Technical fundamentals

What a Card's CVV or CVC Is and What It Is For

Published:  ·  7 min read

The CVV (Card Verification Value) is a 3- or 4-digit security code printed on the card that serves to confirm that the person paying physically has the card in their hands.

Key points

  • The CVV (or CVC) is the 3-digit security code on the back; on American Express it is 4 digits on the front and is called the CID.
  • It has several names depending on the network: CVV2, CVC2, CID, CW2. They all designate the same printed code.
  • CVV1 is encoded on the magnetic stripe and CVV2 is the printed one you type when shopping online.
  • In testing, the CVV is only a simulated value: it must never be stored or written to logs.
  • Complying with PCI DSS requires that the CVV not be stored after the transaction is authorised.

On Visa and Mastercard cards they are 3 digits and go on the back; on American Express they are 4 digits and go on the front. It is not part of the card number and it is not stored on the visible magnetic stripe.

Its function is to add a layer of verification to card-not-present purchases (over the internet or by phone). If someone steals only the card number, without the CVV they cannot complete most online payments.

For a developer or QA, the CVV matters for another reason: it is one more field in the payment form that must be validated, protected and never stored. In this guide you will see exactly what it is, how it differs from CVV1, how to handle it in your tests and what best practices to follow.

What the CVV is and where the name comes from

CVV stands for Card Verification Value, a value that the issuer calculates cryptographically from the card's data. The idea is simple: only the issuing bank knows the secret key that generates that code, so a merchant can check it against the issuer to confirm that the card is genuine.

Each network gave its own commercial name to the same concept:

NetworkCode nameDigitsLocation
VisaCVV23Back, next to the signature
MastercardCVC23Back, next to the signature
American ExpressCID4Front, above the number
DiscoverCID3Back
OthersCVV, CW23Back

That is why, when a form asks you for "CVV", "CVC", "CVC2" or "CID", it is really asking for the same thing: the printed verification code. The only practical difference is the length and the position on the card.

CVV1 vs CVV2: two different codes

Here is the most common confusion. There are in fact two verification values:

  • CVV1 (or iCVV): it is encoded on the magnetic stripe and in the chip. It is read automatically when you swipe the card at a card reader. You do not see it and you do not type it.
  • CVV2 (or iCVV in the chip): it is the printed code you type in online purchases. It is the one people know as "the CVV".

When a website asks you for the security code, it always means the CVV2. The CVV1 is invisible to the user and only circulates in card-present transactions.

Where the CVV is on the card

The location depends on the network:

  • Visa and Mastercard: on the back, in the signature panel. It is normally a group of 3 digits that appears after the last four printed digits of the card number.
  • American Express: on the front, above and to the right of the card number. They are 4 digits.
  • Discover: on the back, also in the signature panel.

A security tip worth repeating: never share a photo of the front and back of your card. With the number, the date and the CVV, anyone can try to pay online.

What the CVV is for

The CVV serves three main purposes:

  1. It verifies physical possession of the card. It proves that the person paying has the card in front of them, not just its number.
  2. It reduces fraud in card-not-present (CNP) payments. It is an extra barrier against numbers stolen from databases.
  3. It shifts liability to the issuer. When a merchant requests and validates the CVV correctly, in many cases liability for fraud falls on the issuing bank, not the merchant.

The CVV does not replace 3D Secure or other strong authentication. It is one more layer, not the only one.

How to handle the CVV in software testing

When you develop or test a payment gateway, the CVV is one more field, but with special rules. Here is what you need to keep in mind:

  • Never store the CVV. Not in a database, not in logs, not in a ticketing system. The PCI DSS standard prohibits storing it after the transaction is authorised.
  • Do not include it in logs. If your application logs requests, make sure to mask the CVV as you do with the card number.
  • Validate the format, not the value. In testing you can only check that it has 3 digits (4 for Amex) and that they are numeric. The real value is validated by the issuer.
  • Use simulated data. For testing, any 3-digit CVV (or 4 for Amex) works with the gateways' test cards.

A useful fact: in the Stripe sandbox, any 3-digit CVC (4 for American Express) is valid, as is any future expiration date. You only need to use a test API key. You can combine this with our credit card generator, which already includes a CVV and a date on every simulated card.

A real security case

At an e-commerce startup, a developer added a debugging function that dumped the full payment request into a log file to investigate an error. The log included the CVV and the card number in plain text. Months later, a PCI DSS audit found the file and the company had to redo its logging policy, purge the data and reinforce team training. The lesson: the CVV must never reach a log, not even "temporarily for debugging".

Best practices for protecting the CVV

If your application handles payments, these practices should be mandatory:

  • Do not store the CVV. If you need it, validate it at the moment and discard it.
  • Do not record it in logs or error traces. Always mask sensitive fields.
  • Use tokenization. Let the gateway handle the card data and store only a token.
  • Comply with PCI DSS. If you process, store or transmit card data, you are within the scope of the standard. The less data you touch, the simpler compliance is.
  • Limit internal access. Only the systems and people who really need it should see payment data.
  • Encrypt in transit. Every payment form must go over HTTPS.

The fewer sensitive data your system touches, the easier it will be to protect them and to demonstrate compliance. In practice, the best strategy is to never store the CVV.

The CVV and test cards

When you test an integration, you do not need real cards. Gateways offer test cards with official numbers, and our generator creates Luhn-valid numbers with a CVV and a date included. That way you can simulate the full payment flow without exposing any real data. If you want to choose a specific network, start with the credit card selection page or review the Stripe and PayPal test cards.

Do you need to test your payment form right now? Generate cards with a CVV and a date in seconds with the credit card generator and validate the result in the card validator.

Conclusion

The CVV or CVC is the 3- or 4-digit code that confirms you have the card in your hand. Its name changes depending on the network (CVC2, CVV2, CID), but it always serves the same purpose: adding a layer of verification to card-not-present payments.

For anyone developing or testing payment software, the golden rule is simple: validate it, but never store it. Treat it as an ephemeral piece of data, mask it in logs and always use simulated data in your tests.

With a generator to create test cards and a validator to check them, you will be able to test any payment form without touching a single real card.

Responsible use notice: the numbers and CVVs generated on this site are fictitious. They do not correspond to real cards, cannot be used to make purchases and must be used only for software testing. Using them for fraud is illegal.

Sources and further reading

Frequently Asked Questions

Is the CVV the same as the CVC?

Yes. CVC, CVV, CVC2, CVV2 and CID designate the same printed verification code; only the name changes depending on the network.

Why does American Express have 4 digits and the others 3?

It is a decision made by each network. American Express prints the 4-digit CID on the front, while Visa and Mastercard use 3 digits on the back.

Can the CVV be calculated from the card number?

Not in practice. The CVV is generated with a secret key held by the issuer that is not public. Any CVV you see in a generator is a simulated value, valid only for testing.

Is storing the CVV allowed?

No. The PCI DSS standard prohibits storing the CVV after the transaction is authorised, even encrypted.

CVVCVCsecurityPCI DSS

⚡

Ready to generate your test numbers?

Use the free generator and get Luhn-valid cards with CVV and expiry in seconds.

Open the generator