<akomaNtoso xmlns:uk="https://www.legislation.gov.uk/namespaces/UK-AKN" xmlns:ukl="http://www.legislation.gov.uk/namespaces/legislation" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/legaldocml/ns/akn/3.0" xsi:schemaLocation="http://docs.oasis-open.org/legaldocml/ns/akn/3.0 http://docs.oasis-open.org/legaldocml/akn-core/v1.0/cos01/part2-specs/schemas/akomantoso30.xsd"><act name="eur"><meta><identification source="#"><FRBRWork><FRBRthis value="http://www.legislation.gov.uk/id/eur/2018/389"/><FRBRuri value="http://www.legislation.gov.uk/id/eur/2018/389"/><FRBRdate date="2017-11-27" name="adopted"/><FRBRauthor href=""/><FRBRcountry value="EU"/><FRBRnumber value="389"/><FRBRname value="Regulation (EU) 2018/389"/><FRBRprescriptive value="true"/></FRBRWork><FRBRExpression><FRBRthis value="http://www.legislation.gov.uk/eur/2018/389/2023-07-11"/><FRBRuri value="http://www.legislation.gov.uk/eur/2018/389/2023-07-11"/><FRBRdate date="2023-07-11" name="validFrom"/><FRBRauthor href="#"/><FRBRlanguage language="eng"/></FRBRExpression><FRBRManifestation><FRBRthis value="http://www.legislation.gov.uk/eur/2018/389/2023-07-11/data.akn"/><FRBRuri value="http://www.legislation.gov.uk/eur/2018/389/2023-07-11/data.akn"/><FRBRdate date="2026-05-30+01:00" name="transform"/><FRBRauthor href="http://www.legislation.gov.uk"/><FRBRformat value="application/akn+xml"/></FRBRManifestation></identification><lifecycle source="#"><eventRef refersTo="#adopted" date="2017-11-27" eId="date-adopted" source="#"/><eventRef date="2017-11-27" eId="date-2017-11-27" source="#"/><eventRef date="2023-07-11" eId="date-2023-07-11" source="#"/></lifecycle><analysis source="#"><restrictions source="#"><restriction refersTo="#extent-e+w+s+ni" type="jurisdiction"/><restriction href="#body" refersTo="#extent-e+w+s+ni" type="jurisdiction"/><restriction href="#chapter-II" refersTo="#extent-e+w+s+ni" type="jurisdiction"/><restriction href="#article-4" refersTo="#extent-e+w+s+ni" type="jurisdiction"/><restriction href="#article-5" refersTo="#extent-e+w+s+ni" type="jurisdiction"/><restriction href="#article-6" refersTo="#extent-e+w+s+ni" type="jurisdiction"/><restriction href="#article-7" refersTo="#extent-e+w+s+ni" type="jurisdiction"/><restriction href="#article-8" refersTo="#extent-e+w+s+ni" type="jurisdiction"/><restriction href="#article-9" refersTo="#extent-e+w+s+ni" type="jurisdiction"/><restriction refersTo="#period-from-2023-07-11" type="jurisdiction"/><restriction href="#body" refersTo="#period-from-2017-11-27" type="jurisdiction"/><restriction href="#chapter-II" refersTo="#period-from-2017-11-27" type="jurisdiction"/><restriction href="#article-4" refersTo="#period-from-2017-11-27" type="jurisdiction"/><restriction href="#article-5" refersTo="#period-from-2017-11-27" type="jurisdiction"/><restriction href="#article-6" refersTo="#period-from-2017-11-27" type="jurisdiction"/><restriction href="#article-7" refersTo="#period-from-2017-11-27" type="jurisdiction"/><restriction href="#article-8" refersTo="#period-from-2017-11-27" type="jurisdiction"/><restriction href="#article-9" refersTo="#period-from-2017-11-27" type="jurisdiction"/></restrictions><otherAnalysis source=""/></analysis><temporalData source="#"><temporalGroup eId="period-from-2017-11-27"><timeInterval start="#date-2017-11-27" refersTo="#"/></temporalGroup><temporalGroup eId="period-from-2023-07-11"><timeInterval start="#date-2023-07-11" refersTo="#"/></temporalGroup></temporalData><references source="#"><TLCEvent eId="adopted" href="" showAs="AdoptedDate"/><TLCLocation eId="extent-e+w+s+ni" href="/ontology/jurisdictions/uk.EnglandWalesScotlandNorthernIreland" showAs="E+W+S+N.I."