On 14 March 2022, Strong Customer Authentication (SCA) and 3D Secure became mandatory for all website- and app-based card transactions in the UK and EU. This introduced an additional verification step—often a 6-digit code sent by text/email or an approval via a banking app.
Donorfy has been fully SCA and 3D Secure compliant since 2019. All Donorfy Forms, Campaign Donation Pages and Web Widgets use Stripe’s secure payment elements. Because the payment process occurs entirely within Stripe, Donorfy remains PCI compliant.
What SCA Means for Donors
SCA requires cardholders to authenticate higher-risk or randomly selected transactions. This may involve:
Entering a one-time passcode (OTP) sent by SMS or email.
Approving the payment through a banking app.
If the donor enters the OTP incorrectly or fails to respond, the transaction will fail.
Lower-risk transactions may bypass the challenge, but banks typically require every sixth online transaction per card to undergo SCA, and all higher-risk payments always require authentication.
Because SCA is still relatively new for many cardholders, a temporary increase in failed transactions may occur.
Customer / Supporter Actions
Ensure their contact details (email and phone number) are up to date with their bank.
Enable push notifications in their mobile banking app.
Check the card is not frozen, restricted, or blocked for online transactions.
Ensure their device is receiving OTP messages reliably.
Your Online Forms and Web Widgets
To help more transactions pass SCA challenges:
Add a 3D Secure information notice
Include a paragraph explaining that online transactions now require additional verification and that donors should try another card or payment method if a transaction is declined.Collect additional donor information
Add address, email, and phone number fields to your forms. Stripe passes these details to the card issuer, which can strengthen verification and reduce the likelihood of SCA challenges failing.Offer more payment options (Donorfy Forms only)
Enable:Apple Pay
Google Pay
Microsoft Pay
PayPal
These payment methods include built-in two-factor authentication, which often leads to fewer declines.
Monitor Stripe for failed transactions
Use your Stripe Dashboard to identify failed attempts.
When you see a decline, you can contact the donor and offer an alternative payment option such as a MOTO payment (Stripe Terminal or phone payment).
📌 Note: MOTO payments are exempt from SCA and will not trigger authentication challenges.
Chat to support and stay up to date
If you are seeing continued issues with failing payments, raise a support request with Stripe initially (Stripe's support website) and also let the Donorfy team know via a support ticket.
Follow Stripe on Twitter - @StripeStatus or via their Stripe Status webpage here you find out about regional and global incidents.
