Strong authentication

Strong authentication (MFA/2FA) combines two independent factors, such as a password and phone, to secure logins and authorise qualified signatures.

Strong (multi-factor) authentication requires at least two independent factors from different categories: knowledge (PIN, password), possession (phone, token, key) and inherence (biometrics). Compromising one factor must not compromise the other. Using two factors from the same category - for example two passwords, or a PIN plus a security question - does not qualify as strong or multi-factor authentication.

In the trust-services world strong authentication protects account access and - crucially - authorises remote signing. What eIDAS itself demands there is sole control, not literally two factors: the two-factor rule comes from the server-signing standards, where SCAL2 requires each qualified signature (or an authorised batch within one authentication session) to be activated from something only the signatory holds.

Two neighbouring regimes set their own bar. For eID, the assurance levels worked out in Commission Implementing Regulation (EU) 2015/1502 require two factors from different categories at both substantial and high, and the EUDI Wallet targets high. In payments, PSD2 requires strong customer authentication; that regime is being replaced by the PSD3 and PSR proposals, which are agreed but not yet in force, so treat the details of what counts as a factor there as moving.

Frequently asked questions

Back to glossary