How Dynamic CVV and Rotating Security Codes Work

A dynamic CVV is a payment card security code that changes on a schedule instead of staying printed on the back of your card forever. Here is how dynamic CVV works in practice: your card and your issuer’s server independently run the same cryptographic calculation at the same moment, producing a three- or four-digit code that is valid for a short window — often about an hour on physical cards with a small display, or on demand inside a banking app. When you enter that code at online checkout, the issuer recomputes what the code should be right now and approves the transaction only if the numbers match. A code copied from a breached database or an old receipt has already rotated out by the time a thief tries to use it.

How the Rotating Code Is Generated

Dynamic CVV systems rely on cryptographic algorithms such as AES or Triple DES. The card (or the app on your phone) combines a portion of your card number, a timestamp or rolling counter, and a secret key that only your issuer knows. That input is encrypted, and a three- or four-digit code is extracted from the output.

Your issuer runs the same calculation on its own server in parallel. When your code arrives with the authorization request, the server checks it against the value it just generated for that moment. A small grace period covers network delay, so a code that expired a few seconds before you hit submit will still clear.

Refresh intervals depend on the implementation. Physical cards with a built-in e-paper screen, like those using IDEMIA’s Motion Code technology, generate a new code roughly every hour.1IDEMIA. MOTION CODE – Dynamic Cryptogram Card App-based versions can refresh more often, or produce a code on demand when you open the app to pay. Either way, the window is short enough that a stolen code is worthless by the time someone tries to reuse it.

Where You Can Actually Get One

Two delivery methods exist. The first is a physical card with a tiny e-paper display where the static code would normally be printed; the screen refreshes on its own using an embedded battery, and the card otherwise looks and feels like any other credit card.1IDEMIA. MOTION CODE – Dynamic Cryptogram Card The second is an app-based approach, where the current code appears only inside your bank’s mobile application.

The technology is more common in Europe than in the United States. Société Générale in France began issuing physical dynamic CVV cards through IDEMIA in 2016. In the U.S., the best-known example is Apple Card, issued by Goldman Sachs, which shows a rotating security code inside the Wallet app rather than printing one on the titanium card. PNC Financial Services has piloted Motion Code cards, but a broad U.S. rollout has not followed.

Merchants generally do not need to change anything to accept these codes. Visa’s dCVV2 service supports both physical and app-based generation and is listed as globally available, with no back-end changes required for merchants already handling card-not-present transactions.2Visa Developer. Enable Generation of Dynamic CVV2 Codes

Turning It On and Using It at Checkout

If your bank offers dynamic CVV through its app, the setting usually lives in the card management or security area of your dashboard. Activating it typically requires multi-factor authentication. Some institutions push a software update before the feature goes live. Once it is on, the app displays your current code alongside a countdown showing when it will refresh.

If you want a physical card with an embedded display, you have to request a replacement. Some banks charge for the upgraded plastic, and availability depends on whether your issuer has partnered with a manufacturer that produces e-paper display cards. Société Générale, for example, has charged roughly a dollar a month for the feature as a subscription.

At checkout, the process is identical to entering a static CVV. Type your card number and expiration date, glance at the card’s display or open the app for the current code, and submit before the timer runs out. The authorization request travels through the payment network to your issuer, which validates the code against its own server-side calculation for that moment.

Subscriptions, Hotel Holds, and Other Recurring Charges

Rotating codes do not break subscription billing. The initial signup transaction uses your current dynamic code, but the payment processor does not store the code itself. It stores a token: a substitute identifier that represents your card without containing the actual security digits. Your issuer flags later charges from that merchant as recurring, and no fresh security code is required. This is the same tokenization already used for recurring payments on static-CVV cards.

Delayed-charge transactions work through the same mechanism but can still cause friction. Hotels and rental car companies typically authorize your card at check-in and finalize the charge days later, long after the original code has expired. Most of the time the token carries the payment through. When it does not, you may need to contact the merchant or your bank to reauthorize.

If you cancel a subscription and the charges continue anyway, you can dispute them. For credit cards, federal law requires your issuer to acknowledge a written billing dispute within 30 days and resolve it within two billing cycles, no more than 90 days.3Office of the Law Revision Counsel. 15 USC 1666 – Correction of Billing Errors For debit cards, Regulation E under the Electronic Fund Transfer Act governs the dispute process and sets its own timelines.4eCFR. 12 CFR Part 205 – Electronic Fund Transfers (Regulation E)

What Dynamic CVV Actually Protects Against

The technology is genuinely effective against the most common form of card-not-present fraud: reuse of stolen data. When a retailer’s database is breached and millions of card numbers leak, static security codes in that data stay valid for the life of the card. A rotating code expires within hours. The same logic applies to numbers copied from old receipts, photographs of cards, or magnetic-stripe skimmers.1IDEMIA. MOTION CODE – Dynamic Cryptogram Card

There is a real blind spot. If a phishing site tricks you into entering your current code and relays the transaction in real time, that code is still valid during the session. Visa has flagged relay fraud as a growing concern. Dynamic CVV forces the attacker to move fast, but it does not stop the attack. No security code, static or rotating, helps you if you type it into a fraudulent checkout page.

Dynamic CVV also does nothing for in-person theft of the physical card. Chip and contactless terminals read the chip directly and ignore the code printed or displayed on the back. The technology is built for online transactions where the merchant cannot physically verify the card.

Your Fraud Liability Stays the Same

Federal fraud protections do not change based on whether your card has a static or dynamic security code. Neither Regulation Z nor Regulation E ties liability to the security technology in use.4eCFR. 12 CFR Part 205 – Electronic Fund Transfers (Regulation E)

For credit cards, your liability for unauthorized charges is capped at $50, and your issuer has to meet specific disclosure conditions for even that much to apply.5eCFR. 12 CFR 1026.12 – Special Credit Card Provisions Most major issuers voluntarily offer zero-liability policies that go beyond that floor.

Debit cards follow a tiered structure under Regulation E. Report an unauthorized transfer within two business days of learning about it and your liability is capped at $50. Report between two business days and 60 days after your statement is sent and the cap rises to $500. Miss the 60-day window and you can be responsible for the full amount of transfers that occur after that deadline.4eCFR. 12 CFR Part 205 – Electronic Fund Transfers (Regulation E) Prompt reporting matters regardless of which security code is on the card.

Practical Limits to Keep in Mind

The biggest day-to-day risk with app-based dynamic CVV is losing access to your phone. A dead battery, a crashed app, or no service means no code, and no online purchase until you are back up. Physical e-paper cards sidestep this because the display runs on its own battery. Apple Card users, who rely on the Wallet app, live with this trade-off.

Dynamic CVV Is Not the Same as a Virtual Card Number

People often confuse the two, and they solve different problems. Dynamic CVV keeps your real card number and expiration date intact and only rotates the security code. A virtual card number generates an entirely separate card number for each transaction or merchant, keeping your real number hidden. Some banks offer both, and they can layer.

Virtual card numbers are the more widely available option in the U.S. right now. If your issuer does not offer a rotating code, generating a virtual number through your bank’s app produces a similar anti-fraud outcome for online purchases. The trade-off is that virtual numbers can complicate returns or price-match requests if the merchant needs to credit the original card number.