# sca

Source: https://startwithidentity.com/glossary/sca/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

The PSD2 requirement that electronic payment authentication use at least two of: knowledge, possession, inherence. Plus dynamic linking, the auth factor must be tied to the specific transaction amount and payee.

Dynamic linking is what separates SCA from ordinary MFA: the authentication has to be cryptographically tied to the amount and the payee, and the user has to see them. That rules out an approval prompt that just says "confirm sign-in". Exemptions for low-value and recurring payments exist and are where most of the implementation complexity actually sits.

See also: [PSD2](https://startwithidentity.com/glossary/psd2/), [MFA](https://startwithidentity.com/glossary/mfa/), [step-up auth](https://startwithidentity.com/glossary/step-up-auth/), [FAPI](https://startwithidentity.com/standards/fapi/)
