{"id":"circulars/faq-faq-in-relation-to-procedures-and-protocols-exempted-from-strong-customer-authen","title":"FAQ in relation to procedures and protocols exempted from strong customer authentication pursuant to Article 17 of Delegated Regulation (EU) 2018/389","type":"circular","date":"2020-10-01","kind":"faq","html":"<p>FAQ in relation to procedures and protocols exempted from strong customer authentication pursuant to Article 17 of Delegated Regulation (EU) 2018/389 is a CSSF FAQ, published 1 October 2020.</p>\n<p>Relevant for: AISPs, Credit institutions, E-money institutions, Payment institutions, Payment institutions/electronic money institutions/AISPs.</p>\n<p>Keywords: Information and communications technology (ICT), Payment Service Provider (PSP), Payment services, Postal financial services.</p>\n<h2>Text</h2>\n<p>Q&#x26;A in relation to procedures and protocols exempted from SCA pursuant to Article 17 of the delegated Regulation (EU) 2018/389 30/09/2020</p>\n<p>Q&#x26;A IN RELATION TO PROCEDURES AND PROTOCOLS EXEMPTED FROM SCA PURSUANT TO ARTICLE 17 OF THE DELEGATED REGULATION (EU) 2018/389 Unrestricted</p>\n<p>Q&#x26;A in relation to procedures and protocols exempted from SCA pursuant to Article 17 of the delegated Regulation (EU) 2018/389 Question 1: What are the procedures and protocols exempted from SCA pursuant to Article 17 of the delegated Regulation (EU) 2018/389 Article 17 of the RTS provides that “PSPs shall be allowed not to apply strong customer authentication, in respect of legal persons initiating electronic payment transactions through the use of dedicated payment processes or protocols that are only made available to payers who are not consumers, where the competent authorities are satisfied that those processes or protocols guarantee at least equivalent levels of security to those provided for by Directive (EU) 2015/2366\". For the application of Article 17 of the RTS, the CSSF is satisfied that the following protocols and processes guarantee at least equivalent levels of security to those provided for by Directive (EU) 2015/2366: • •</p>\n<p>EBICS-TS version 2.4 and higher SWIFTNet protocols used for FIN, InterAct and FileAct services.</p>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/faq-in-relation-to-procedures-and-protocols-exempted-from-strong-customer-authentication-pursuant-to-article-17-of-delegated-regulation-eu-2018-389/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/FAQ_CSSF_position_art.17_EBICS_SWIFT.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}