The proliferation of digital commerce has magnified the tension between securing online transactions and providing a seamless user experience. For merchants, payment fraud represents a substantial financial threat, costing e-commerce businesses an average of 3.6% of their total revenues in 2022, with cumulative losses projected to reach USD 206 billion between 2021 and 2025.1 In response, regulatory bodies and technology providers have developed distinct models for authenticating users and authorizing payments. In the European Union, the revised Payment Services Directive (PSD2) established a top-down, regulatory mandate for Strong Customer Authentication (SCA), enforcing a multifactor approach to security.2 In contrast, the United States has largely pursued a market-driven path, characterized by industry-led innovation and the voluntary adoption of new technologies like passkeys, which are based on the FIDO2 standard.3
While both approaches aim to reduce fraud, their methodologies and resulting impacts on the digital ecosystem differ profoundly. The EU’s prescriptive framework has demonstrated success in curbing fraudulent activities but has been criticized for introducing significant friction into the payment process, leading to increased cart abandonment and lost revenue for merchants. Conversely, passkeys promise a future of phishing-resistant security combined with a simplified, often single-gesture, user experience. However, their integration into Europe’s rigid regulatory landscape faces considerable challenges.
This paper aims to provide a comparative analysis of these two models from a multi-stakeholder perspective, encompassing merchants, financial institutions, technology providers, regulators, and consumers. By examining both quantitative metrics (e.g., fraud rates, transaction success) and qualitative factors (e.g., user experience, implementation complexity), this study seeks to illuminate the trade-offs inherent in each approach and provide insights into the future of digital payment authentication.
The academic and industry literature reveals a clear divergence between the regulatory-push model of the EU and the market-pull dynamics of the US in payment authentication. PSD2 mandates SCA for electronic payments within the European Economic Area, requiring authentication using at least two of three independent factors: knowledge (something only the user knows), possession (something only the user possesses), and inherence (something the user is).2 An opinion from the European Banking Authority (EBA) further clarified that these two elements must belong to different categories, effectively upgrading the requirement to true two-factor authentication (2FA).4
This regulatory intervention has yielded significant results in fraud prevention. A report from the EBA showed that the average fraud rate in Europe was halved to 0.06% between June 2020 and June 2021.5 Similarly, France reported a 37% decrease in online card fraud between 2019 and 2021 following SCA implementation.6 However, this security gain came at a considerable cost to user experience and merchant revenue. The initial rollout of SCA caused some European merchants to lose nearly 40% of transactions due to user confusion and cart abandonment.7 Other research found that merchants in France, Germany, Italy, and Spain lost between 26% and 39% of transactions where 3-D Secure (3DS), a primary mechanism for SCA, was applied.8 A 2016 PayPal study noted an average 40% transaction abandonment rate following the introduction of 3DS, and an econometric analysis found that a significant increase in secure payments was associated with a reduction in overall card turnover.9
In contrast, the US market, characterized by voluntary industry initiatives, has fostered the growth of passkey technology.3 Passkeys, built on the FIDO2 standard, inherently satisfy two of the three SCA elements (possession via the user’s device and either inherence via biometrics or knowledge via a PIN) and are designed to be phishing-resistant.10 Large-scale deployments in the US have demonstrated the potential to achieve superior outcomes on both security and usability fronts. For example, PayPal reported that its implementation of passkeys resulted in a 70% reduction in Account Takeover (ATO) rates and a more than 10% increase in login success rates compared to passwords.6 Further data suggests passkeys can lead to a 4x higher login success rate and a 60-90% reduction in authentication support costs for banking institutions.11 The primary gap this paper addresses is the direct comparison of these two models, with a focus on the regulatory ambiguity in the EU that hinders the adoption of technologically superior, user-friendly solutions like passkeys.6
This study utilizes a comparative analysis framework to evaluate the EU’s PSD2 SCA regulations against the US market-driven adoption of passkeys. The research synthesizes evidence from a curated selection of sources, including academic studies, industry white papers, reports from regulatory bodies like the European Banking Authority, and technical documentation from technology providers. This approach allows for a comprehensive assessment that incorporates both theoretical underpinnings and real-world performance data.
To ensure a balanced evaluation, the analysis is structured from a multi-stakeholder perspective, considering the distinct priorities and concerns of merchants (conversion, implementation costs), financial institutions (risk, compliance), technology providers (innovation, market share), regulators (consumer protection, market stability), and end-consumers (experience, security). The comparison is based on a balanced scorecard of quantitative and qualitative metrics. Quantitative indicators include fraud reduction rates, transaction approval rates, false decline rates, and cart abandonment rates. Qualitative factors include user experience (UX) and sentiment, perceived security, implementation complexity, and the long-term viability of the respective ecosystems.
By juxtaposing these metrics across the two models, this paper aims to provide a nuanced understanding of the trade-offs between mandated security and market-led innovation in the digital payments landscape.
The analysis of the two authentication models reveals a stark contrast in outcomes related to security, commerce, and technological adoption. The findings are organized into quantitative and qualitative comparisons to highlight the inherent trade-offs.
