offensive-security-services#red-teaming)
          - [Continuous testing](https://csacyber.com/offensive-security-services#continuous-assurance)
          - [Managed offensive security](https://csacyber.com/offensive-security-services#managed-offensive)
    - [Consultancy Services](https://csacyber.com/cyber-consultancy-services) 
          - [Frameworks & assessments](https://csacyber.com/cyber-consultancy-services/frameworks-and-assessments)
          - [Data protection](https://csacyber.com/cyber-consultancy-services#data-protection)
          - [Virtual leadership](https://csacyber.com/cyber-consultancy-services#virtual-leadership)
          - [Technical security consulting](https://csacyber.com/cyber-consultancy-services#technical-consultancy)
          - [Governance, Risk & Compliance (GRC)](https://csacyber.com/cyber-consultancy-services/governance-risk-and-compliance-services)
    - [Extended Managed Security Services](https://csacyber.com/extended-managed-security-services) 
          - [Microsoft Sentinel SIEM](https://csacyber.com/extended-managed-security-services#microsoft-sentinel)
          - [SOC services](https://csacyber.com/extended-managed-security-services#soc-services)
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/extended-managed-security-services#cyber-helpdesk)
    - [Incident Response Services](https://csacyber.com/incident-response-services) 
          - [Emergency Incident Response](https://csacyber.com/urgent/emergency-incident-response)
          - [Incident Response Retainer](https://csacyber.com/incident-response-services)
          - [Cyber Incident Readiness & Response Planning](https://csacyber.com/incident-response-services)
          - [Tabletop Exercises & Live-Range Engagements](https://csacyber.com/incident-response-services)
    - [Specialist Security Services](https://csacyber.com/specialist-services) 
          - [AI Security](https://csacyber.com/cyber-services-for-ai)
          - [Operational Technology (OT)](https://csacyber.com/specialist-services#operational-technology)
          - [Cyber security for Private Equity](https://csacyber.com/specialist-services#mergers-and-acquisitions)
          - [Cyber training and education](https://csacyber.com/specialist-services#training-and-education)
          - [Virtual leadership](https://csacyber.com/specialist-services#leadership)
    - [Cyber Technologies](https://csacyber.com/cyber-technologies) 
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/cyber-technologies#sentinelone)
          - [AppGuard Endpoint & Server Zero Trust Protection](https://csacyber.com/cyber-technologies#appguard)
          - [Qualys Vulnerability Management as a Service (VMaaS)](https://csacyber.com/cyber-technologies#qualys-vmaas)
          - [Lookout Mobile Device Protection](https://csacyber.com/cyber-technologies#lookout)
          - [ThreatER DNS Protection](https://csacyber.com/cyber-technologies#threater-dns)
          - [Cyber Security Awareness & Training platform](https://csacyber.com/cyber-technologies#boxphish)
- [About](https://csacyber.com/about-us) 
    - [Careers](https://csacyber.com/careers)
    - [Certifications](https://csacyber.com/certifications-and-awards)
- [Blog](https://csacyber.com/blog)
- [Support Centre](https://csacyber.com/support)
- Resources 
    - [Case Studies](https://csacyber.com/case-studies)
    - [Downloads & Reports](https://csacyber.com/downloads-and-reports)
    - [Webinars](https://csacyber.com/webinars)
    - [Partners](https://csacyber.com/partners)
    - [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)
- [Contact](https://csacyber.com/contact-us)

- Search Search
  
  Search

 April 1, 2022

 4 min read time

# The New Strong Customer Authentication Rules for Online Purchases

![Cyber Security Associates](https://app.hubspot.com/settings/avatar/d41d8cd98f00b204e9800998ecf8427e) [Written by: Cyber Security Associates -](https://csacyber.com/blog/author/cyber-security-associates)

[Article](https://csacyber.com/blog/tag/article) 

![](https://csacyber.com/hubfs/stong-auth1.png)

### Executive Summary

Strong Customer Authentication (SCA) became compulsory for services taking all types of electronic payment transactions from the European Economic Area (EEA) on the 31st of December, 2020. This includes contactless point-of-sale payments, online card transactions, and banking services such as the faster payments system. In the UK, the Financial Conduct Authority issued a deadline for full SCA compliance for e-commerce transactions in the UK, which came into effect on the 14th of March, 2022.

### Why is SCA important?

If either the payee or payer is based elsewhere, then SCA is not currently a requirement. However, it would be prudent for Payment Service Providers (PSP) around the world to ensure that their online payment services still adhere to SCA requirements. Not only is this best practice, but other countries are likely to enact similar policies eventually, just like Australia did in 2019.

