What is CVV test localization?

CVV test localization is the practice of checking that a payment form's card security code field works the way shoppers in each target market expect. It covers label wording, digit count, input direction, keyboard layout, and error text. A form that passes in the US can fail in Germany or Saudi Arabia for reasons that have nothing to do with the payment gateway.

The card security code carries at least six names. Visa calls it CVV2, Mastercard uses CVC2, American Express uses CID, and UnionPay uses CVN2. Your form has to match both the card brands you accept and the language of the person typing.

What changes from one locale to the next?

  • Digit count. Visa, Mastercard, Discover, and UnionPay use three digits. American Express uses four. A hard rule of "3 digits only" blocks every Amex cardholder at checkout.
  • Label text. German shoppers look for "Kartenprüfnummer", French shoppers for "cryptogramme visuel", Spanish speakers for "código de seguridad".
  • Card side. Three-digit codes sit on the back of the card. Amex prints its four-digit code on the front, so the help graphic has to change with the brand.
  • Reading direction. Arabic and Hebrew forms run right to left. The code inside the input stays left to right.
  • Keyboard. Mobile forms need a numeric keypad and autofill that fills the field with one tap.
  • Error messages. "CVC invalid" needs a translated version that fits the space and reads like a real sentence.

How do you build a CVV test matrix?

Start with the locales you sell into and combine them with the card brands you accept. That product is your matrix. A shop that ships to 12 countries and takes Amex has about 24 core cases before you add right-to-left layouts.

  1. List each locale with its language, script, and direction.
  2. List each card brand with its code name and digit count.
  3. Pick one test card per brand from your processor's sandbox.
  4. Test the happy path, then a wrong length, then a letter typed into the field.
  5. Check the translated error message for overflow and clipping.
  6. Repeat on a mobile viewport with the on-screen keyboard open.

Why do German and Finnish locales break layouts?

German compounds run long. "Kartenprüfnummer" needs 17 characters where "CVV" needs three. If the label sits in a fixed-width column, the word wraps, the field drops below the fold, or the text clips. Finnish and Hungarian labels cause the same damage.

How should numeric input behave in right-to-left forms?

Set the input to dir="ltr" even when the surrounding form is RTL. Reversed digits confuse shoppers and break copy-paste. The label and help text stay RTL, the digits do not.

Which label should you use per language?

  • English (US): "Security code" or "CVV"
  • German: "Kartenprüfnummer"
  • French: "Cryptogramme visuel"
  • Spanish: "Código de seguridad"
  • Italian: "Codice di sicurezza"
  • Portuguese (BR): "Código de segurança"
  • Japanese: セキュリティコード
  • Chinese: 安全码
  • Arabic: رمز التحقق

Some teams shorten the visible label and move the full name into help text. That keeps field width stable across languages. Pick one pattern and apply it across the whole checkout.

What breaks in real payment forms?

  • A maxlength of 3 that rejects Amex.
  • Placeholder text that never went through translation.
  • A help tooltip that shows the back of the card for every brand.
  • An input mask that blocks paste, so shoppers cannot copy a code from their banking app.
  • A missing autocomplete="cc-csc" attribute, which kills mobile autofill.
  • Validation that trims plain spaces but not non-breaking spaces from translated strings.
  • Error text that returns in the source language after a failed submit.

How do you test CVV fields without real card data?

Use test card numbers from your payment processor. They pass the Luhn check and route to a sandbox that never charges anyone. Build a card for each brand so the four-digit Amex path gets covered on every run.

Confirm that your logging pipeline drops the field before it hits storage. PCI DSS treats the security code as sensitive authentication data, and keeping it after authorization is a compliance finding, not a bug report.

Frequently asked questions

Is CVV the same as CVC?

They mean the same thing. CVV is Visa's term, CVC is Mastercard's. The digits serve one purpose: show that the card is in the shopper's hand.

How many digits does a CVV have?

Three for Visa, Mastercard, Discover, and UnionPay. Four for American Express, printed on the front of the card.

Does CVV localization change conversion?

It can. A form that asks for a "CVV" in a market where shoppers know the term as "Kartenprüfnummer" adds friction on the last step of checkout. Correct labels and correct digit rules remove that friction.

Do I need to store the CVV to validate it?

No. Send it to the processor with the authorization request and keep nothing. Storing it creates a liability with no upside.

What should a finished localization pass include?

Sign off on four things: label text per language, digit rules per brand, input direction, and translated error copy. Add screenshots at mobile and desktop widths so the next developer sees the target. When a new locale goes live, add its row to the matrix before launch, not after the first support ticket.