What Does a CVV Test Check?
A CVV test checks the card security code against the issuer's verification logic during an authorization request. The gateway passes the code with the transaction, the issuer compares it to the value on file, and a response comes back as match, no match, not processed, or not applicable.
Developers run CVV tests in a sandbox with fake card numbers. Anyone running authorization requests against real card numbers they do not own is operating a card-checking service, and US law treats that as access device fraud under 18 U.S.C. § 1029.
The latest CVV test results in a dashboard are just the response codes from your last batch of authorization attempts. They describe your integration, not the card behind the number.
CVV, CVV2, CVC, CID: What Each Code Means
- CVV1 sits in the magnetic stripe and is read on a swipe. It never appears in print.
- CVV2 (Visa) is the 3-digit code on the back of the card, near the signature panel.
- CVC2 (Mastercard) works the same way, and CID on American Express runs to 4 digits on the front.
- The value is generated by the issuer from the card number, the expiration date, and a secret key. Copying a card number does not reveal it.
That design is the point. A verification code shows the buyer holds the physical card, which is why merchants ask for it on card-not-present orders.
How Legitimate CVV Testing Works
- Get sandbox API keys from your payment processor.
- Pull the processor's test card table. Stripe, Adyen, Braintree, and Worldpay publish numbers that force a specific CVV outcome.
- Run a charge with a number that returns a CVV mismatch and confirm your app shows a clear error.
- Run a charge with a matching code and confirm the payment completes.
- Log the response code, never the code value. Storing the CVV after authorization breaks PCI DSS.
- Repeat the set for every brand you accept, including Amex and debit networks.
What the Response Codes Mean
- M (Match): the code lines up with the issuer record.
- N (No match): the code is wrong. Most processors decline the transaction.
- P (Not processed): the issuer skipped the check. Common with some debit and prepaid issuers.
- U (Not applicable): the card carries no verification code, or the network does not support the check.
A "not processed" result is not a pass. The check did not run, so the fraud risk stays with the merchant.
Why Testing Live Card Numbers Is Fraud
Card checking fires small authorization requests at large batches of stolen numbers to see which ones still work. Issuers and card networks watch for that pattern, and the fallout is fast: closed accounts, chargebacks, and referrals to law enforcement.
In the US, 18 U.S.C. § 1029 covers the use and trafficking of access devices, with penalties that reach 10 years for a first offense and 20 for a repeat. State statutes add their own charges.
A merchant that runs card checks through its own gateway loses the account. Processors close the business and report it to network fraud databases, which makes a replacement merchant account hard to obtain.
PCI DSS Rules That Shape CVV Testing
PCI DSS classifies the CVV as sensitive authentication data. The standard forbids storing it after authorization, even in encrypted form. If your test logs capture a CVV, you are out of compliance.
Sound practice: mask the field at entry, pass the value to the processor, drop it from memory, and keep only the result. Your test suite should assert that no CVV value shows up in logs, database rows, or error traces.
Checklist Before You Go Live
- Sandbox tests cover match, no match, not processed, and cards with no code.
- Declines show a message the customer can act on.
- Application logs and error trackers hold no CVV values.
- Refund, void, and subscription flows never ask for the code again.
- Fraud rules handle the "not processed" case.
- Test card numbers are stripped from production configuration.
FAQ
Is it legal to test a CVV?
Yes, when you test your own card in a sandbox or with written permission from the cardholder. Testing card numbers that belong to other people without permission is illegal in the US and most other countries.
Do test CVVs work in production?
No. Sandbox numbers are issued by processors for development. They return simulated results and live networks reject them.
What does "CVV not processed" mean?
The issuer skipped the check. The charge may still approve, but you carry the risk if the buyer used a stolen card.
Where do I find test card numbers?
Your processor's developer documentation. Stripe, Adyen, Braintree, and Worldpay all publish tables that map a test number to a known response.
Does a CVV test prove a card is valid?
No. A match means the code aligns with the issuer record. It does not prove the buyer owns the card or that the account holds funds.
What should I do with a card that fails a CVV check?
Decline the order, ask the buyer for another payment method, and flag the attempt in your fraud tooling. Do not retry the same number in a loop.