/></references><proprietary xmlns:ukm="http://www.legislation.gov.uk/namespaces/metadata" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:dct="http://purl.org/dc/terms/" source="#"><dc:identifier>http://www.legislation.gov.uk/eur/2018/389/chapter/II</dc:identifier><dc:title>Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication (Text with EEA relevance)</dc:title><dct:alternative>Commission Delegated Regulation (EU) 2018/389</dct:alternative><dc:description>Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication (Text with EEA relevance)</dc:description><dc:publisher>King's Printer of Acts of Parliament</dc:publisher><dc:source>https://webarchive.nationalarchives.gov.uk/eu-exit/https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32018R0389</dc:source><dc:type>text</dc:type><dc:format>text/xml</dc:format><dc:language>en</dc:language><dc:modified>2024-07-04</dc:modified><dc:contributor>Expert Participation</dc:contributor><dct:valid>2023-07-11</dct:valid><ukm:EUMetadata><ukm:DocumentClassification><ukm:DocumentCategory Value="euretained"/><ukm:DocumentMainType Value="EuropeanUnionRegulation"/><ukm:DocumentStatus Value="revised"/></ukm:DocumentClassification><ukm:Year Value="2018"/><ukm:Number Value="389"/><ukm:EURLexIdentifiers xmlns:atom="http://www.w3.org/2005/Atom" xmlns="http://www.legislation.gov.uk/namespaces/legislation"><ukm:Cellar Value="28c2f705-268d-11e8-ac73-01aa75ed71a1"/><ukm:ELI Value="reg_del:2018:389:oj"/><ukm:OfficialJournal Value="JOL_2018_069_R_0006"/><ukm:CELEX Value="32018R0389"/></ukm:EURLexIdentifiers><ukm:EnactmentDate Date="2017-11-27"/><ukm:EURLexModified Date="2020-05-13T05:13:10Z"/><ukm:EURLexExtracted Date="2020-05-13T09:54:05Z"/><ukm:XMLGenerated Date="2020-12-12T17:49:56Z"/><ukm:XMLImported Date="2020-12-12T23:20:43Z"/><ukm:Treaty Title="Treaty on the Functioning of the European Union (consolidated version 2012)" Code="TFEU_2012"/><ukm:CreatedBy Label="European Commission" URI="http://publications.europa.eu/resource/authority/corporate-body/COM"/><ukm:CreatedBy Label="Directorate-General for Financial Stability, Financial Services and Capital Markets Union" URI="http://publications.europa.eu/resource/authority/corporate-body/FISMA"/><ukm:Subject Scheme="EuroVoc" Label="financial legislation" URI="http://eurovoc.europa.eu/560"/><ukm:Subject Scheme="EuroVoc" Label="financial services" URI="http://eurovoc.europa.eu/8469"/><ukm:Subject Scheme="EuroVoc" Label="electronic money" URI="http://eurovoc.europa.eu/1971"/><ukm:Subject Scheme="EuroVoc" Label="electronic banking" URI="http://eurovoc.europa.eu/3248"/><ukm:Subject Scheme="DirectoryCode" Label="Banks" URI="http://publications.europa.eu/resource/authority/fd_555/06202020"/><ukm:Subject Scheme="DirectoryCode" Label="Sectoral application" URI="http://publications.europa.eu/resource/authority/fd_555/0620"/><ukm:Subject Scheme="DirectoryCode" Label="Right of establishment and freedom to provide services" URI="http://publications.europa.eu/resource/authority/fd_555/06"/><ukm:Subject Scheme="DirectoryCode" Label="Service activities" URI="http://publications.europa.eu/resource/authority/fd_555/062020"/><ukm:Subject Scheme="EuroVoc" Label="safety standard" URI="http://eurovoc.europa.eu/5234"/><ukm:Subject Scheme="DirectoryCode" Label="Free movement of capital" URI="http://publications.europa.eu/resource/authority/fd_555/1040"/><ukm:Subject Scheme="DirectoryCode" Label="Economic and monetary policy and free movement of capital" URI="http://publications.europa.eu/resource/authority/fd_555/10"/><ukm:Subject Scheme="EuroVoc" Label="information security" URI="http://eurovoc.europa.eu/c_04ae3ba8"/><ukm:Subject Scheme="EuroVoc" Label="payment system" URI="http://eurovoc.europa.eu/c_e749c083"/><ukm:Subject Scheme="EuroVoc" Label="provision of services" URI="http://eurovoc.europa.eu/2602"/><ukm:Subject Scheme="EuroVoc" Label="consumer protection" URI="http://eurovoc.europa.eu/2836"/><ukm:Subject Scheme="EuroVoc" Label="technical standard" URI="http://eurovoc.europa.eu/5235"/><ukm:Subject Scheme="SubjectMatter" Label="Free movement of capital" URI="http://publications.europa.eu/resource/authority/fd_070/LCC"/><ukm:Subject Scheme="SubjectMatter" Label="Freedom of establishment" URI="http://publications.europa.eu/resource/authority/fd_070/LES"/><ukm:Subject Scheme="SubjectMatter" Label="Internal market - Principles" URI="http://publications.europa.eu/resource/authority/fd_070/MARI"/><ukm:DocumentCurrentStatus><ukm:UKAmended Value="true"/></ukm:DocumentCurrentStatus><ukm:UnappliedEffects><ukm:UnappliedEffect Comments="made under Directive 2015/2366/EC Sch. 1 para. (v) Researched using EU Publications Office