1. Home
  2. ConvesioPay
  3. SCA Compliance: A Merchant’s Guide to PSD2 Payment Authentication

SCA Compliance: A Merchant’s Guide to PSD2 Payment Authentication

SCA compliance is not simply a matter of enabling 3D Secure and calling it done. Sophisticated merchants optimize their SCA strategy to maximize frictionless authentication rates — keeping conversion high while maintaining full regulatory compliance and liability shift protection. This guide covers the exemption strategies that matter most and how to implement them.

The SCA Optimization Framework

The goal of SCA optimization is to route as many transactions as possible through frictionless authentication while ensuring that challenged transactions convert at the highest possible rate. This requires understanding which exemptions apply to which transactions and configuring your processor to request them appropriately.

Transaction Risk Analysis (TRA): The Most Valuable Exemption

TRA allows an acquirer to skip SCA for low-risk transactions if the acquirer’s overall fraud rate is below the qualifying threshold for the transaction amount:

  • Below €100: Acquirer fraud rate must be below 0.13%
  • Below €250: Acquirer fraud rate must be below 0.06%
  • Below €500: Acquirer fraud rate must be below 0.01%

Adyen maintains fraud rates well within TRA qualifying thresholds for most transaction tiers, making TRA the most broadly applicable exemption for ConvesioPay merchants selling to European customers.

Low-Value Exemption: Simple but Limited

Transactions under €30 can be exempted from SCA without TRA analysis — but the exemption is capped at five consecutive transactions or €100 cumulative before SCA is required. Best used for low-value digital goods or content purchases where friction would severely impact conversion.

Merchant-Initiated Transactions: Critical for Subscriptions

After a customer completes an initial SCA-authenticated payment — such as a subscription sign-up — subsequent recurring charges qualify as merchant-initiated transactions (MIT) and are exempt from SCA. This is the mechanism that allows subscription merchants to charge customers on a schedule without requiring re-authentication each time.

The key requirement: the initial transaction must use proper stored credential consent language, and the MIT flag must be sent correctly in subsequent charges. ConvesioPay handles this automatically for WooCommerce Subscriptions merchants.

Trusted Beneficiary (Whitelisting)

Customers can whitelist a merchant with their issuing bank after an initial authenticated transaction, causing future purchases to flow through without SCA challenges. Adoption varies by issuer and country, but whitelisting can meaningfully improve repeat purchase conversion for trusted merchants.

ConvesioPay’s Exemption Strategy

ConvesioPay, through Adyen’s global SCA infrastructure, automatically applies the appropriate exemption for each transaction based on amount, transaction type, and acquirer fraud rates — requesting frictionless authentication first and falling back to challenge flows only when required. The result is maximum conversion with full compliance. Standard pricing applies: 2.9% + $0.30 per transaction, no monthly fees.

Ready to get started? Learn more about ConvesioPay or view pricing.

Updated on June 23, 2026

Was this article helpful?

Related Articles

Need Support?
Can’t find the answer you’re looking for? we’re here to help!
Contact Support