7
MIN READ

What is the CVV (also CVC or CSC), how does it work, and what does it mean for your business's payments?

Zru Team

Isabel Martín

Business Development

Updated

Published

CVV code of 3 digits on the back of a credit card
Table of contents

The CVV is a 3 or 4-digit security code linked to a credit or debit card.

CVV stands for Card Verification Value, and we can also refer to that code as CVC (Card Verification Code) or CSC (Card Security Code).

These three terms mean the same thing and are used interchangeably (some card brands use one or another).

The purpose of the CVV is fraud prevention, and in this article we explain how it works, what it involves, and how to handle it when you run a business with online payments.

What is the CVV and where does it come from?

The CVV is usually found on the back of cards, although on some cards, like American Express, it appears on the front.

The CVV is generated by the card's issuing bank when the card is manufactured, using an algorithm that combines the card number (PAN), the expiration date, and a cryptographic key the issuer keeps (CVK, for Card Verification Key).

The CVV can have 3 digits, as on most Visa and Mastercard cards, or 4 digits, as on American Express cards.

What are the differences between CVV, CVV1, and CVV2?

As we've seen, the CVV is the code printed on the card that merchants ask buyers for when they make an online purchase. In some more technical contexts, it's referred to as CVV2, to distinguish it from CVV1, a code that the cardholder "doesn't see."

The CVV1 is stored on the card's magnetic stripe. When someone pays at a physical store and swipes their card through a POS terminal, the terminal reads that code automatically and sends it to the issuer to verify that the card is valid.

How does the CVV work within the online card authorization flow?

When a customer enters the CVV at an online store's checkout, that code travels alongside the card number and expiration date in the authorization request the merchant sends to its payment processor. The processor passes it on to the payment network (whether Visa, Mastercard, or other networks), which forwards it to the card's issuing bank so it can verify that all the data matches.

The issuer compares the CVV it receives with the one it has on record, and if they match, it returns an approval response. If they don't match, it returns a decline code.

When the merchant uses a platform like Zru, it's Zru's gateway that captures the card data, including the CVV, and transmits it securely to the payment processor. This way the merchant doesn't have to worry about collecting highly sensitive data like the CVV.

The CVV isn't the only thing the issuer validates at that moment. It also checks that the card is active, that it hasn't been reported as stolen, that there are sufficient funds, and that the transaction doesn't trigger its own fraud filters.

Why you can't store the CVV and what happens if you do

The PCI DSS standard (Payment Card Industry Data Security Standard) prohibits storing the CVV once the payment authorization is complete. This means that no one, neither merchants nor payment gateways, can store the CVV, and it applies without exception: not encrypted, not masked, not on paper. If the data exists in your systems after the payment has been processed, you're in breach of PCI DSS.

This prohibition makes sense, since the CVV is no longer needed once the transaction has been authorized. On top of that, if the merchant stores it and its systems suffer a security breach, this data could be used to make fraudulent purchases.

This means that in the case of recurring payments and subscriptions, the CVV cannot be used for charges after the first one. For that type of transaction, the correct mechanism is tokenization: the payment processor generates a token that represents the card, so the business can carry out the subsequent charges.

For this type of transaction, platforms like Zru handle tokenization so that the merchant never has access to the CVV or other sensitive card data, allowing it to run subscriptions and recurring payments in compliance with PCI DSS.

Dynamic CVV: what is it and what changes for your business?

The dynamic CVV, also known as dCVV2 on Visa and dCVC2 on Mastercard, replaces the static code printed on cards with a code that changes periodically. The cardholder can check it through their banking app each time they need to make an online purchase.

This makes it much more secure, because if the card is stolen, the thieves don't have access to the CVV code printed on it. What's more, since the code has a limited lifespan, once it expires it's no longer useful for anything.

For merchants, the process is exactly the same: the dynamic CVV is captured and validated in the same way as a static CVV. It requires no technical adaptation on the business's part.

How can Zru help you manage the CVV in payments?

Zru is a payments infrastructure that lets merchants manage their payments securely and without having to worry about handling the CVV.

When a customer pays on a website that uses Zru, it's Zru's checkout that captures the card data, including the CVV, and transmits it securely to the processor. The merchant never stores any kind of information about the cards.

For recurring payments and subscriptions, Zru tokenizes the card from the first charge. That way, future charges can be carried out without asking the customer for their data again and without the CVV needing to be present in subsequent charges.

Zru lets merchants use more than 200 payment methods and processors, to adapt to the needs of each market where they operate.

In addition, if a payment fails, Zru lets you define fallback routes within the orchestration itself to retry the charge through another processor and avoid losing the sale. All of this is done from the dashboard and without needing to touch code.

If you have questions about how to manage the CVV or your business's payments, our team can help you find the best solution.

7
MIN READ

What is the CVV (also CVC or CSC), how does it work, and what does it mean for your business's payments?