data" AffectedClass="EuropeanUnionRegulation" AffectingNumber="29" AffectingClass="UnitedKingdomPublicGeneralAct" URI="http://www.legislation.gov.uk/id/effect/key-1ef30993eda9b70c677fcab1eb9989d7" EffectId="key-1ef30993eda9b70c677fcab1eb9989d7" AffectedURI="http://www.legislation.gov.uk/id/eur/2018/389" AffectedNumber="389" AffectedProvisions="Regulation" RequiresApplied="true" Type="revoked" Modified="2026-03-02T11:20:22Z" AffectingProvisions="Sch. 1 Pt. 3" AffectedYear="2018" AffectingURI="http://www.legislation.gov.uk/id/ukpga/2023/29" AffectingYear="2023" Row="1157"><ukm:AffectedTitle>Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication (Text with EEA relevance)</ukm:AffectedTitle><ukm:AffectedProvisions>Regulation</ukm:AffectedProvisions><ukm:AffectingTitle>Financial Services and Markets Act 2023</ukm:AffectingTitle><ukm:AffectingProvisions><ukm:Section Ref="schedule-1" URI="http://www.legislation.gov.uk/id/ukpga/2023/29/schedule/1">Sch. 1 </ukm:Section><ukm:Section Ref="schedule-1-part-3" URI="http://www.legislation.gov.uk/id/ukpga/2023/29/schedule/1/part/3">Pt. 3</ukm:Section></ukm:AffectingProvisions><ukm:Savings><ukm:Section Ref="section-1-4" URI="http://www.legislation.gov.uk/id/ukpga/2023/29/section/1/4">s. 1(4)</ukm:Section></ukm:Savings><ukm:CommencementAuthority><ukm:Section Ref="section-86-3" URI="http://www.legislation.gov.uk/id/ukpga/2023/29/section/86/3">s. 86(3)</ukm:Section></ukm:CommencementAuthority><ukm:InForceDates><ukm:InForce Applied="false" Prospective="true" Qualification=""/></ukm:InForceDates></ukm:UnappliedEffect></ukm:UnappliedEffects></ukm:EUMetadata><ukm:Alternatives><ukm:Alternative URI="http://www.legislation.gov.uk/eur/2018/389/pdfs/eur_20180389_adopted_en.pdf" Date="2017-11-27" Size="493802"/></ukm:Alternatives><ukm:Statistics><ukm:TotalParagraphs Value="38"/><ukm:BodyParagraphs Value="38"/><ukm:ScheduleParagraphs Value="0"/><ukm:AttachmentParagraphs Value="0"/><ukm:TotalImages Value="0"/></ukm:Statistics></proprietary></meta><body eId="body"><chapter eId="chapter-II" uk:target="true"><num>CHAPTER II</num><heading><b>SECURITY MEASURES FOR THE APPLICATION OF STRONG CUSTOMER AUTHENTICATION</b></heading><article eId="article-4"><num>Article 4</num><heading>Authentication code</heading><paragraph eId="article-4-1"><num>1.</num><content><p>Where payment service providers apply strong customer authentication in accordance with Article 97(1) of Directive (EU) 2015/2366, the authentication shall be based on two or more elements which are categorised as knowledge, possession and inherence and shall result in the generation of an authentication code.</p><p>The authentication code shall be only accepted once by the payment service provider when the payer uses the authentication code to access its payment account online, to initiate an electronic payment transaction or to carry out any action through a remote channel which may imply a risk of payment fraud or other abuses.</p></content></paragraph><paragraph eId="article-4-2"><num>2.</num><intro><p>For the purpose of paragraph 1, payment service providers shall adopt security measures ensuring that each of the following requirements is met:</p></intro><level class="para1"><num>(a)</num><content><p>no information on any of the elements referred to in paragraph 1 can be derived from the disclosure of the authentication code;</p></content></level><level class="para1"><num>(b)</num><content><p>it is not possible to generate a new authentication code based on the knowledge of any other authentication code previously generated;</p></content></level><level class="para1"><num>(c)</num><content><p>the authentication code cannot be forged.</p></content></level></paragraph><paragraph eId="article-4-3"><num>3.