# OB-SCA-003 — AISP SCA every 180 days

> The AISP applies SCA when the user accesses their data through it at least 180 days after the last one, using its own SCA or the ASPSP's.

- Article: PSR 86(4)
- Who is bound: AISP
- Who it is for: Product, API, Audit and pentest
- Application: 21 months after entry into force, the general application date (Article 112).
- Level 2: RTS under Article PSR 89(1)(a), draft due at T + 12 months.
- Origin: RTS 2018/389, Art. 10

Provisional numbering of the April 2026 compromise (Council doc. 8221/26). The final numbering will be added when the Official Journal publishes the text, without changing the id.

## STET 1.6.3: To review

Using the bank's SCA, the AISP runs a full OAuth2 authorisation journey again. STET does not provide for the AISP telling the bank about an SCA it performed itself.

- <https://openfinanceguide.com/en/stet/1.6.3/flows/6-1-psu-context-retrieval>
- <https://openfinanceguide.com/en/stet/1.6.3/framework/3-prerequisites-and-technical-details>

## Sources

- [Council doc. 8221/26, page 363](https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=363)

Checked on 2026-10-04. https://openfinanceguide.com/en/dsp3/obligations/ob-sca-003
