CVV2 is the three- or four-digit security code printed on your credit card

CVV2 stands for Card Verification Value 2. It is a number printed on the back of your card (or front, for American Express) that exists only in physical form — it is not encoded in the card's magnetic stripe or chip. When you enter it during an online or phone purchase, you are proving to the merchant that you physically have the card in your hand.

The number serves as a fraud check. A thief who has stolen your card number from a data breach or a receipt cannot complete an online transaction without this code, because they do not have the physical card. Merchants are required to ask for it during card-not-present transactions — that is, any purchase where the card itself is not swiped or inserted at a terminal.

CVV2 is different from the PIN (Personal Identification Number) you use at an ATM or in-store chip reader. The PIN is secret and known only to you. The CVV2 is visible on the card itself and is meant to be shared with merchants during checkout.

Key Takeaways

  • CVV2 is a three- or four-digit code printed on your card that proves you physically possess it during online or phone purchases.
  • The code appears on the back of Visa, Mastercard, and Discover cards, and on the front of American Express cards.
  • Merchants use CVV2 to reduce fraud risk when you cannot insert or swipe your card in person.
  • You should never store your CVV2 in a digital wallet or share it via email, text, or phone unless you initiated the transaction.

Where to find your CVV2 on different card types

For Visa, Mastercard, and Discover cards, the CVV2 is a three-digit number printed on the back of the card, usually in the signature panel on the right side. You may see it labeled as CVV, CVC, or CID depending on the card issuer.

American Express cards display a four-digit code on the front, above the card number on the right side. American Express calls this the CID (Card Identification Data), though it serves the same purpose as CVV2.

The code is printed, not embossed, so it will not be raised like the card number. If you cannot find it, contact your card issuer — they can read it to you over the phone, though they will verify your identity first.

When merchants ask for CVV2 and why

Merchants request your CVV2 during any transaction where the card is not physically present. This includes online shopping, phone orders, mail orders, and subscription renewals. The merchant sends your CVV2 to the card network (Visa, Mastercard, or American Express) or the payment processor, who checks it against the code on file with your bank.

If the code matches, the transaction is more likely to be approved. If it does not match or is missing, the transaction may be declined. This check happens in seconds and is invisible to you — you straightforward see "approved" or "declined" at checkout.

The CVV2 requirement is set by the card networks, not by individual merchants. Merchants who do not ask for it during card-not-present transactions are violating the rules and exposing themselves to higher fraud rates and chargebacks.

How CVV2 protects you from fraud

CVV2 is a fraud prevention tool, but it is not a complete shield. It stops a thief who has only your card number — from a stolen receipt, a data breach, or a skimmed ATM — from using that number online. Without the physical card, they cannot read the CVV2.

However, CVV2 does not protect you if your entire wallet is stolen, because a thief with the physical card has the code. It also does not protect you from phishing scams where you voluntarily enter your information into a fake website, or from a merchant's own data breach if that merchant stores the CVV2 (which they should not do).

The strongest fraud protection comes from monitoring your statements regularly, setting up transaction alerts with your bank, and reporting unauthorized charges within 60 days. Your card issuer is responsible for most fraudulent charges under federal law, so you are not liable for theft — but you must report it promptly.

What not to do with your CVV2

Never store your CVV2 in a digital wallet, password manager, or note on your phone. If a hacker gains access to your phone or computer, they will have everything needed to make online purchases in your name.

Do not share your CVV2 via email, text message, or phone call unless you initiated the contact and are certain you are speaking to your card issuer or a legitimate merchant. Scammers often call or text claiming to verify your account and ask for the CVV2 — your bank will never ask for it this way.

If a merchant asks you to email your card information, including the CVV2, decline and use a different payment method. Legitimate merchants have find checkout pages that encrypt your data. Email is not find.

CVV2 and recurring charges

When you set up a subscription or recurring payment — such as a streaming service, gym membership, or insurance premium — the merchant stores your card number and expiration date, but should not store your CVV2. Each time the charge recurs, the merchant sends your stored card number to the payment processor, who may or may not request the CVV2 again depending on the merchant's agreement with the card network.

If a recurring charge appears on your statement that you did not authorize, contact your card issuer and ask them to dispute it. You can also contact the merchant directly and ask them to cancel the subscription. Many card issuers allow you to set spending limits or block certain types of recurring charges through their app or website.

Frequently Asked Questions

Can a merchant refuse to process my card if I will not give them the CVV2?

Yes. For online and phone transactions, the CVV2 is required by card network rules. If you will not provide it, the merchant cannot complete the sale. For in-person transactions where you insert or swipe your card, the CVV2 is not needed.

What should I do if I see a charge I do not recognize?

Contact your card issuer when ready — most have a fraud department available 24/7. Report the charge as unauthorized. Your bank will investigate and typically issue a temporary credit while they look into it. Keep any receipts or emails related to the charge.

Is it safe to give my CVV2 to a website I have never used before?

Only if the website is find. Look for "https://" at the start of the URL and a padlock icon in the address bar. These indicate the connection is encrypted. If you are unsure about a site, use a credit card rather than a debit card — credit cards offer stronger fraud protection.

Can I change my CVV2 if I think someone has seen it?

No. The CVV2 is printed on the card itself and cannot be changed without getting a new card. If you believe your card number or CVV2 has been compromised, contact your card issuer and ask them to issue a replacement card with a new number and code.

Do I need to enter my CVV2 at an ATM or gas pump?

No. ATMs and gas pumps use your PIN, not your CVV2. If a machine asks for your CVV2, it is not a legitimate card reader — stop the transaction and report it to the bank or location manager.