A card verification value is the short security code printed on your credit or debit card that proves you have the card in hand when you can’t swipe, tap, or insert it. Visa, Mastercard, and Discover print a three-digit code on the back, usually to the right of the signature strip. American Express prints a four-digit code on the front, above the account number. You’ll be asked for it whenever you buy something online or over the phone.
Where to Find It on Your Card
On a Visa, Mastercard, or Discover card, look at the back. The code is three digits, printed to the right of the signature panel. You may also see the last four digits of your account number in that same area, with the security code just after it.
On an American Express card, look at the front. The code is four digits, printed above and slightly to the right of your full account number.
On every card, the code is flat-printed rather than embossed. That’s deliberate. Flat ink can’t be picked up by a carbon-copy imprint or a rubbing of the card’s surface, so the number stays with the card itself.
Different Names for the Same Number
Each network has its own name for the code, which is why a checkout page might ask for something that doesn’t say “CVV.” They all mean the same thing:
- Visa: card verification value (CVV)
- Mastercard: card validation code (CVC)
- American Express: card identification number (CID)
- Discover: card verification data (CVD)
If a site asks for a “CVV,” “CVC,” “CID,” “CVD,” “CSC,” or just a “security code,” type the digits printed on your card.
What the Code Does at Checkout
When you enter your card number, expiration date, and security code on a website, the merchant passes all three to your card-issuing bank through a payment processor. The bank checks the code you typed against the value it has on file for your card. If they match, the transaction moves forward. If they don’t, the bank declines it, no matter how much credit or cash is available on the account.
The reason this small check matters: the code isn’t stored on the magnetic stripe or embedded in the chip. Someone who steals your card number from a data breach or a skimmed stripe still doesn’t have the printed code. Card-not-present fraud accounts for roughly 74 percent of all card payment fraud, and the security code is one of the main defenses against it.
Why Subscriptions Don’t Ask You for It Every Month
You’ve probably noticed that streaming services and other recurring charges hit your card each month without asking you to re-enter the security code. That’s because merchants aren’t allowed to keep it. The Payment Card Industry Data Security Standard prohibits storing the printed security code after a transaction is authorized, in any form, encrypted or not, in any database, log, or cache.
So how do repeat charges work? Through tokenization. When you first save your card with a merchant, the payment system replaces your actual card number with a random string called a token. The token is stored in place of your card data and used to charge future payments. Your real number and security code never sit in the merchant’s system. If the merchant is later breached, the stolen tokens can’t be reversed into working card numbers.
The practical effect for you: on a new one-time purchase, you’ll almost always be asked to type the security code again, even if the site already has your card number saved. That’s not the site being paranoid. It’s the rule.
Dynamic and Virtual Security Codes
The printed code has one weakness: it never changes. Anyone who sees or photographs the back of your card has a working code for as long as that card is valid.
Some banks now offer a dynamic code through their mobile app. You open the app and get a temporary security code that replaces the printed one for online purchases. The code refreshes on a schedule, so a copied code stops working within minutes or hours.
Virtual card numbers go further. Many issuers let you generate an entirely separate card number, with its own security code and expiration date, for a single merchant or a single purchase. You can set the virtual card to lock after one use. If that merchant is breached later, the exposed number is useless anywhere else, and your real card number was never handed out in the first place. Check your issuer’s app or website to see whether either option is available on your account.
What You Owe if Your Security Code Is Stolen
Federal law caps your liability for unauthorized charges, but the ceiling depends on whether the compromised card was a credit card or a debit card. The gap between the two is large.
Credit Cards
Your maximum liability for unauthorized credit card charges is $50, and only for charges made before you notify the issuer. After you report the problem, you owe nothing for anything charged from that point forward. Most major issuers waive the $50 as a matter of policy and advertise zero-liability protection, but $50 is the legal ceiling either way.
Debit Cards
Debit card protection is tiered by how quickly you report:
- Report within two business days of learning your card was compromised: your maximum liability is $50.
- Report after two business days but within 60 days of the statement that shows the unauthorized charges: your maximum liability rises to $500.
- Report more than 60 days after that statement is sent: unlimited liability for unauthorized transfers that occur after the 60-day window. Your bank is not required to reimburse those later charges at all.
The gap matters. A stolen credit card security code is capped at $50 no matter what. A stolen debit card security code can drain the account if you don’t catch it fast. Reviewing your statements and reporting anything unfamiliar within two business days keeps you at the strongest tier of protection the law provides.