What card verification value (CVV) is – and how it helps businesses prevent fraud
What is the CVV code on credit and debit cards? Here’s what a card verification value (CVV) is and how CVV numbers help businesses prevent fraud.

CVV stands for Card Verification Value, the 3-digit code (4 digits on American Express) printed on a payment card and used to confirm the person making an online or phone purchase actually has the physical card in hand.
Anyone who's checked out online has typed a CVV without necessarily knowing what it does or why it exists. It's a small detail with an outsized role in preventing card fraud, especially for the growing share of purchases that happen without a card ever being physically swiped or tapped.
What CVV stands for and where to find it
CVV, short for Card Verification Value, goes by a few different names depending on the card network:
CVV / CVV2: Visa
CVC / CVC2: Mastercard
CID: American Express
Despite the different names, they all serve the same purpose. On Visa, Mastercard, and Discover cards, it's the 3-digit number on the back of the card, next to the signature strip. On American Express cards, it's a 4-digit number printed on the front, above the card number.
Why the CVV exists
A card's primary account number is often exposed in ways that make it vulnerable, receipts, card readers, and in some cases data breaches. The CVV is deliberately not encoded on the card's magnetic stripe or chip, which means someone who copies the card number from a receipt or a skimmed swipe still doesn't have the CVV.
That gap is exactly the point. Requiring the CVV for online and phone purchases is a way of confirming the buyer has physical possession of the card itself, not just its number, which is why it's specifically effective against card-not-present fraud.
Why merchants can't store your CVV
Under PCI DSS, the security standard that governs how businesses handle card data, merchants are prohibited from storing the CVV after a transaction is authorized, regardless of how the rest of the card data is stored. This is one of the more strictly enforced rules in the entire standard, precisely because a stored CVV defeats the purpose it exists for.
In practice, this means:
A legitimate business will never ask you to provide your CVV for a recurring or saved-card charge after the first transaction
Any site or service that claims to have your CVV on file for future use is violating PCI requirements, and that's a meaningful red flag
If your business accepts cards and stores customer payment info for repeat purchases, your payment processor should be handling this compliantly through tokenization, not by retaining raw CVV data anywhere in your systems
CVV vs. other card security terms
It's easy to mix up CVV with other card details, since they're often requested together at checkout:
CVV confirms physical possession of the card, used for card-not-present transactions
PIN authenticates the cardholder for in-person, chip-and-PIN or ATM transactions, and can be changed by the cardholder
Card number (PAN) identifies the specific account, and is what actually gets charged
Only the CVV is designed specifically to combat fraud in situations where the card itself can't be physically verified.
What to do if you're asked for your CVV somewhere unusual
A few situations worth treating with caution:
A phone call claiming to be your bank asking for your CVV. Legitimate banks generally don't need your CVV to verify your identity over the phone; if in doubt, hang up and call your bank directly using the number on the back of your card.
A merchant asking for your CVV for a subscription renewal. If they charged your card successfully before without asking, a sudden CVV request could indicate the original transaction wasn't compliant, or the request itself is a phishing attempt.
Any site storing your CVV "for convenience." This shouldn't happen under standard card network and PCI rules, so treat it as a signal to use a different, more compliant checkout.
For businesses accepting card payments
If you're building or evaluating a checkout flow, requiring CVV entry for online and phone transactions is one of the simplest, lowest-friction fraud prevention tools available, and most payment gateways support it by default. For a broader look at what's involved in accepting cards correctly, see our guide on how to accept credit card payments.
Final thoughts
The CVV is a small code doing a specific job: proving the person making an online or phone purchase actually holds the card, not just its number. Understanding what it's for, and knowing that no legitimate business should ever be storing it, is a simple but genuinely useful piece of card security literacy for both shoppers and merchants.
If your business is evaluating processors on how well they handle card security and compliance, it's worth comparing providers side by side on their fraud prevention tools, not just their headline processing rate.
More from the blog

How long do international payments take? What to know about international electronic funds transfers
Here’s how long international payments take, including how international electronic funds transfers work and why they might be delayed.

BIC and SWIFT codes: Definitions, differences and their structure
Learn more about BIC and SWIFT codes in global payments, from what the acronyms stand for to the differences between them, as well as how both codes are structured.

How to accept credit card payments from customers ?
Here's what small businesses need to know about accepting credit card payments online, in person and over the phone.