What card verification value (CVV) is – and how it helps businesses prevent fraud

What is the CVV code on credit and debit cards? Here’s what a card verification value (CVV) is and how CVV numbers help businesses prevent fraud.

Payment Processor Guide Editorial Team4 min read
Share
Cover image for What card verification value (CVV) is – and how it helps businesses prevent fraud

CVV stands for Card Verification Value, the 3-digit code (4 digits on American Express) printed on a payment card and used to confirm the person making an online or phone purchase actually has the physical card in hand.

Anyone who's checked out online has typed a CVV without necessarily knowing what it does or why it exists. It's a small detail with an outsized role in preventing card fraud, especially for the growing share of purchases that happen without a card ever being physically swiped or tapped.

What CVV stands for and where to find it

CVV, short for Card Verification Value, goes by a few different names depending on the card network:

  • CVV / CVV2: Visa

  • CVC / CVC2: Mastercard

  • CID: American Express

Despite the different names, they all serve the same purpose. On Visa, Mastercard, and Discover cards, it's the 3-digit number on the back of the card, next to the signature strip. On American Express cards, it's a 4-digit number printed on the front, above the card number.

Why the CVV exists

A card's primary account number is often exposed in ways that make it vulnerable, receipts, card readers, and in some cases data breaches. The CVV is deliberately not encoded on the card's magnetic stripe or chip, which means someone who copies the card number from a receipt or a skimmed swipe still doesn't have the CVV.

That gap is exactly the point. Requiring the CVV for online and phone purchases is a way of confirming the buyer has physical possession of the card itself, not just its number, which is why it's specifically effective against card-not-present fraud.

Why merchants can't store your CVV

Under PCI DSS, the security standard that governs how businesses handle card data, merchants are prohibited from storing the CVV after a transaction is authorized, regardless of how the rest of the card data is stored. This is one of the more strictly enforced rules in the entire standard, precisely because a stored CVV defeats the purpose it exists for.

In practice, this means:

  • A legitimate business will never ask you to provide your CVV for a recurring or saved-card charge after the first transaction

  • Any site or service that claims to have your CVV on file for future use is violating PCI requirements, and that's a meaningful red flag

  • If your business accepts cards and stores customer payment info for repeat purchases, your payment processor should be handling this compliantly through tokenization, not by retaining raw CVV data anywhere in your systems

CVV vs. other card security terms

It's easy to mix up CVV with other card details, since they're often requested together at checkout:

  • CVV confirms physical possession of the card, used for card-not-present transactions

  • PIN authenticates the cardholder for in-person, chip-and-PIN or ATM transactions, and can be changed by the cardholder

  • Card number (PAN) identifies the specific account, and is what actually gets charged

Only the CVV is designed specifically to combat fraud in situations where the card itself can't be physically verified.

What to do if you're asked for your CVV somewhere unusual

A few situations worth treating with caution:

  • A phone call claiming to be your bank asking for your CVV. Legitimate banks generally don't need your CVV to verify your identity over the phone; if in doubt, hang up and call your bank directly using the number on the back of your card.

  • A merchant asking for your CVV for a subscription renewal. If they charged your card successfully before without asking, a sudden CVV request could indicate the original transaction wasn't compliant, or the request itself is a phishing attempt.

  • Any site storing your CVV "for convenience." This shouldn't happen under standard card network and PCI rules, so treat it as a signal to use a different, more compliant checkout.

For businesses accepting card payments

If you're building or evaluating a checkout flow, requiring CVV entry for online and phone transactions is one of the simplest, lowest-friction fraud prevention tools available, and most payment gateways support it by default. For a broader look at what's involved in accepting cards correctly, see our guide on how to accept credit card payments.

Final thoughts

The CVV is a small code doing a specific job: proving the person making an online or phone purchase actually holds the card, not just its number. Understanding what it's for, and knowing that no legitimate business should ever be storing it, is a simple but genuinely useful piece of card security literacy for both shoppers and merchants.

If your business is evaluating processors on how well they handle card security and compliance, it's worth comparing providers side by side on their fraud prevention tools, not just their headline processing rate.

More from the blog