<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Strong Customer Authentication in Integration and Testing</title>
    <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68352#M41582</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have software which integrates with&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="il"&gt;Authorize&lt;/SPAN&gt;&lt;SPAN&gt;.N&lt;/SPAN&gt;&lt;SPAN class="il"&gt;et&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;using an Authorize.Net hosted payment page. I understand that a new EU regulation regarding online payments is coming into force on September 2019, called Strong Customer Authentication (SCA), part of PSD2, and I'm assuming that&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="il"&gt;Authorize&lt;/SPAN&gt;&lt;SPAN&gt;.N&lt;/SPAN&gt;&lt;SPAN class="il"&gt;et&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;has or will be making changes to support it. Can anyone confirm whether we'll need to make any changes to our integration as a result or will everything be handled on the Authorize.Net side?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any pointers would be gratefully received!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Matt&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jul 2019 16:31:28 GMT</pubDate>
    <dc:creator>mattcollins</dc:creator>
    <dc:date>2019-07-10T16:31:28Z</dc:date>
    <item>
      <title>Strong Customer Authentication</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68352#M41582</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have software which integrates with&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="il"&gt;Authorize&lt;/SPAN&gt;&lt;SPAN&gt;.N&lt;/SPAN&gt;&lt;SPAN class="il"&gt;et&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;using an Authorize.Net hosted payment page. I understand that a new EU regulation regarding online payments is coming into force on September 2019, called Strong Customer Authentication (SCA), part of PSD2, and I'm assuming that&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="il"&gt;Authorize&lt;/SPAN&gt;&lt;SPAN&gt;.N&lt;/SPAN&gt;&lt;SPAN class="il"&gt;et&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;has or will be making changes to support it. Can anyone confirm whether we'll need to make any changes to our integration as a result or will everything be handled on the Authorize.Net side?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any pointers would be gratefully received!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Matt&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2019 16:31:28 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68352#M41582</guid>
      <dc:creator>mattcollins</dc:creator>
      <dc:date>2019-07-10T16:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Strong Customer Authentication</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68609#M41781</link>
      <description>&lt;P&gt;I'm also wondering the same and would love a reply to this from Authorize.net. Thanks!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 14:33:27 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68609#M41781</guid>
      <dc:creator>phanie12</dc:creator>
      <dc:date>2019-07-31T14:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: Strong Customer Authentication</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68706#M41863</link>
      <description>&lt;P&gt;Yeah, is there an update here? It seems that Authorize.net is pretty slow to react to changes like this, unlike Stripe.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Aug 2019 21:18:37 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68706#M41863</guid>
      <dc:creator>dnetzer</dc:creator>
      <dc:date>2019-08-10T21:18:37Z</dc:date>
    </item>
    <item>
      <title>Re: Strong Customer Authentication</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68707#M41864</link>
      <description>&lt;P&gt;Hi Matt, were you able to find any good resources on this? Not seeing much! Which seems odd.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Aug 2019 21:20:06 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68707#M41864</guid>
      <dc:creator>dnetzer</dc:creator>
      <dc:date>2019-08-10T21:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: Strong Customer Authentication</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68715#M41871</link>
      <description>&lt;P&gt;No, I haven't found anything about it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It sounds like the industry as a whole has been slow to implement the necessary changes and, as a result, the UK's regulator, at least, is likely to delay when they start enforcing of it:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.fstech.co.uk/fst/FCA_UK_Finance_18_Month_Delay_SCA_Deadline.php" target="_blank"&gt;http://www.fstech.co.uk/fst/FCA_UK_Finance_18_Month_Delay_SCA_Deadline.php&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other countries' regulators may or may not do the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2019 10:58:22 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68715#M41871</guid>
      <dc:creator>mattcollins</dc:creator>
      <dc:date>2019-08-12T10:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: Strong Customer Authentication</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68720#M41876</link>
      <description>&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/23642"&gt;@dnetzer&lt;/a&gt; &lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/31512"&gt;@mattcollins&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;A few things about this- 1 is that you can use 3D secure to comply with this. Auth.net payment transaction API already has a request field to pass this value. 2 is that this is only applicable to transactions of a certain amount, equal to around $50 USD I think. 3 the $50 doesn’t help you that much, but you can also get an exemption for “low risk transactions” which depend on the fraud rate at your MSP and payment provider. I think if both fraud rates are .01% or less you are exempt for any transaction of any amount. 4 cybersource which has common ownership with auth.net is implementing this, so it is likely on auth.nets radar.&lt;BR /&gt;&lt;BR /&gt;The easiest way that already exists on auth.net seems to be the 3DS. For that it is up to your MSP to use 3DS 2.0.</description>
      <pubDate>Mon, 12 Aug 2019 15:03:49 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68720#M41876</guid>
      <dc:creator>Renaissance</dc:creator>
      <dc:date>2019-08-12T15:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: Strong Customer Authentication</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68722#M41878</link>
