Oh no! How do I audit SCA and CSC under PSD2?
NOREA, the Dutch Payments Association and the Dutch Banking Association offer practical guidance for IT audits of strong customer authentication (SCA) and common and secure communication (CSC) under PSD2.

The Payments Knowledge Group of NOREA (the professional association of IT auditors in the Netherlands (in Dutch) ), the Dutch Payments Association and the Dutch Banking Association (NVB (in Dutch) ) have published guidance on an audit approach (in Dutch) for SCA (Strong Customer Authentication) and CSC (Common & Secure Communication) under PSD2 (Revised Payment Services Directive).
This guidance is an initial minimum viable product: practical advice developed in the summer of 2019 following consultation with IT auditors and stakeholders. It helps auditors follow a widely agreed, harmonised and workable audit approach that is aligned with legal requirements. The recommendations in the guidance are endorsed by the financial institutions consulted and can also be used by other organisations that must comply with PSD2. It supports a flexible approach that reuses previous audit work and can be adapted easily if the requirements change.
Related articles
-
EU trilogue on the digital euro begins
-
News
-
European legislation
-
-
Digital Resilience and AI
-
News
-
Digital identity
-
-
Workshop on agentic payments and the EUDI Wallet
-
News
-
Digital identity
-
-
The Digital Euro and Stablecoins: Apples and Oranges
-
News
-
European legislation
-
-
Payment orders with unstructured address data will be rejected starting November 14 or 15, 2026
-
News
-
European legislation
-
-
First online lunch session updates members on current developments in the payments sector
-
News
-
European legislation
-