Zru Team

Isabel Martín

Business Development

Updated

Published

CVV code of 3 digits on the back of a credit card
Table of contents

The CVV is a 3 or 4-digit security code linked to a credit or debit card.

CVV stands for Card Verification Value, and we can also refer to that code as CVC (Card Verification Code) or CSC (Card Security Code).

These three terms mean the same thing and are used interchangeably (some card brands use one or another).

The purpose of the CVV is fraud prevention, and in this article we explain how it works, what it involves, and how to handle it when you run a business with online payments.

What is the CVV and where does it come from?

The CVV is usually found on the back of cards, although on some cards, like American Express, it appears on the front.

The CVV is generated by the card's issuing bank when the card is manufactured, using an algorithm that combines the card number (PAN), the expiration date, and a cryptographic key the issuer keeps (CVK, for Card Verification Key).

The CVV can have 3 digits, as on most Visa and Mastercard cards, or 4 digits, as on American Express cards.

What are the differences between CVV, CVV1, and CVV2?

As we've seen, the CVV is the code printed on the card that merchants ask buyers for when they make an online purchase. In some more technical contexts, it's referred to as CVV2, to distinguish it from CVV1, a code that the cardholder "doesn't see."

The CVV1 is stored on the card's magnetic stripe. When someone pays at a physical store and swipes their card through a POS terminal, the terminal reads that code automatically and sends it to the issuer to verify that the card is valid.

How does the CVV work within the online card authorization flow?

When a customer enters the CVV at an online store's checkout, that code travels alongside the card number and expiration date in the authorization request the merchant sends to its payment processor. The processor passes it on to the payment network (whether Visa, Mastercard, or other networks), which forwards it to the card's issuing bank so it can verify that all the data matches.

The issuer compares the CVV it receives with the one it has on record, and if they match, it returns an approval response. If they don't match, it returns a decline code.

When the merchant uses a platform like Zru, it's Zru's gateway that captures the card data, including the CVV, and transmits it securely to the payment processor. This way the merchant doesn't have to worry about collecting highly sensitive data like the CVV.

The CVV isn't the only thing the issuer validates at that moment. It also checks that the card is active, that it hasn't been reported as stolen, that there are sufficient funds, and that the transaction doesn't trigger its own fraud filters.

Why you can't store the CVV and what happens if you do

The PCI DSS standard (Payment Card Industry Data Security Standard) prohibits storing the CVV once the payment authorization is complete. This means that no one, neither merchants nor payment gateways, can store the CVV, and it applies without exception: not encrypted, not masked, not on paper. If the data exists in your systems after the payment has been processed, you're in breach of PCI DSS.

This prohibition makes sense, since the CVV is no longer needed once the transaction has been authorized. On top of that, if the merchant stores it and its systems suffer a security breach, this data could be used to make fraudulent purchases.

This means that in the case of recurring payments and subscriptions, the CVV cannot be used for charges after the first one. For that type of transaction, the correct mechanism is tokenization: the payment processor generates a token that represents the card, so the business can carry out the subsequent charges.

For this type of transaction, platforms like Zru handle tokenization so that the merchant never has access to the CVV or other sensitive card data, allowing it to run subscriptions and recurring payments in compliance with PCI DSS.

Dynamic CVV: what is it and what changes for your business?

The dynamic CVV, also known as dCVV2 on Visa and dCVC2 on Mastercard, replaces the static code printed on cards with a code that changes periodically. The cardholder can check it through their banking app each time they need to make an online purchase.

This makes it much more secure, because if the card is stolen, the thieves don't have access to the CVV code printed on it. What's more, since the code has a limited lifespan, once it expires it's no longer useful for anything.

For merchants, the process is exactly the same: the dynamic CVV is captured and validated in the same way as a static CVV. It requires no technical adaptation on the business's part.

How can Zru help you manage the CVV in payments?

Zru is a payments infrastructure that lets merchants manage their payments securely and without having to worry about handling the CVV.

When a customer pays on a website that uses Zru, it's Zru's checkout that captures the card data, including the CVV, and transmits it securely to the processor. The merchant never stores any kind of information about the cards.

For recurring payments and subscriptions, Zru tokenizes the card from the first charge. That way, future charges can be carried out without asking the customer for their data again and without the CVV needing to be present in subsequent charges.

Zru lets merchants use more than 200 payment methods and processors, to adapt to the needs of each market where they operate.

In addition, if a payment fails, Zru lets you define fallback routes within the orchestration itself to retry the charge through another processor and avoid losing the sale. All of this is done from the dashboard and without needing to touch code.

If you have questions about how to manage the CVV or your business's payments, our team can help you find the best solution.

Subscribe to our newsletter

START NOW

Talk to a payments expert

Tell us about your situation and we'll show you in 30 minutes how Zru can improve your operations.

No commitments or long-term contracts

One integration, access to the entire ecosystem

Dedicated support from day one

Call us now

We’re available Monday to Friday.