CVV fraud rules are the card network and PCI DSS requirements that control how the card verification value is collected, transmitted, validated, and stored. They exist to reduce card-not-present fraud by forcing merchants to prove the buyer physically holds the card. Merchants that skip CVV validation usually absorb the fraud loss themselves through chargebacks.

What Are the Three Types of CVV Codes?

The card verification value exists in three forms, and each is used in a different part of the payment chain.

  • CVV1 is encoded on the magnetic stripe and read when a card is swiped at a terminal.
  • CVV2 is the three-digit code printed on the back of Visa, Mastercard, and Discover cards. American Express prints a four-digit CID on the front.
  • iCVV is embedded in the EMV chip and changes when chip data is copied, which helps detect cloned cards.

Online merchants only ever ask for CVV2 or CID. The other values are generated and verified inside the payment network.

Which Rules Require CVV Validation?

Visa, Mastercard, American Express, and Discover each publish their own validation rules, but the practical effect is the same for merchants.

A card-not-present transaction that includes a CVV2 match generally qualifies for a liability shift, meaning the issuer absorbs certain fraud chargebacks. When the CVV does not match or is not submitted at all, that protection is typically lost. Processors may also decline the authorization outright when the code fails.

What Does PCI DSS Say About Storing CVV Data?

PCI DSS treats CVV1, CVV2, iCVV, and full track data as sensitive authentication data. Requirement 3 prohibits storing any of it after authorization, even in encrypted form. Merchants that keep CVV values in a database, log file, or customer record are out of compliance and face fines or loss of card processing privileges.

What Happens When a CVV Check Fails?

The issuer returns a mismatch response, and the merchant decides whether to retry, request another verification method, or decline the order.

Card networks limit repeated authorization attempts on the same card, so aggressive retrying can trigger monitoring programs or penalty fees. A failed CVV check is a strong fraud signal, and most risk teams review the order before approving it.

How Do CVV Rules Affect Chargeback Liability?

Liability for a fraudulent card-not-present chargeback typically falls on the party that failed to apply the available fraud tools.

If a merchant submitted a CVV2 match, a matching AVS result, and 3-D Secure authentication, the issuer often carries the loss. If the merchant skipped those checks, the chargeback returns to the merchant.

How Can Merchants Stay Compliant?

  1. Validate CVV2 or CID on every card-not-present transaction.
  2. Never store the CVV2 after authorization, and scrub it from logs and receipts.
  3. Use tokenization so real card numbers never reach your systems.
  4. Enable 3-D Secure for higher-risk orders and cross-border sales.
  5. Monitor failed CVV attempts for patterns and block repeated retries.

Frequently Asked Questions

Is asking for a CVV allowed on every order?

Yes. Merchants may request the CVV2 or CID for each card-not-present transaction, provided they do not store it afterward.

Can a merchant require the CVV in person?

No. In-person transactions use CVV1 and iCVV, which the terminal reads automatically, so cashiers should never ask for the printed code.

Does a CVV match guarantee the order is legitimate?

No. Stolen card data can include the printed code, so a match should be combined with AVS, device checks, and velocity rules.