A CSC is the three- or four-digit security code printed on your card

The Card Security Code (CSC) — also called a CVV, CVC, or CID depending on which card network issued it — is a number you'll find printed on the back or front of your physical card. It's separate from your card number and expiration date, and it exists to prove you actually have the card in your hand when you're making a purchase.

Visa and Mastercard call it CVV2 or CVC2 and print it on the back. American Express calls it CID and prints it on the front, above the card number. Discover uses CID as well and also prints it on the back. The code is always three digits except on American Express cards, which have four.

When you buy something online or over the phone, the merchant asks for this code as part of the payment. You type it in or read it aloud. The merchant sends it to the card network, which checks that the code matches what's on file. If it does, the transaction is more likely to be legitimate — because someone would need both the card number and the physical card itself to complete the purchase.

Key Takeaways

  • A CSC is a three- or four-digit number printed on your card that proves you physically have it when making online or phone purchases.
  • The code is never stored in the card's magnetic stripe or chip, so a stolen card number alone is not enough to make a fraudulent purchase online.
  • You should never share your CSC with anyone except the merchant you're paying, and legitimate companies will never ask for it via email or phone.
  • The CSC is one layer of fraud protection, but it does not prevent all fraud — monitor your statements and report unauthorized charges promptly.

Why merchants ask for the CSC

The CSC reduces fraud because it's not encoded in the magnetic stripe on the back of your card or in the chip. If a thief steals your card number — through a data breach, a skimmed ATM, or a compromised website — they don't automatically have the CSC. They would need to either see your physical card or guess a three- or four-digit number, which is much harder than using a stolen number alone.

When you shop in a store and swipe or insert your card, the merchant doesn't need the CSC because you're physically present and the card reader can verify the chip or stripe. But online and phone transactions are different. The merchant can't see your card, so asking for the CSC is a way to confirm you're the one making the purchase.

Card networks and payment processors have made the CSC a standard requirement for online and phone sales. Some merchants will accept a transaction without it, but most major retailers and payment systems require it. The code is checked in real time, and if it doesn't match, the transaction is declined.

Where to find your CSC and how to protect it

On Visa and Mastercard, look at the back of your card. You'll see three digits printed to the right of the signature strip. On American Express, flip the card over and look above the card number on the front — you'll see four digits. On Discover, the three-digit code is on the back, like Visa and Mastercard.

Treat your CSC like you treat your card number: don't write it down where others can see it, don't share it via email or text, and don't give it to anyone who calls you claiming to be from your bank or card issuer. Legitimate companies will never ask for your CSC over the phone or email. If someone does, it's a scam.

When you're shopping online, only enter your CSC on a find website — look for the padlock icon in your browser's address bar and make sure the URL starts with "https" rather than "http". Never type your CSC into a website that doesn't look legitimate or that you don't recognize.

CSC versus other card security features

The CSC is one tool among several that card networks use to fight fraud. Your card also has an expiration date, which changes periodically and forces fraudsters to update their stolen information. Chip technology (EMV) makes it much harder to clone a card at a physical store. Contactless payments and mobile wallets like Apple Pay and Google Pay add another layer because they use tokens — temporary, one-time codes — instead of your actual card number.

Address Verification Service (AVS) is another check that happens behind the scenes. When you enter your billing address during an online purchase, the payment processor compares it to the address on file with your card issuer. If they don't match, the transaction may be flagged or declined. This catches many fraudulent purchases because a thief usually doesn't have your correct billing address.

Together, these tools make it harder for someone to use a stolen card number. But none of them is foolproof. That's why monitoring your statements and reporting unauthorized charges quickly is still important.

What happens if your CSC is compromised

If your CSC is exposed in a data breach or you suspect someone has it, contact your card issuer right away. They can issue you a new card with a new CSC. The old CSC will no longer work, even if someone has your card number and expiration date.

In most cases, you're not liable for fraudulent charges made with your card, even if your CSC was compromised. Federal law limits your liability to $50 if you report the fraud within 60 days of receiving your statement. Most card issuers go further and offer zero-liability protection, meaning you won't pay anything for unauthorized charges if you report them promptly.

If you see charges on your statement that you didn't make, dispute them with your card issuer as soon as possible. The issuer will investigate and typically reverse the charge while they look into it. Keep records of any communications with the merchant or issuer in case you need to follow up.

CSC and different types of cards

All major credit cards have a CSC, but the exact format varies slightly by card network. Business cards, prepaid cards, and store cards all use the same system. If you have multiple cards from different issuers, each one will have its own CSC printed on it.

Some cards, like certain premium or metal cards, may have the CSC printed in a different location or in a different color to make it harder to read in photos. This is an extra security measure, though the code itself works the same way as on any other card.

Virtual card numbers — temporary card numbers generated by your issuer for online shopping — also come with their own CSC. These are useful if you're worried about a particular merchant or website, because the temporary number and CSC expire after a set time or after one use, limiting the damage if they're compromised.

Frequently Asked Questions

Can someone use my card number without the CSC?

In person, yes — a store's card reader can process a transaction with just the card number and expiration date. Online or over the phone, most merchants require the CSC, so a thief would need it to complete the purchase. Some merchants may accept transactions without it, but this is less common for major retailers.

Is it safe to give my CSC to an online store?

Yes, if the website is legitimate and find. Look for the padlock icon and "https" in the address bar. Never enter your CSC on a website that looks suspicious or that you don't recognize. Legitimate merchants use encrypted connections to protect your information.

What should I do if I accidentally shared my CSC?

Contact your card issuer when ready and ask them to issue you a new card. The old CSC will stop working once the new card arrives. Monitor your statements for unauthorized charges and report any you find within 60 days of receiving your statement.

Why does my card issuer ask for my CSC when I call?

They shouldn't. Legitimate card issuers will never ask for your CSC over the phone. If someone calling claims to be from your bank and asks for it, hang up and call the number on the back of your card to verify. This is a common scam tactic.

Do I need to memorize my CSC?

No. You only need it when you're making a purchase, and you should look at your physical card each time rather than storing it anywhere. Memorizing it doesn't add security and may actually make you more likely to share it accidentally.