On the primary objective of fraud reduction, PSD2 SCA has been an unambiguous success. Data shows that the regulation helped halve the average fraud rate in Europe to just 0.06% and contributed to a 37% drop in online card fraud in France.5,6 This stands in sharp contrast to the US, where one source placed the card-not-present fraud level at 4%.5 However, this success was achieved at the expense of commercial efficiency. The friction introduced by SCA led to significant transaction failures, with reports of merchants initially losing up to 40% of transactions and sustained losses of 26-39% in transactions where 3DS was applied.7,8 Earlier studies also pointed to a 40% transaction abandonment rate with 3DS.9
The US passkey model presents a different narrative. Data from PayPal’s large-scale deployment shows it is possible to achieve dual objectives: a 70% reduction in account takeover fraud was accompanied by a 10% increase in login success rates.6 Further evidence suggests passkeys can deliver a 4x higher login success rate than passwords and dramatically reduce authentication-related support costs.11 This quantitative data suggests that market-driven technological innovation has produced a solution that is superior in balancing security and user experience, whereas the regulatory approach forced a direct trade-off between the two.
From a qualitative perspective, the implementation of SCA in Europe has been complex and fragmented. A study of the DACH region revealed that while most issuers offered an app-based authentication procedure, 83% of these were separate, non-integrated apps, creating a disjointed user journey.12 For merchants, a key technical challenge is implementing ‘dynamic linking,’ a cornerstone of PSD2 that requires each transaction to be authenticated with a code specific to the payment amount and payee.10
The primary hurdle for passkey adoption in the EU is regulatory ambiguity. The EBA has not provided clear guidance on whether a passkey (possession) unlocked by a biometric (inherence) on the same device constitutes two sufficiently independent factors.6 This uncertainty causes banks and Payment Service Providers (PSPs) to avoid relying on passkeys for SCA compliance.6 Further complexity arises from the distinction between ‘synced passkeys’ (cloud-based) and ‘device-bound passkeys.’ While the latter are PSD2 compliant, the former, which offer a better user experience, are not, forcing a trade-off between compliance and convenience.13 In contrast, the US ecosystem fosters competing architectural models for passkey integration—Issuer-Centric, Merchant-Centric, Network-Centric, and PSP-Centric—driving innovation as players like Visa and Mastercard launch proprietary passkey services.14,15
The findings illuminate a fundamental divergence in philosophy and outcome between regulatory-prescribed security and market-driven innovation. PSD2’s SCA mandate successfully established a high, uniform floor for payment security across the EU, drastically reducing fraud. However, its rigid, factor-based framework has inadvertently become a barrier to adopting newer, more user-friendly, and potentially more secure technologies like passkeys. The initial high rates of transaction abandonment demonstrate the significant economic cost of prioritizing security compliance over user experience. While systems like Mastercard’s Identity Check aim to make 90–95% of authentications frictionless through risk-based analysis, the underlying friction of a challenge remains a threat to conversion.16
The US passkey adoption model, led by major technology and payment players, demonstrates that the goals of fraud reduction and customer convenience are not mutually exclusive. PayPal’s results—simultaneously decreasing fraud and increasing login success—underscore the power of an outcome-focused approach.6 The urgency for such an approach is amplified by the evolving threat landscape; the rise of AI-driven phishing attacks, which saw a 1,265% increase in malicious emails after the launch of ChatGPT, renders traditional phishable factors like SMS OTPs increasingly obsolete.6 Passkeys, being inherently phishing-resistant, are better suited to this modern reality.
However, the European regulatory landscape is not static. The proposed PSD3/PSR framework introduces new rules for Delegated Authentication (DA), where a merchant or third party performs SCA. By classifying DA as ‘outsourcing,’ the framework imposes significant compliance burdens, including liability for fraud, on the authenticating party.17 This move could complicate merchant-centric passkey models, and industry players like Mastercard are actively lobbying against such a broad classification, arguing it could stifle innovation.18 This ongoing debate highlights the struggle to fit modern, distributed identity models into traditional, centralized regulatory frameworks.
This comparative analysis reveals that while the EU’s regulatory-driven PSD2 SCA framework has been highly effective in reducing payment fraud, it has done so at the cost of significant customer friction and has been slow to adapt to superior authentication technologies. In contrast, the market-driven adoption of passkeys in the US demonstrates a powerful alternative, achieving substantial fraud reduction while simultaneously enhancing the user experience. The primary barrier to harmonizing these outcomes is the regulatory ambiguity within the EU, which penalizes innovation by adhering to a prescriptive, factor-based definition of security rather than focusing on the outcome of phishing resistance.
For the digital payments ecosystem to advance, regulatory frameworks must evolve to become technology-neutral and outcome-oriented. Instead of dictating the ‘how’ of authentication, future regulations should define the ‘what’—resilience against modern threats like account takeover and phishing. Future research should focus on the real-world impact of the finalized PSD3/PSR on Delegated Authentication models, conduct longitudinal studies on the economic and security effects of scaled passkey adoption in the US, and perform qualitative analyses of consumer trust and preference between SCA and passkey-based systems.