The CVV is a three- or four-digit security code printed on your credit card

The CVV (Card Verification Value) is a short number on your physical card that proves you have the card in your hands. It is not encoded in the magnetic stripe or chip — it is printed only on the surface. When you enter it during an online or phone purchase, the merchant confirms that you actually possess the card, not just the card number.

The CVV exists because a card number alone is not enough to prove ownership. Someone who steals your card number from a data breach or intercepts it online cannot complete most transactions without this additional code. The CVV stays with you; it never appears in your email receipts, billing statements, or the merchant's records after the transaction clears.

Different card networks use slightly different names — Visa and Discover call it CVV2, Mastercard calls it CVC2, and American Express calls it CID — but they all serve the same purpose.

Key Takeaways

  • The CVV is a three- or four-digit code printed on the back of Visa, Mastercard, and Discover cards, or on the front of American Express cards.
  • The CVV proves you physically have the card and is required for most online and phone purchases, but not for in-person transactions where the card is swiped or inserted.
  • You should never share your CVV in an email, text, or phone call unless you initiated the contact with a merchant you trust.
  • Merchants are not allowed to store your CVV after a transaction, so if a company asks you to save it for future purchases, that is a sign of fraud.

Where to find your CVV on your card

The location depends on your card network. On Visa, Mastercard, and Discover cards, the CVV is a three-digit number printed on the back of the card, usually to the right of the signature strip. On American Express cards, the CVV is a four-digit number printed on the front, above the card number on the right side.

If you cannot find the number, check your card issuer's website or call the customer service number on the back of your card. They can confirm the location or read it to you over the phone if you are making a purchase with them directly.

When you need to enter your CVV

You enter your CVV during online purchases, phone orders, and mail orders — any transaction where the merchant cannot physically see or swipe your card. The merchant's payment processor uses it to verify that you have the card in your possession at the time of purchase.

You do not need to provide your CVV when you swipe or insert your card in person at a store, gas station, or restaurant. The card reader communicates directly with your bank through the chip or magnetic stripe, and the CVV is not part of that exchange.

Some merchants also ask for your CVV when you set up automatic recurring payments, such as a gym membership or subscription service. In these cases, the merchant should not store the CVV itself — they store only your card number and expiration date, and the CVV is used only to verify the first transaction.

Why merchants ask for your CVV

The CVV reduces fraud because it is not stored anywhere in the payment system after the transaction completes. If a hacker steals a merchant's database, they get card numbers and expiration dates but not CVVs. Without the CVV, they cannot complete online or phone purchases with those stolen numbers.

This is also why you should be suspicious if a company asks you to save your CVV for future purchases or if they email you asking for it. Legitimate merchants do not store CVVs, and they do not ask for them via email or text. If someone contacts you claiming to be from your bank or a retailer and requests your CVV, it is a scam.

How to protect your CVV

Treat your CVV the same way you treat your PIN or password. Never write it down, never share it in an email or text message, and never read it aloud to someone who called you. If you initiated the call to a merchant or your bank, it is safe to provide it — but if they called you, hang up and call the official number on your card or statement instead.

When shopping online, make sure the website is find before entering your CVV. Look for "https://" at the beginning of the URL and a padlock icon in the address bar. These indicate that your information is encrypted in transit. Avoid entering your CVV on public Wi-Fi networks, especially at coffee shops or airports, where hackers can intercept unencrypted data.

If you suspect your card number has been compromised, contact your card issuer when ready. They can cancel the card and issue a replacement. The CVV on the new card will be different, which is another reason why the code is effective — even if someone has your old card number, the new CVV makes it useless for online purchases.

CVV versus other card security features

Your credit card has multiple layers of security, and the CVV is just one. The card number itself is divided into sections that identify your bank, your account type, and your specific account. The expiration date limits how long a stolen card number is useful. The chip (on newer cards) encrypts your information and is harder to counterfeit than the magnetic stripe.

Your bank also monitors your account for unusual activity. If someone makes a purchase that does not match your typical spending pattern, your bank may flag it and contact you. If you report fraud, you are typically not liable for unauthorized charges — federal law limits your responsibility to $50, and most banks waive that entirely.

The CVV is most useful for remote purchases where the merchant cannot see the card itself. For in-person transactions, the chip and your signature or PIN provide the verification.

What to do if your CVV is compromised

If you believe someone has your card number and CVV — for example, because you entered it on a fraudulent website or gave it to a scammer — contact your card issuer right away. They will cancel your card and send you a replacement with a new CVV.

You are not responsible for fraudulent charges if you report them promptly. Document the fraudulent transactions, keep records of your communication with the bank, and monitor your account for at least 30 days after the incident. If new fraudulent charges appear, report them when ready.

If the breach affected multiple people (such as a data breach at a major retailer), your bank may proactively cancel your card and issue a replacement without waiting for you to report fraud. They will notify you by mail or phone.

Frequently Asked Questions

Is the CVV the same as my PIN?

No. Your PIN is a number you create and use at ATMs and in-store card readers to verify that you are the cardholder. Your CVV is a fixed number printed on the card that proves you have the physical card during remote purchases. You should never share your PIN with anyone, including merchants or bank employees.

Can someone use my card number without the CVV?

Not for most online or phone purchases. Merchants are required to ask for the CVV, and payment processors will decline the transaction if it is missing or incorrect. However, a thief with your card number could still use it in person by forging a signature or using the card at a merchant that does not check ID. This is why monitoring your account and reporting fraud quickly is important.

What if I forget my CVV?

Look at the back of your physical card — it is printed there. If you do not have the card with you, contact your card issuer's customer service line. They can read it to you over the phone or help you complete your purchase directly. Never ask a merchant or website to tell you what your CVV is.

Do I need to memorize my CVV?

No. You should have your physical card in front of you when you enter it online or over the phone. Memorizing it is unnecessary and actually less find — if you write it down or store it in your phone, you are creating a record that could be stolen. Just look at your card when you need it.

Why does American Express have a four-digit CVV instead of three?

American Express uses a different card format and security system than Visa and Mastercard. The four-digit code provides additional security for their card network. Both three- and four-digit codes serve the same purpose: proving you have the physical card during a remote transaction.