Retail EU Banking
All in-scope payments require SCA.
Recommended
Full SCA + Dynamic Linking
Governance Intelligence · Framework
Strong Customer Authentication for EU mobile banking
PSD2 Regulatory Technical Standards on Strong Customer Authentication and dynamic linking — the EU mobile banking authentication baseline.
3
Auth Factors
Knowledge, Possession, Inherence
Mandatory
Dynamic Linking
Per payment
8
Exemptions
Risk-based
EU + UK
Mapped Mandates
FCA aligned
Governance Snapshot
PSD2 • live APK index
Category coverage
PSD2-K
85%Knowledge Factor
PSD2-P
78%Possession Factor
PSD2-I
80%Inherence Factor
PSD2-DL
72%Dynamic Linking
PSD2-TRA
64%Transaction Risk Analysis
Overview
Why governance, AppSec and audit teams adopt this framework.
Two-of-three independent factors per session.
Bind authentication to amount + payee.
Apply TRA exemptions safely.
Protect auth secrets in isolated env.
Control Domains
Per-domain coverage, common failures and APK evidence — expand each for detail.
Something only the user knows — PIN, password, response to challenge.
Checks
Common Failures
APK Finding Examples
Something only the user possesses — device, hardware token, mobile SIM.
Checks
Common Failures
APK Finding Examples
Something the user is — biometric (fingerprint, face) via secure platform APIs.
Checks
Common Failures
APK Finding Examples
Authentication code must be specific to the amount and payee — visible to the user before approval.
Checks
Common Failures
APK Finding Examples
Risk-based exemptions require server-side scoring — fraud rate must remain within RTS thresholds.
Checks
Common Failures
APK Finding Examples
Banking Implications
Recommended posture by app type and the regulators that reference this framework.
All in-scope payments require SCA.
Recommended
Full SCA + Dynamic Linking
Third-party provider compliance.
Recommended
PSD2 + APIs
Account information services.
Recommended
SCA on consent
API certificate identity.
Recommended
PSD2 + eIDAS QSeal
Regulator Mapping
UAE CB
referencedGCC
SAMA
referencedGCC
MAS TRM
recommendedAPAC
RBI
referencedAPAC
APRA CPS 234
referencedAPAC
FFIEC
referencedAmericas
PSD2 / EBA
recommendedEU
DORA
recommendedEU
Cross Mapping
How this framework maps across MASVS, OWASP Mobile, PCI DSS, PSD2, DORA and central-bank guidance.
| Control | MASVS | OWASP Mobile | PCI DSS Mobile | PSD2 | DORA | UAE CB |
|---|---|---|---|---|---|---|
| Strong Auth | ● | ● | ● | ● | ● | ● |
| Dynamic Linking | ◐ | ◐ | ○ | ● | ○ | ◐ |
| Biometric Hardening | ● | ● | ◐ | ● | ◐ | ● |
| TRA | ○ | ○ | ○ | ● | ◐ | ○ |
Live APK Governance
Sample governance report from a recent assessment — coverage, gaps and top violations.
Coverage heatmap
Knowledge
Possession
Inherence
Dyn. Link
TRA
Top Violations
Run on your APK →Dynamic linking missing on transfer
PSD2-DL
Biometric template cached in sandbox
PSD2-I
OTP not bound to amount + payee
PSD2-DL
TRA exemption fraud above threshold
PSD2-TRA
Upload your APK to receive a PSD2 SCA assessment
Get coverage score, missing controls, severity-weighted gaps and a board-ready PDF.
Upload APK for PSD2 SCA Assessment →Threat Intelligence
Curated mobile attack patterns aligned to the controls above.
Threat
Prevent rooted-device fraud and runtime privilege abuse.
Read intel →
Threat
Detect and resist Frida / proxy interception of TLS.
Read intel →
Threat
Block credential and OTP theft from malicious overlays.
Read intel →
Threat
Detect APK repackaging, dynamic patching and hooking.
Read intel →
Threat
Prevent instrumentation-based runtime manipulation.
Read intel →
Country Mandates
Country regulators that reference this framework — usage confidence and mapped control count.
CBUAE
MAS
RBI
EBA / PSD2
FCA / PRA
SAMA
Trust & Adoption
Mobile banking security teams use this framework to establish secure release gates and runtime baselines.
EU banks
All in-scope EU mobile banking apps implement SCA.
UK FCA
FCA aligns mobile banking SCA expectations with PSD2 RTS.
FAQ
For BFSI CISOs, AppSec, audit and governance teams.
SCA is required for account access (after 90 days) and electronic payments, with explicit RTS exemptions for low-value, trusted-beneficiary and recurring transactions.
Dynamic linking binds the authentication code to a specific amount and payee, visible to the user before approval. It is mandatory for PSD2-scoped payments.
MobAIsec inspects auth flows, biometric handling and binding signals in the APK, then maps findings to PSD2 RTS articles for audit-ready evidence.
Start now
Upload your Android banking app and receive a complete enterprise governance assessment in minutes.