The CVN on a credit or debit card is the three- or four-digit security code printed on the card that a merchant asks for during online, phone, and mail-order purchases. It proves you physically have the card, not just the number. Different networks use different names for it — CVV2 at Visa, CVC2 at Mastercard, CID at American Express — but the code does the same job everywhere.
Where to Find the Code on Your Card
Location depends on the network:
- Visa: three digits on the back, in or next to the signature panel. Visa calls it a Card Verification Value (CVV2).
- Mastercard: three digits on the back, in the same spot as Visa. Mastercard calls it a Card Validation Code (CVC2).
- Discover: three digits on the back, usually at the end of the account number near the signature strip.1Discover. What Is a CVV Number on a Credit Card
- American Express: four digits on the front, printed above or near the account number. Amex calls it a Card Identification Number (CID) and hot-stamps it onto the card face.2American Express. Guide to Checking Card Faces
If you have a Visa, Mastercard, or Discover card and can’t spot the code, flip it over and look to the right of the signature panel for a standalone group of three digits.
What the CVN Actually Does
The CVN exists to fight card-not-present fraud, meaning any transaction where the merchant can’t physically inspect your card. Online purchases, phone orders, and mail orders all count.3Federal Reserve Bank of Kansas City. Card-Not-Present Fraud Rates in the United States After the Migration to Chip Cards
A thief who scrapes only your card number and expiration date from a data breach usually can’t complete an online purchase, because there’s no CVN in the stolen file. The code on the printed card is generated separately from the value encoded on the magnetic stripe, so a skimmer at a gas pump or ATM doesn’t capture it either. The three or four digits are, in effect, a second factor that only someone holding the card should know.
Why No Merchant Keeps Your CVN on File
The Payment Card Industry Data Security Standard (PCI DSS) classifies the CVN as “sensitive authentication data.” Under Requirement 3.2, merchants must not store it after a transaction is authorized, and must render it unrecoverable once authorization is complete. Even encrypted storage is prohibited. Only card issuers may retain the value.4PCI Security Standards Council. FAQ – Can Card Verification Codes/Values Be Stored for Card-on-File or Recurring Transactions
You’ve probably noticed the consequence. A subscription service or online store asks for your CVN the first time you sign up but not on the monthly charges that follow. The merchant swaps your card details for a token, a randomly generated stand-in, and uses that for future billing. The CVN itself is gone from their system the moment your first payment clears.
How to Protect the Code
Most CVN compromises are not sophisticated. They come from handing the number to the wrong person or typing it on the wrong site. A few habits close off the common paths:
- Never share the code on an incoming call, email, or text. Your bank will not ask you for it. Any unsolicited request is a scam.
- Before you type it in, check for a padlock and “https://” in the address bar. The absence of it guarantees an unencrypted connection.
- Don’t read the code aloud in public. Phone orders in coffee shops and airports hand it to anyone in earshot.
- Don’t photograph the back of your card. If you’ve memorized the digits, some security guides suggest covering them on the physical card with a small opaque sticker so a glance or quick photo can’t pick them up.
Virtual Card Numbers
Many issuers now offer virtual card numbers: a temporary card number, expiration date, and CVN generated for a single merchant or single purchase. Your real card details stay locked in a digital vault, and the retailer only sees the disposable token. If that retailer is breached, the stolen number is useless because it can be deleted or has already expired. Some virtual cards also let you set spending limits and custom expiration dates.5Chase. How Virtual Credit Card Numbers Protect Information
Dynamic CVN
A newer option is a dynamic CVN, where the code changes automatically every 12 to 24 hours. Some physical cards carry a small electronic display on the back powered by a thin embedded battery; a more common version generates the fresh code inside your banking app for you to type at checkout.6National Cyber Security Centre. Insight – The Codes They’re A-Changin’ Stolen digits go stale within hours. Adoption among U.S. issuers is still limited.
If Your Card or CVN Is Compromised
Speed matters when you notice something wrong, and it matters more for debit cards than credit cards because the liability rules are different.
On a credit card, the Truth in Lending Act caps your liability for unauthorized charges at $50, and only for charges made before you report the card. After you notify the issuer, you owe nothing.7Office of the Law Revision Counsel. 15 U.S.C. 1643 – Liability of Holder of Credit Card In practice, most major issuers waive the $50 through zero-liability policies.
Debit cards work on a sliding scale under the Electronic Fund Transfer Act:8Office of the Law Revision Counsel. 15 U.S.C. 1693g – Consumer Liability
- Report within two business days of learning about the theft, and your liability is capped at $50 (or the amount taken, if less).
- Report after two business days but within 60 days of the statement showing the transfer, and you can be liable for up to $500.
- Miss the 60-day window entirely, and unauthorized transfers made after that window closes carry unlimited liability.
The 60-day clock starts when your bank sends the statement showing the unauthorized transaction, not when you open it.9Consumer Financial Protection Bureau. Regulation E Official Interpretations – Section 1005.6 That’s a strong reason to read debit statements as they arrive.
If you suspect a compromise, do four things:
- Call the number on the back of your card, or use your bank’s app, to block the card and request a replacement.10Office of the Comptroller of the Currency. Credit Card and Debit Card Fraud
- Dispute the unauthorized charges. Your issuer is required to investigate; credit card charges are typically reversed while it does. On a debit card the money may already be gone from your account, which is why fast reporting limits the damage.
- Turn on real-time transaction alerts if you haven’t already.
- Scan recent statements for small unfamiliar charges. Fraudsters often test a stolen card with a tiny purchase before running a large one.
Your replacement card will carry a new CVN, so any subscription or saved payment method tied to the old one has to be updated before the next bill.