Skip to content
Risk & Compliance

CVV (Card Verification Value)

3-4 digit security code on back of card. Proves cardholder has physical card. Reduces CNP fraud by 25-40%.

Overview

What is CVV?

CVV (Card Verification Value), also called CVV2, CVC (Card Verification Code), or CID (Card Identification Number), is the 3-digit security code printed on the back of Visa/Mastercard/Discover cards or the 4-digit code on the front of American Express cards. CVV codes verify that the person making an online purchase physically possesses the card - not just the card number. Unlike card numbers and expiration dates that merchants store for recurring billing, CVV codes cannot be stored after authorization per PCI DSS regulations, making CVV an effective defense against data breach fraud where criminals steal stored card data but lack CVV codes.

CVV verification reduces CNP fraud by 25-40% by blocking transactions where fraudsters have stolen card numbers but don't possess the physical card to obtain the CVV. When customers enter payment details at checkout, your payment gateway sends the card number, expiration, and CVV to the issuing bank for verification. The issuer confirms whether the CVV matches their records, returning match/no-match/unavailable responses. High-risk merchants typically decline all CVV mismatches to minimize fraud exposure, accepting 1-3% false declines from legitimate customers who mistype CVV codes or have worn cards where CVV is illegible.

CVV limitations prevent it from being a complete fraud solution. CVV match doesn't guarantee legitimacy - fraudsters with complete card data (number, expiration, CVV, billing address) obtained through phishing or point-of-sale breaches can still commit fraud. International card support varies - some international issuers don't participate in CVV verification programs, returning "unavailable" responses that force merchants to process without CVV confirmation. Customer entry errors generate 2-3% false decline rates when legitimate customers mistype CVV, mis-read worn cards, or enter CVC2 instead of CVV2 for certain card types.

Storage prohibitions are strictly enforced under PCI DSS. Merchants cannot store CVV codes after initial authorization - not in databases, log files, backup systems, or any persistent storage. This makes CVV valuable for first-time transactions but useless for recurring billing (where customers' stored cards lack CVV data for future charges). Merchants caught storing CVVs face immediate PCI compliance violations, potential $5K-100K monthly fines, and possible merchant account termination. This prohibition is why recurring billing has higher fraud rates than initial purchases - the CVV verification isn't available for subscription renewals.

In depth

Everything you need to know.

During checkout, customers enter card number, expiration date, and CVV code into your payment form. Your gateway captures this data and transmits it to the acquirer via secure connection, which forwards to the card network, which routes to the issuing bank. The issuer validates the CVV against their records and returns one of three responses: Match (CVV is correct), No Match (CVV is incorrect - likely fraud or customer error), or Not Processed/Unavailable (issuer doesn't support CVV verification or system error). Your fraud rules determine how to handle each response. Most high-risk merchants decline "No Match" transactions automatically (accepting 1-2% false positive rate from legitimate customer errors), while "Not Processed" responses require risk-based decisions - declining loses international customers but accepting increases fraud exposure. After authorization, the CVV must be immediately purged from all systems per PCI DSS - you can store card number tokens for recurring billing but never CVV codes.

CVV verification is your first-line defense against card-not-present fraud. For high-risk merchants experiencing 1-3% fraud rates (costing $100K-300K annually on $10M volume), enforcing CVV matches reduces fraud by 25-40%, recovering $25K-120K yearly. This fraud reduction also protects chargeback rates: a merchant at 0.9% chargeback rate with CVV enforcement stays compliant, while removing CVV verification might push rates to 1.2-1.5%, triggering ECP monitoring programs and threatening merchant account termination. CVV also shifts fraud liability in some scenarios: transactions with CVV match receive better treatment during chargeback disputes than CVV-not-checked transactions, improving representment win rates 10-15%. The storage prohibition, while inconvenient for recurring billing, actually benefits merchants by reducing PCI scope - if you never store CVV, you eliminate entire attack vectors from compliance assessments, potentially saving $15K-40K annually in reduced PCI validation costs.

Illustrative example — not a specific client engagement.

  • An e-commerce merchant processing $8M annually with 2.1% fraud rate implemented strict CVV matching (declining all mismatches), reducing fraud to 1.3% within 3 months. This $64K annual fraud recovery also brought chargeback rate from 1.2% to 0.8%, preventing entry into Visa ECP monitoring program and avoiding $15K-25K monthly ECP fines.
  • A subscription service experiencing 18% recurring billing failure rates (customers' cards expiring or reissuing) implemented network tokenization that automatically updates card details including CVV equivalent for recurring charges. Recurring authorization rates improved from 82% to 91%, recovering $162K annually in previously failed renewals on $1.8M subscription revenue.
  • A high-ticket merchant ($2K average order) implemented adaptive CVV requirements: requiring CVV for orders under $1K but making it optional (with 3D Secure mandatory) for orders over $1K where international customers frequently lacked CVV due to corporate card policies. This reduced international cart abandonment 23% while maintaining fraud rates through 3D Secure liability shift, generating $340K additional annual revenue.
  • Decline all CVV "No Match" transactions on first-time purchases - accept 1-2% false decline rate to prevent 25-40% fraud reduction
  • Implement risk-based handling for "Not Processed" CVV responses: accept for low-value orders ($50) or high fraud-score transactions ($200+)
  • Monitor CVV match rates by geography - if specific countries show 20%+ "Not Processed" rates, consider accepting without CVV for those markets with additional fraud checks
  • Combine CVV with complementary fraud tools: AVS verification (address matching), device fingerprinting, velocity checking, and 3D Secure for high-value transactions
  • Educate customers on CVV location in checkout flow - "3-digit code on back of card" with visual diagram reduces entry errors 15-25%
  • Implement immediate CVV purging post-authorization - use tokenization systems that automatically strip CVV from stored payment methods
  • For recurring billing, use network tokenization where available - Visa/Mastercard network tokens update automatically when cards reissue, reducing recurring payment failures
  • Storing CVV codes after authorization for "customer convenience" - immediate PCI violation risking $5K-100K monthly fines and merchant account termination
  • Accepting CVV mismatch transactions to avoid losing sales - increases fraud rates 30-50% and drives chargeback rates above monitoring thresholds
  • Not distinguishing between "No Match" and "Not Processed" CVV responses - treating all CVV failures identically declines legitimate international transactions unnecessarily
  • Requiring CVV for subscription renewals - impossible since CVV cannot be stored, frustrating customers who must re-enter cards for each renewal
  • Logging CVV codes in error logs or support tickets - creates PCI violations even if CVV never reaches primary database
  • Using CVV as only fraud prevention measure - CVV match does not prevent fraud from complete card data theft or account takeover

Keep exploring

Related terms

APPROVED

Put this to work
for your business.

MIDs structures high-risk acquiring across 30+ banks — smart routing, fraud and chargeback control built in. Tell us your category and volume and we'll build the setup around it.