PSD2 SCA
What is PSD2 SCA?
Payment Services Directive 2 Strong Customer Authentication requirements. It comprises 6 controls organised across 6 domains, and applies in the European Union.
How PSD2 SCA maps to other frameworks
All 6 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 6 domains PSD2 SCA groups its controls into
Frameworks that share controls with PSD2 SCA
Each of these has at least one control mapped to a control in PSD2 SCA. The number is how many PSD2 SCA controls are shared, counted from the mapping graph.
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
4 shared controlsVietnam PDPD
4 shared controlsUS Maritime Transportation Security Act (MTSA) and USCG Cybersecurity Requirements
4 shared controlsUS EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
4 shared controlsTurkey KVKK
4 shared controlsProtective Security Policy Framework (PSPF) Release 2024
4 shared controlsNIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
4 shared controlsFFIEC IT Examination Handbook
4 shared controlsWhere PSD2 SCA overlaps with the standards you already hold
What PSD2 SCA means in your sector
What PSD2 SCA means for your job
Questions people ask about PSD2 SCA
What is PSD2 SCA?
How many controls does PSD2 SCA have?
Where does PSD2 SCA apply?
What frameworks does PSD2 SCA map to?
How do I get started with PSD2 SCA compliance?
Query PSD2 SCA programmatically
PSD2 SCA, its 6 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
PSD2 SCA API reference and MCP config →What PSD2 SCA requires, control by control
Each page carries the requirement text for one PSD2 SCA control and what an assessor expects to see as evidence.
- PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
- PSDTWO-2 SCA Exemptions and Risk-Based Authentication
- PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs
- PSDTWO-4 Fraud Reporting and Incident Management
- RTS-A1 General Authentication Requirements
- RTS-A18 Transaction Risk Analysis Exemption
- RTS-A2 Authentication Code Properties
- RTS-A4 Dynamic Linking
How ready are you for PSD2 SCA?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.