Skip to main content
Certyneo
Glossary term · A

Strong authentication

Definition

Strong authentication requires the presentation of at least two proofs of identity belonging to different categories to verify a person''s identity — this is the principle of MFA (multi-factor authentication) :
• What I know : password, PIN code ;
• What I have : phone receiving an OTP code, YubiKey/FIDO2 security key, smart card ;
• What I am : fingerprint, facial recognition (biometrics).

Two regulatory frameworks require it : the DSP2 directive (art. 97) requires SCA — Strong Customer Authentication — for payments and access to online bank accounts; the eIDAS regulation requires it de facto for advanced electronic signature (AES), article 26 of which requires that the signature be created under the exclusive control of the signatory and be linked to them in a unique manner.

In electronic signature, strong authentication occurs at the moment of signing: the signatory proves they control their email address (unique link) and their phone (SMS OTP code) before the document is sealed. This double verification, time-stamped in the audit trail, is what distinguishes an enforceable AES from a simple checkbox.

On Certyneo : for envelopes at the advanced level, the email + SMS OTP combination is applied by default to each signatory; user accounts can enable MFA (TOTP or email OTP). DSP2 & strong authentication: the guide →

Ready to put these concepts into practice?

Certyneo allows you to create eIDAS-compliant signature envelopes in a few clicks, without installation.