What Does Card Not Present Mean? Fees, Chargebacks, and 3D Secure

A card-not-present transaction is any payment where the merchant never physically reads the buyer’s card through a chip, swipe, or contactless tap. So when people ask what “card not present” means, the short answer is this: the classification covers online checkouts, phone and mail orders, recurring subscription billing, and any charge where card details are keyed in rather than read from the card’s security hardware. The label matters because card networks treat these payments as higher risk, which shows up in three concrete ways for the merchant — higher interchange fees, stricter rules about the data you collect and store, and default liability for fraudulent charges.

Which Transactions Count as Card Not Present

The card networks draw the line strictly around whether the card’s chip, magnetic stripe, or NFC antenna was physically interacted with. It doesn’t matter whether the customer is a regular or a first-time buyer. What matters is how the payment data entered the system.

The common scenarios:

  • Online purchases processed through a website or mobile app shopping cart.
  • Phone and mail orders (often called MOTO), where a customer reads card details over the phone or mails them in on an order form.
  • Recurring billing against a card stored on file, even if the customer originally handed the card over in person.
  • Manual key entry, when a merchant types card numbers into a terminal because the chip reader failed or the stripe won’t read. The terminal is physically present, but the card’s security hardware was bypassed, so the network treats it as CNP.

Virtual terminals — web-based interfaces where a merchant employee keys in payment details from a laptop or tablet — also produce CNP transactions. Unlike a standard e-commerce checkout where the customer enters their own information, a virtual terminal has the merchant doing the data entry. The classification is the same either way because no physical card read occurred.

Where Digital Wallets Fit In

Digital wallets like Apple Pay and Google Pay are the most common source of confusion. When a customer taps their phone at a physical terminal, the payment uses NFC tokenization and gets classified as card-present, with card-present interchange rates. But when that same customer uses Apple Pay to check out on a website, the transaction source is flagged as an internet payment and processed at CNP rates. The authentication method — fingerprint or face scan — doesn’t change the classification. What matters is whether the payment traveled through a physical terminal or a web gateway.

What Data You Need to Collect, and What You Can’t Store

Without a physical card read, you need enough information to convince the issuing bank the charge is legitimate. The essentials:

  • The Primary Account Number (PAN), typically the 16-digit number on the front of the card, which identifies the issuing bank and funding account.
  • The expiration date, which confirms the account hasn’t been closed or reissued.
  • The Card Verification Value (CVV or CVV2) — the three-digit code on the back of Visa and Mastercard cards, or four digits on the front of American Express. This code stands in for physically holding the card, since it isn’t encoded on the magnetic stripe or chip and shouldn’t appear in stolen data from a card-present breach.
  • The billing address, used by the Address Verification Service (AVS) to cross-check the street number and zip code against the issuer’s records.

Merchants are prohibited from storing the CVV after the transaction is authorized. PCI Data Security Standards treat it as sensitive authentication data that must be purged immediately, even if encrypted.1PCI Security Standards Council. PCI Data Storage Dos and Donts

AVS is the primary tool for verifying that the person placing the order actually has access to the cardholder’s billing statements. Visa’s documentation describes it as a service that determines whether the issuer recognizes the billing address provided during checkout, and notes it is primarily used in CNP environments.2Visa. How to Use Payment Account Validation

Tokenization for Cards on File

If you bill customers on a recurring basis, you need to charge the card repeatedly but aren’t allowed to store the actual card number in your own systems without meeting heavy PCI requirements. Tokenization solves this by replacing the PAN with a randomly generated substitute that has no mathematical relationship to the original number. The real card data sits in a secure vault maintained by the payment processor or a dedicated token service provider. When the next billing cycle arrives, your system sends the token, the vault looks up the real PAN, and the charge goes through.

The practical benefit is scope reduction. If your systems never touch actual card numbers, most of your infrastructure falls outside the PCI audit boundary, which lowers compliance costs and reduces exposure in a breach.

Why CNP Costs More

Every card transaction involves interchange (paid to the issuing bank), a processor markup, and network assessments. CNP transactions cost more at the interchange layer because the network rates themselves are higher.

For a standard Mastercard consumer credit purchase, the published schedules show the gap. Small-ticket card-present transactions carry interchange of 1.65% plus $0.02 per transaction, while the equivalent CNP rate is 1.95% plus $0.02.3Mastercard. 2024-2025 US Region Interchange Programs and Rates Premium rewards cards, signature cards, and commercial cards push CNP interchange higher, into the 2.05% to 2.50% range for consumer cards and above 3.00% for certain commercial card categories. Card-present rates for the same card types are consistently lower.

Across common card mixes, the CNP premium runs roughly 0.3 to 0.8 percentage points above what a chip-read or contactless tap would cost. Processor markup sits on top of that, so the total gap can be wider than the interchange gap alone.