      <description>&lt;P&gt;OK, seems so far I'm getting the run around on this and playing a game of "Pass the Hot Potato".&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I first called Authorize.net Merchant Support and my rep told me&lt;SPAN&gt;&amp;nbsp;they do not have any information on PSD2 yet and he directed me to:&amp;nbsp;&lt;A href="mailto:Privacy@visa.com" target="_blank" rel="noopener"&gt;Privacy@visa.com&lt;/A&gt;&amp;nbsp;for further support.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I did question why Authroize.net was referring me to Vias for this but they said that's who is responsible for this matter. Then I got this email response:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Thank you for writing. Your question was forwarded to the Visa USA area for further assistance. For future queries that address is:&amp;nbsp;&lt;/SPAN&gt;&lt;A href="mailto:askvisausa@visa.com" target="_blank" rel="noopener"&gt;askvisausa@visa.com&lt;/A&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Who later responded with this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;Thank you for your inquiry.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For specific assistance of this nature, please contact the Visa client financial institution with which you have your business account. Visa does not set up, service, or have access to cardholder or merchant accounts. This is done through our client financial institutions (the banks).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Your bank is the only party that can directly assist you with this matter. You may wish to speak with a manager or supervisor.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you for writing.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Visa Webmaster&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is Vias referring me back to Authroize,.net here or my bank? Correct me if I'm wrong but my bank, (BB&amp;amp;T) has nothing to do with PSD2 and how the credit cards are being processed via Authroize.net. Or am I wrong on that?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not happy about the run around I'm getting at all.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2019 15:09:30 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68722#M41878</guid>
      <dc:creator>phanie12</dc:creator>
      <dc:date>2019-08-12T15:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Strong Customer Authentication</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68734#M41889</link>
      <description>&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/31935"&gt;@phanie12&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;BB&amp;amp;T is likely your payment processor and MSP. Auth.net acts as a gateway only for many companies.&lt;BR /&gt;&lt;BR /&gt;I googled it and I don’t see that authorize.net has a location in the EEA. I’m not seeing how any transaction for a U.S. based company with a U.S. based payment gateway and a U.S. bank falls under the jurisdiction of the EU. The PSD2 legislation is online, and without reading all of it, it has the scope of the regulation including businesses *located* in the EU or EEA. It has language “both the payee ..... and the payer” in reference to the PSPs in the scope, meaning if any one party is outside the EEA on either side then the SCA isn’t applicable.&lt;BR /&gt;&lt;BR /&gt;So unless you are an EEA member based business with an acquiring bank located in the EEA, I don’t think this is an issue to be concerned with.</description>
      <pubDate>Wed, 14 Aug 2019 00:58:39 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68734#M41889</guid>
      <dc:creator>Renaissance</dc:creator>
      <dc:date>2019-08-14T00:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: Strong Customer Authentication</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68738#M41893</link>
      <description>&lt;P&gt;Thanks for your input on this, R.:)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would really like to hear it directly from someone at Authorize.net (would put all of our minds at ease I'm sure) since it seems some of the other online payment processors like Stripe and CyberSource have already addressed and made sure they are PSD2 compliant.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2019 15:09:35 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68738#M41893</guid>
      <dc:creator>phanie12</dc:creator>
      <dc:date>2019-08-14T15:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: Strong Customer Authentication</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68748#M41902</link>
      <description>Cybersource is the parent of auth.net. Visa is the parent company of Cybersource. Cybersource deals with large businesses, while auth.net is the arm that does the smaller businesses. From this we can deduce two things- 1 Cybersource deals with more multinational companies, and 2 being that Cybersource and auth.net are under the same leadership at some level, if auth.net has anything needed for this they will be doing it just like Cybersource. Stripe may be a larger processor, I don’t know. Their website also mentions the location exclusion.&lt;BR /&gt;&lt;BR /&gt;You will likely get an answer from auth.net at some point, but I would rest easy if I were you. If someone on the phone tells you that you are required to comply, they are wrong and you can rest easy. If they tell you that you do not need to comply, you can rest easy there too. You can skip the middle man and google to get the legislation.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 15 Aug 2019 04:38:11 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68748#M41902</guid>
      <dc:creator>Renaissance</dc:creator>
      <dc:date>2019-08-15T04:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: Strong Customer Authentication</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68750#M41903</link>
      <description>&lt;P&gt;Thank you for your valuable input. We'll go with that for now!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 15:46:11 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/68750#M41903</guid>
      <dc:creator>phanie12</dc:creator>
      <dc:date>2019-08-15T15:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: Krispy Kreme Customer</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/80129#M50478</link>
      <description>&lt;P&gt;I googled it and I don't see that authorize.net has an area in the EEA. I'm not perceiving how any exchange for a U.S. based organization with a U.S. based installment entryway and a U.S. bank falls under the locale of the EU. The PSD2 enactment is on the web, and without perusing every last bit of it, it has the extent of the guideline incorporating organizations *located* in the EU or EEA. It has language&amp;nbsp;&lt;A href="https://smokelesscooking.com/best-gas-grill-smoker-combo/" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;check it out article&lt;/SPAN&gt;&lt;/A&gt; "both the payee ..... what's more, the payer" regarding the PSPs in the degree, which means on the off chance that any one party is outside the EEA on either side then the SCA isn't material.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Nov 2021 22:36:43 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/Strong-Customer-Authentication/m-p/80129#M50478</guid>
      <dc:creator>alexabell</dc:creator>
      <dc:date>2021-11-28T22:36:43Z</dc:date>
    </item>
  </channel>
</rss>