Although businesses and customers alike may question the need for another layer of authentication, the increase in fraudulent transactions has driven this development. According to Action Fraud, over 103,000 reports of online shopping and auctions fraud were reported in 2020. UK Finance, which represents the banking industry, revealed that more than £750 million was stolen via fraud in the first half of 2021. Consumers need to be confident in the integrity of the payment system, and the safety of their financial resources.

As well as online and contactless transactions, the number of people in the UK using online banking services grew from 30% in 2007 to 76% in 2020. There have been objections from some groups of users, who don’t have a mobile phone, aren’t able to receive a reliable signal, or have other barriers that may prevent them from being able to use SCA effectively. However, several banks have agreed that customers can be sent security codes via landline (such as Lloyds, Tesco and TSB) or continue to access accounts and make payments at bank branches (like Santander.)

Currently, the 3D Secure authentication protocol requires a user to satisfy one additional verification request before a payment can be authorised. Typically, this is a code sent via SMS to the phone number registered to the bank account. 3D Secure is due to be phased out later in 2022.

### What’s needed for authentication?

The revised Payment Services Directive 2 (PSD2) legislation requires that service providers use the 3D Secure 2 authentication protocol to verify a user’s identity before a transaction can be approved. This requires two discrete pieces of information from the user, which can be from three potential categories:

• Knowledge - something only the user knows, such as a password or a PIN.

• Possession - something the user has, such as a code sent via SMS.

• Inherence - something that’s a part of what the user is, such as a fingerprint.

Some banks have chosen to enact SCA by sending a notification to their online banking app, which details the merchant’s name and amount to be paid on the payer’s banking app. The payer must then log in to their app (knowledge) and confirm that the transaction is valid on the app (possession). Digital wallet services such as PayPal, Apple Pay, and Google inherently meet two-factor authentication requirements.

There are several exemptions from SCA, which include:

• Transactions initiated by merchants - i.e., a payment on a date that has previously been agreed by the customer, such as pre-authorised card payments taken on a periodic basis. Direct debit mandates fall under this exemption only if the customer’s bank is not involved in the initial setup.

• For recurring payments such as standing orders and subscriptions, only the first payment requires SCA. If it’s amended at a later date, then SCA will be required again.

• Contactless payments below £100, or cumulative contactless payments totalling less than £300 since the last time SCA was required.

• Unattended payment terminals for payment of transport fares or parking fees.

• Credit transfers where the payer and payee are the same person.

• Whenever corporate payments are made via dedicated payment processes not available to consumers.

### What should you be doing?

With these new requirements in mind, businesses and organisations may find that existing procedures will need to be adjusted to ensure a continuation of services, even if they’re not operating within the retail sphere.

For instance, when paying supplier invoices via faster payments, if there’s not already a procedure outlined, now would be the time to do so. Ideally, two senior members of staff would be designated to make such payments, and the SCA requirements set up to deliver a confirmation code to their work-provided phone. Alternatively, the process for employees booking transport and accommodation for business-related travel could be assigned to one member of the finance team (corporate credit cards are exempt from SCA – allowing the provision of these for staff who often travel may be another viable alternative).

A full audit of outgoing payments, sources and requisitions should provide some insight into any necessary adjustments that need to be made. Payments can be a source of compromise – phishing and whaling (an even more targeted version of phishing) attacks are often aimed at specific members of staff who are known to hold fiscal responsibility – so ensuring that procedures are clear will help to protect your organisation against potential exploitation, monetary loss, and reputational damage.

If you’re unsure of what cyber security procedures you might need to enact, or how to educate your employees about what to do in the case of phishing campaigns, then look no further. At Cyber Security Associates, we can help your staff with security training, to create a more cyber-secure culture within your business. As well as E-learning courses, we offer webinars and sessions for organisations of all sizes, in both the public and private sectors. Find out more about how we can help, and get in touch with us today.