</num><intro><p>Payment service providers shall ensure that the authentication by means of generating an authentication code includes each of the following measures:</p></intro><level class="para1"><num>(a)</num><content><p>where the authentication for remote access, remote electronic payments and any other actions through a remote channel which may imply a risk of payment fraud or other abuses has failed to generate an authentication code for the purposes of paragraph 1, it shall not be possible to identify which of the elements referred to in that paragraph was incorrect;</p></content></level><level class="para1"><num>(b)</num><content><p>the number of failed authentication attempts that can take place consecutively, after which the actions referred to in Article 97(1) of Directive (EU) 2015/2366 shall be temporarily or permanently blocked, shall not exceed five within a given period of time;</p></content></level><level class="para1"><num>(c)</num><content><p>the communication sessions are protected against the capture of authentication data transmitted during the authentication and against manipulation by unauthorised parties in accordance with the requirements in Chapter V;</p></content></level><level class="para1"><num>(d)</num><content><p>the maximum time without activity by the payer after being authenticated for accessing its payment account online shall not exceed 5 minutes.</p></content></level></paragraph><paragraph eId="article-4-4"><num>4.</num><content><p>Where the block referred to in paragraph 3(b) is temporary, the duration of that block and the number of retries shall be established based on the characteristics of the service provided to the payer and all the relevant risks involved, taking into account, at a minimum, the factors referred to in Article 2(2).</p><p>The payer shall be alerted before the block is made permanent.</p><p>Where the block has been made permanent, a secure procedure shall be established allowing the payer to regain use of the blocked electronic payment instruments.</p></content></paragraph></article><article eId="article-5"><num>Article 5</num><heading>Dynamic linking</heading><paragraph eId="article-5-1"><num>1.</num><intro><p>Where payment service providers apply strong customer authentication in accordance with Article 97(2) of Directive (EU) 2015/2366, in addition to the requirements of Article 4 of this Regulation, they shall also adopt security measures that meet each of the following requirements:</p></intro><level class="para1"><num>(a)</num><content><p>the payer is made aware of the amount of the payment transaction and of the payee;</p></content></level><level class="para1"><num>(b)</num><content><p>the authentication code generated is specific to the amount of the payment transaction and the payee agreed to by the payer when initiating the transaction;</p></content></level><level class="para1"><num>(c)</num><content><p>the authentication code accepted by the payment service provider corresponds to the original specific amount of the payment transaction and to the identity of the payee agreed to by the payer;</p></content></level><level class="para1"><num>(d)</num><content><p>any change to the amount or the payee results in the invalidation of the authentication code generated.</p></content></level></paragraph><paragraph eId="article-5-2"><num>2.</num><intro><p>For the purpose of paragraph 1, payment service providers shall adopt security measures which ensure the confidentiality, authenticity and integrity of each of the following:</p></intro><level class="para1"><num>(a)</num><content><p>the amount of the transaction and the payee throughout all of the phases of the authentication;</p></content></level><level class="para1"><num>(b)</num><content><p>the information displayed to the payer throughout all of the phases of the authentication including the generation, transmission and use of the authentication code.</p></content></level></paragraph><paragraph eId="article-5-3"><num>3.</num><intro><p>For the purpose of paragraph 1(b) and where payment service providers apply strong customer authentication in accordance with Article 97(2) of Directive (EU) 2015/2366 the following requirements for the authentication code shall apply:</p></intro><level class="para1"><num>(a)</num><content><p>in relation to a card-based payment transaction for which the payer has given consent to the exact amount of the funds to be blocked pursuant to Article 75(1) of that Directive, the authentication code shall be specific to the amount that the payer has given consent to be blocked and agreed to by the payer when initiating the transaction;</p></content></level><level class="para1"><num>(b)</num><content><p>in relation to payment transactions for which the payer has given consent to execute a batch of remote electronic payment transactions to one or several payees, the authentication code shall be specific to the total amount of the batch of payment transactions and to the specified payees.