EBA · 2025_7482 Final Q&A

SCA exception for Contactless only terminals (SoftPOS) in case of emergency

Regulation
Directive 2015/2366/EU (PSD2)
Article
97
Topic
Strong customer authentication and common and secure communication (incl. access)
Submitted by
Other
Submitted
2025-06-13
Answered
2025-10-03
Answer provided by
ESAs (EBA, ESMA, EIOPA)

Question

We are in the process of developing a backup solution for our SoftPOS terminal application, intended for use during exceptional circumstances such as cyber-attacks or other disruptions to internet connectivity and acquirer systems. As SoftPOS terminals operate exclusively with contactless transactions, and contactless transactions does not support Offline PIN, it is technically not possible to perform Strong Customer Authentication (SCA) in offline mode. We would like to confirm whether, under these conditions, it is acceptable to process offline contactless transactions without applying SCA and follow Directive (EU) 2015/2366 article 0 (15)

Background

In Denmark, as well as in several other countries, legislative efforts are underway that will require all payment solutions—including SoftPOS terminals—to support offline processing. To comply with the upcoming regulations, we must ensure that offline processing is supported, regardless of the authentication methods available.

Answer

Article 97(1)(b) of  Directive 2015/2366/EU (PSD2)  prescribes that the payment service provider (PSP) shall apply ‘strong customer authentication (SCA) where the payer initiates an electronic payment transaction’. Therefore, in the case where the payer initiates an electronic card-based payment transaction at a Software Point of Sale (POS), the issuer shall apply Strong Customer Authentication (SCA) to that transaction, unless an exemption from SCA applies in accordance with Articles 11– 18 of the  Delegated Regulation (EU) 2018/389 . Other exemptions from SCA, including for emergency situations, than those specified within the Delegated Regulation are not available. In the specific case described by the submitter where a payment transaction is initiated at a software POS during a cyber attack or disruption to internet connectivity or acquirer's system, SCA should be applied, unless the payment transaction can be subject to an SCA exemption. It should also be noted that, as clarified in  Q&A 2018_4055 , the PIN can be transmitted and verified offline, provided that it meets the requirements of Articles 6(1), 22(1) and 22(4) of the Delegated Regulation.

Original source: European Banking Authority, Q&A ID 2025_7482

This Q&A is published by European Banking Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.