EBA · 2018_4039 Final Q&A

Qualification of SMS OTP as an authentication factor

Regulation
Directive 2015/2366/EU (PSD2)
Article
97
Topic
Strong customer authentication and common and secure communication (incl. access)
Submitted by
Other
Submitted
2018-06-28
Answered
2018-10-05
Answer provided by
ESAs (EBA, ESMA, EIOPA)

Question

Please clarify whether a One-Time Password (OTP) sent via SMS to a mobile phone qualifies as an ownership factor (“something only the user possesses”), and shall be subject to Article 7 of the RTS on strong customer authentication and secure communication.

Background

The SMS OTP qualifies as an ownership factor (“something only the user possesses”) because it is received on a device that the cardholder owns and that has been securely associated with the cardholder by the issuer. This ensures a valid alternative authentication method for cardholders without a smartphone with biometric capabilities.

Answer

Paragraph 35 of the EBA opinion on the implementation of the Commission Delegated Regulation (EU) 2018/389 (Regulatory Technical Standards on Strong customer authentication and secure communication) clarifies that “ For a device to be considered possession, there needs to be a reliable means to confirm possession through the generation or receipt of a dynamic validation element on the device ”. In this context, a one-time password sent via SMS would constitute a possession element and should therefore comply with the requirements under Article 7 of the Delegated Regulation, provided that its use is ‘subject to measures designed to prevent replication of the elements’, as required under Article 7(2) of this Delegated Regulation. The possession element would not be the SMS itself, but rather, typically, the SIM-card associated with the respective mobile number. In addition, regardless of whether a strong customer authentication element is possession, knowledge or inherence, Article 22(1) of the Delegated Regulation requires that “ payment service providers shall ensure the confidentiality and integrity of the personalised security credentials of the payment service user, including authentication codes, during all phases of the authentication” and Article 22(4) of the Delegated Regulation states that “payment service providers shall ensure that the processing and routing of personalised security credentials and of the authentication codes generated in accordance with Chapter II take place in secure environments in accordance with strong and widely recognised industry standards ”.

Original source: European Banking Authority, Q&A ID 2018_4039

This Q&A is published by European Banking Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.