</p></content></level></paragraph></article><article eId="article-6"><num>Article 6</num><heading>Requirements of the elements categorised as knowledge</heading><paragraph eId="article-6-1"><num>1.</num><content><p>Payment service providers shall adopt measures to mitigate the risk that the elements of strong customer authentication categorised as knowledge are uncovered by, or disclosed to, unauthorised parties.</p></content></paragraph><paragraph eId="article-6-2"><num>2.</num><content><p>The use by the payer of those elements shall be subject to mitigation measures in order to prevent their disclosure to unauthorised parties.</p></content></paragraph></article><article eId="article-7"><num>Article 7</num><heading>Requirements of the elements categorised as possession</heading><paragraph eId="article-7-1"><num>1.</num><content><p>Payment service providers shall adopt measures to mitigate the risk that the elements of strong customer authentication categorised as possession are used by unauthorised parties.</p></content></paragraph><paragraph eId="article-7-2"><num>2.</num><content><p>The use by the payer of those elements shall be subject to measures designed to prevent replication of the elements.</p></content></paragraph></article><article eId="article-8"><num>Article 8</num><heading>Requirements of devices and software linked to elements categorised as inherence</heading><paragraph eId="article-8-1"><num>1.</num><content><p>Payment service providers shall adopt measures to mitigate the risk that the authentication elements categorised as inherence and read by access devices and software provided to the payer are uncovered by unauthorised parties. At a minimum, the payment service providers shall ensure that those access devices and software have a very low probability of an unauthorised party being authenticated as the payer.</p></content></paragraph><paragraph eId="article-8-2"><num>2.</num><content><p>The use by the payer of those elements shall be subject to measures ensuring that those devices and the software guarantee resistance against unauthorised use of the elements through access to the devices and the software.</p></content></paragraph></article><article eId="article-9"><num>Article 9</num><heading>Independence of the elements</heading><paragraph eId="article-9-1"><num>1.</num><content><p>Payment service providers shall ensure that the use of the elements of strong customer authentication referred to in Articles 6, 7 and 8 is subject to measures which ensure that, in terms of technology, algorithms and parameters, the breach of one of the elements does not compromise the reliability of the other elements.</p></content></paragraph><paragraph eId="article-9-2"><num>2.</num><content><p>Payment service providers shall adopt security measures, where any of the elements of strong customer authentication or the authentication code itself is used through a multi-purpose device, to mitigate the risk which would result from that multi-purpose device being compromised.</p></content></paragraph><paragraph eId="article-9-3"><num>3.</num><intro><p>For the purposes of paragraph 2, the mitigating measures shall include each of the following:</p></intro><level class="para1"><num>(a)</num><content><p>the use of separated secure execution environments through the software installed inside the multi-purpose device;</p></content></level><level class="para1"><num>(b)</num><content><p>mechanisms to ensure that the software or device has not been altered by the payer or by a third party;</p></content></level><level class="para1"><num>(c)</num><content><p>where alterations have taken place, mechanisms to mitigate the consequences thereof.</p></content></level></paragraph></article></chapter></body></act></akomaNtoso>