Card-not-present payment guidance
What is a CVV check?
A CVV check compares the card verification code entered for a card-not-present payment with the value the card issuer expects. The result is one signal merchants can use when reviewing a transaction, not proof that a payment is legitimate.
Direct answer
What the check actually does
The card verification value is the three- or four-digit code printed on a payment card. Names differ by payment brand, including CVV2, CVC2, CID, CAV2, and CVN2. It is commonly requested for online, phone, mail-order, and other card-not-present transactions because the merchant cannot inspect the physical card at checkout.
When the merchant submits the code with an authorization request, the issuer can compare it with the value associated with that card. The payment response may report a match, a mismatch, that the check was not processed, or that no result was available. The exact labels and available responses depend on the gateway, processor, issuer, and payment brand.
Transaction flow
How a CVV check fits into authorization
The check is part of a broader decision, not a separate promise of approval or fraud prevention.
1. The customer enters the code
The checkout or staff-assisted payment flow collects the printed verification code for the specific transaction. A merchant should use a payment interface designed to protect card data rather than asking a customer to send the code through ordinary email, chat, or a general contact form.
2. The code is submitted
The payment provider sends the value as part of the authorization request when the provider, merchant account, payment method, and transaction flow support the check.
3. The issuer evaluates it
The issuer compares the submitted value with its records and returns a verification result through the payment chain. The result may appear beside other authorization details in a gateway or processor dashboard.
4. The merchant applies a policy
The business reviews the result together with the authorization outcome and other relevant signals. Rules for holding, declining, reviewing, or fulfilling an order should be documented and tested for the merchant's actual workflow.
Result review
What a match or mismatch means
A match indicates that the submitted code agreed with the issuer's expected value. It can add confidence that the person entering the payment had access to the printed code, but it does not establish identity, delivery, customer intent, or freedom from fraud. A valid code can still be used without the cardholder's permission.
A mismatch deserves attention, but it should not be interpreted without the rest of the response. Provider behavior varies: a payment can have a CVV result and a separate authorization outcome, and some systems let merchants configure how a mismatch is handled. An unavailable or unprocessed result is also different from a confirmed mismatch. Merchants should use the provider's current result-code documentation rather than guessing from a generic label.
Data handling
Collect the code only for the transaction
PCI Security Standards Council guidance identifies card verification codes as sensitive authentication data. Merchants may request the code when it is needed for authorization, but must not retain it after authorization, even when encrypted. Customer permission does not create an exception for storage.
This matters for ecommerce forms, virtual terminals, call recordings, notes, support tickets, logs, and recurring-payment setup. Confirm that each system and workflow prevents the code from being retained. For card-on-file or recurring payments, use the payment provider's supported credential-on-file process rather than saving the CVV for later charges.
Do not send a CVV, full card number, password, bank credential, or secret API key through a Payments Max contact form. Questions about a transaction should use non-sensitive references supplied by the payment provider.
Practical questions
Common CVV check questions
Does a CVV match guarantee that an order is safe?
No. A match confirms only that the submitted code matched the issuer's expected value. Review it with the authorization outcome and the merchant's other relevant order signals.
Does a mismatch always decline the payment?
Not universally. Issuer, processor, gateway, and merchant settings can affect how a mismatch is reported or handled. Check the current provider documentation and the separate authorization result.
Can a merchant save the CVV for a later payment?
No. PCI SSC guidance prohibits retaining the printed card verification code after authorization, including for card-on-file and recurring transactions.
Related guidance
Continue your payment-security research
Next step
Verify the result codes used by your provider
Document how your checkout collects the code, where the response appears, and what each result means before changing order-review rules.
To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.
CONTACT US