Related Posts

## You may also like this

[Similar Articles](https://csacyber.com/blog)

[![](https://csacyber.com/hs-fs/hubfs/20230510-N1005919-Edit1.jpg?width=624&height=427&name=20230510-N1005919-Edit1.jpg)](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 August 24, 2026

 2 min read

### [FluidOne Group appoints Charly Davis as Managing Director of CSA Cyber to advance its security-first strategy](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 Experienced industry leader joins FluidOne to strengthen integrated cyber, IT and secure networking...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Untitled%20design.jpg?width=624&height=427&name=Untitled%20design.jpg)](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 August 20, 2026

 2 min read

### [CSA Cyber and FluidOne named as suppliers on G-Cloud 15](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 CSA Cyber (CSA), part of the FluidOne Group, has been named as a supplier on Government Commercial...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Engineered%20to%20Endure%20Campaign%20Assets%20(2).png?width=624&height=427&name=Engineered%20to%20Endure%20Campaign%20Assets%20(2).png)](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 August 20, 2026

 6 min read

### [Why organisations lose security visibility without realising it](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 Before an organisation can understand risk, maintain control or respond effectively to emerging...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![CSA Cyber Logo FNL_Full Logo](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=3463&height=1248&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber Logo FNL_Full Logo")](https://csacyber.com/)

Established in 2013, Cyber Security Associates Limited trading as CSA Cyber provides cyber consultancy and cyber managed services which help to detect, protect and educate against the ever-changing cyber threat. We have built our team from a foundation of Government (ex-Military) and Commercially experienced specialists all holding current and relevant cyber certifications. Today our core services are based around a 24/7 Security Operations Centre (SOC) based in Gloucester.

#### News & Resources

- [Blog](https://csacyber.com/blog)
- [Case Studies](https://csacyber.com/case-studies)
- [Downloads & Reports](https://csacyber.com/downloads-and-reports)
- [Webinars](https://csacyber.com/webinars)
- [Careers](https://csacyber.com/careers)
- [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)

#### Quick Links

- [About Us](https://csacyber.com/about-us)
- [Certifications](https://csacyber.com/certifications-and-awards)
- [Our Parent Company](https://www.fluidone.com)
- [Partners](https://csacyber.com/partners)
- [Contact Us](https://csacyber.com/contact-us)
- [Anti Bribery Policy](https://csacyber.com/hubfs/CSAAnti-BriberyPolicy.pdf)
- [Complaints Policy](https://csacyber.com/hubfs/CSAComplaintsPolicy.pdf)
- [Corporate Social Responsibility Policy](https://csacyber.com/hubfs/CSACorporateSocialResponsibilityPolicy.pdf)
- [Slavery and Human Trafficking Statement](https://csacyber.com/hubfs/CSASlaveryandHumanTraffickingStatement.pdf)
- [NCSC CHECK Status Verification](https://www.ncsc.gov.uk/organisation/csa-cyber/check-penetration-testing)
- [CREST Approved Certification Verification](https://www.crest-approved.org/member_companies/csa-cyber/)

#### Contact Information

**United Kingdom - London**

Cyber Security Associates Ltd

5 Hatfields, London, SE1 9PG

 

**United Kingdom - Gloucester**

Cyber Security Associates Ltd

Unit 11, Wheatstone Court, Waterwells Business Park, GL2 2AQ

 

**Phone:** [+44(0) 300 303 4691](tel:03003034691)

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

**United States of America**

Cyber Security Associates Inc.

6010 W. Spring Creek Pkwy, Plano, Texas, 75024

 

**Phone:** [+1 469 750 1695](tel:14697501695) 

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

[![trust-pilot](https://csacyber.com/hs-fs/hubfs/trust-pilot.png?width=178&height=104&name=trust-pilot.png)](https://uk.trustpilot.com/review/csa.limited)

 

---

- [Website Terms of Use](https://csacyber.com/website-terms-of-use)
- [Website Privacy Policy](https://csacyber.com/privacy-notice)
- [Website Cookie Policy](https://csacyber.com/cookie-policy)

 Copyright 2026. Cyber Security Associates Ltd [Follow us on Facebook](https://www.facebook.com/CSALIMITED/) [Follow us on LinkedIn](https://www.linkedin.com/company/csa-cyber/) [Follow us on Twitter](https://twitter.com/cybersecurityis) [Follow us on Facebook](https://www.youtube.com/@cybersecurityassociateslim) [Follow us on Facebook](https://www.instagram.com/cybersecurityassociates)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Cyber Security Associates",
    "url" : "https://csacyber.com/blog/author/cyber-security-associates"
  },
  "dateModified" : "2024-12-06T14:42:19.964Z",
  "datePublished" : "2022-04-01T04:00:00.000Z",
  "headline" : "The New Strong Customer Authentication Rules for Online Purchases",
  "image" : [ "https://csacyber.com/hubfs/stong-auth1.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://csacyber.com/blog/the-new-strong-customer-authentication-rules-for-online-purchases",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://csacyber.com/hubfs/csacyber-logo-black-01.svg"
    },
    "name" : "Cyber Security Associates Ltd"
  }
}
```