7-part series
Strong Customer Authentication is where passkeys meet European payments regulation, and the answer is more nuanced than it looks. Read in order, this series works from the device-bound versus synced credential distinction, through what PSD2 actually requires, to whether a passkey satisfies SCA and what PSD3 and the PSR change. Start at part one.
Written to be read in order, starting here.
Explore synced passkeys & device-bound passkey, their differences & learn about the role of hardware security modules (secure enclave, TEE, TPM).
Explore insights on SCA & PSD2 requirements & the EBA's role in enhancing payment security with dynamic linking by providing regulatory technical standards.
Explore how synced and device-bound passkeys meet SCA compliance in our latest blog, detailing their roles in secure online banking authentication.
Explore the impact of PSD3/PSR on SCA, focusing on passkey authentication and regulatory changes. Learn how PSD3 will enhance digital payments and security.
Are passkeys the best form of phishing-resistant MFA that is compliant with PSD2 and SCA requirements? This blog post answers all the questions.
Learn about delegated strong customer authentication in PSD3 & PSR, how passkeys could fit, compliance shifts, and what’s still undecided.
Learn how outcome-based Strong Customer Authentication using passkeys enhances security and usability, effectively protecting against AI-driven phishing.
See every login journey clearly, diagnose failures faster and keep your existing IDP in place.