Debit Card
The CVV (Card Verification Value) also called CVC (Card Verification Code) or CSC (Card Security Code) is a short numerical code added to debit and credit cards as an additional layer of security for card-not-present (CNP) transactions, such as online shopping and phone-based purchases.
Unlike your ATM PIN, which is used at physical payment terminals and ATMs, the CVV is only needed when the card is not physically swiped or tapped i.e., during internet transactions. The CVV is never stored by merchants, which is why it needs to be entered every time you shop online.
In India, the Reserve Bank of India (RBI) has made two-factor authentication (2FA) mandatory for all online card transactions meaning even if a fraudster knows your CVV, they cannot complete a transaction without the OTP sent to your registered mobile number.
The CVV is deliberately printed rather than embossed, meaning it does not appear on card imprints adding an extra layer of physical security.
CVV Type | Full Name | Where Used | How Generated |
CVV1 | Card Verification Value 1 | Encoded in magnetic stripe; used for in-person swiped transactions | Encoded at card issuance |
CVV2 | Card Verification Value 2 | Printed on back of card; used for online/phone transactions | Printed at card issuance, static |
iCVV | Integrated CVV / Dynamic CVV | Used in chip (EMV) transactions | Generated dynamically for each chip transaction |
Dynamic CVV | Tokenized/rotating CVV | For online transactions via tokenization | Rotates every transaction or time period |
The key distinction: CVV1 protects in-person swipe transactions, CVV2 protects online transactions, and iCVV protects chip transactions. If a fraudster copies your magnetic stripe (skimming), the iCVV prevents them from using the data online because the codes are different.
Parameter | CVV | ATM PIN |
Length | 3 digits (4 for Amex) | 4 or 6 digits |
Where Used | Online/phone transactions (card not present) | ATM withdrawals, POS terminals (card present) |
Who Sets It | Issued by the bank printed on card | Set by the cardholder |
Can Be Changed? | No fixed at card issuance | Yes changeable anytime at ATM or app |
Stored by Merchants? | No PCI DSS prohibits storage | No |
If Forgotten? | Request a new card | Reset via ATM or bank app |
Several banks globally and increasingly in India are moving towards Dynamic CVV (also called dCVV or DCVV). Unlike the static CVV printed on your card, a dynamic CVV changes periodically (every 30 minutes, hourly, or per transaction). It is displayed on a small e-ink screen on the card itself, or sent via the bank's app.
Benefits of Dynamic CVV: Even if a fraudster captures your CVV in a data breach, it becomes useless within minutes because the code has changed. This dramatically reduces online card fraud in card-not-present scenarios.
From October 2022, RBI mandated that merchants cannot store raw card details (including CVV) on their servers. Instead, they must use card tokenization a process where your card details are replaced with a unique digital token for each merchant.
What this means for you: When you save a card on Amazon, Zomato, or any other platform after October 2022, the merchant stores only a token, not your actual card number or CVV. This significantly reduces the risk of your CVV being stolen in a merchant data breach.
Always do this:
Never do this:
Over time, the CVV printed on the signature strip can fade due to wear. If your CVV is unreadable, you should request a replacement card from your bank. Options include:
In the interim, ask your bank if they can verify your CVV through a secure channel. Never attempt to guess or reconstruct a faded CVV.
Fraudsters commonly use the following tactics to steal CVV details:
✅ Key Takeaways
Understanding your CVV and using it responsibly is an important part of keeping your debit card and online transactions secure. While the CVV provides an additional layer of protection, it should never be shared with anyone, including callers claiming to represent your bank. Always use trusted payment websites, stay alert to phishing attempts, enable transaction alerts, and report any suspicious or unauthorised activity to your bank immediately. By following these simple precautions, you can reduce the risk of card fraud and enjoy safer digital payments.
In India, most online card transactions require CVV plus OTP (two-factor authentication). A few merchants may process transactions without CVV but this is becoming rare as banks enforce stricter security norms.
No. You should only enter your CVV on the payment page of a trusted website. A legitimate merchant or bank representative will never ask you to share your CVV verbally, via email, or on a call.
American Express cards have a 4-digit CVV (called CID Card Identification Number) printed on the front of the card, above the card number on the right side unlike Visa and Mastercard where the CVV is 3 digits on the back.
You should request a replacement debit card immediately via the AU 0 app, net banking, or by visiting your branch. Attempting to guess a CVV is not recommended and may result in card blocking after multiple wrong attempts.
No. CVV is a printed code used for online transactions; your PIN is a password you set yourself for ATM and in-person transactions. They serve completely different security purposes.
In India, this is very difficult because RBI requires OTP verification for online transactions. However, on some international websites that do not require OTP, a CVV combined with card number could be enough which is why you must report any card loss immediately.