Downgrades Quietly Push the Rate Higher

If you fail to submit all required data — skipping the CVV, omitting AVS information, or settling the transaction too slowly — the card network may downgrade your transaction to a higher interchange tier. Non-qualified rates on Mastercard’s schedule reach 3.15% to 3.30% plus $0.10, and similar penalties apply on the Visa network.3Mastercard. 2024-2025 US Region Interchange Programs and Rates

Downgrades usually don’t show up as a separate line on processor statements. Your effective rate just creeps upward. Collecting complete transaction data and settling batches promptly are the simplest ways to avoid them.

Chargebacks and Who Pays When Fraud Happens

Higher fees aren’t the only cost of accepting payments remotely. Chargebacks — where the issuing bank reverses a transaction after a cardholder disputes it — hit CNP merchants far harder than brick-and-mortar businesses. The reason is straightforward: merchants are generally liable for all chargebacks on card-not-present transactions, including those triggered by genuine fraud. For card-present transactions with a chip read, fraud liability usually shifts to the issuing bank.4Mastercard. How Can Merchants Dispute Credit Card Chargebacks

When a chargeback lands, you lose the transaction amount, you lose the shipped merchandise if physical goods were involved, and you get hit with a chargeback fee, typically $20 to $100 per incident depending on the processor. The chargeback fee still applies regardless of whether you’re ultimately found liable.

You can fight a chargeback through a process called representment, where you submit evidence that the transaction was legitimate. Visa gives merchants 30 days to respond with documentation.5Visa. Visa Claims Resolution Mastercard allows 45 calendar days from the settlement date for the acquirer to submit a second presentment.6Mastercard. Chargeback Guide Merchant Edition Winning requires specific evidence: delivery confirmation with signature, AVS match records, device fingerprinting data, or proof that the cardholder continued using the service after the disputed charge. Vague assertions that the charge was valid don’t work.

Too many chargebacks can trigger enrollment in a card network’s monitoring program. Visa’s Acquirer Monitoring Program (VAMP) flags merchants whose combined ratio of fraud reports and disputes to settled transactions reaches 1.5% or higher (effective April 2026 for U.S. merchants), with a minimum of 1,500 monthly fraud and dispute counts.7Visa. Visa Acquirer Monitoring Program Overview Once flagged, merchants face escalating fines and may eventually lose the ability to accept that card brand.

How to Shift Fraud Liability Back With 3D Secure

The single most effective tool for moving CNP fraud liability away from your business is 3D Secure (3DS) authentication, branded as Visa Secure and Mastercard Identity Check. When a customer checks out on your site, 3DS triggers an additional authentication step managed by the issuing bank, often through a one-time passcode or biometric verification on the customer’s device.

The payoff is a liability shift. When a transaction is successfully authenticated through 3DS and a fraud chargeback is later filed, liability moves from the merchant to the card issuer. Visa’s documentation states that successful authentication “reduces fraud risk and can shift liability away from the merchant.”8Visa. 3D Secure: Your Guide to Safer Transactions

There are limits. The liability shift only covers fraud-coded disputes, not complaints about products being defective, not received, or not as described. And “data-only” 3DS, where risk data is shared with the issuer but no full authentication occurs, does not trigger a liability shift. To get the protection, you need a fully authenticated transaction with a valid cryptographic value passed in the authorization.

The earlier version of 3DS was known for adding friction: pop-up windows, clunky redirects, abandoned carts. The current version (EMV 3DS) runs most authentications silently in the background using device and behavioral data. Only high-risk transactions get bumped to an active challenge.

PCI Compliance for Remote Merchants

Any merchant that accepts card payments must comply with the Payment Card Industry Data Security Standard (PCI DSS), but CNP merchants face heavier scrutiny because their systems handle card data transmitted over networks rather than read from a chip. The current standard, PCI DSS version 4.0.1, requires that the Primary Account Number be rendered unreadable wherever it’s stored, through encryption, tokenization, truncation, or one-way hashing.

Strong encryption is mandatory whenever card information travels over public networks. The standard requires that only trusted certificates are accepted and that the encryption protocol doesn’t allow fallback to insecure versions.

Access controls must follow a least-privilege model. Only employees who need cardholder data for a specific job function should be able to reach it, every user must have a unique ID, and direct query access to stored cardholder data is limited to designated administrators.

Failing to validate PCI compliance, usually by completing an annual Self-Assessment Questionnaire, can trigger monthly non-compliance fees from your payment processor. For small merchants, these penalties typically start between $20 and $250 per month and increase with transaction volume and duration of non-compliance. Beyond the fees, non-compliant merchants face significantly higher liability exposure if a data breach occurs. The card networks can impose fines running into tens of thousands of dollars monthly on processors, who pass those costs directly to the merchant.

The most practical way to minimize PCI burden is to reduce the amount of card data your systems touch. Using a hosted payment page, where the customer enters card details on the processor’s site rather than yours, combined with tokenization for stored cards, can drop most of your infrastructure out of PCI scope entirely.