Card-present vs card-not-present: A card-present (CP) transaction occurs when a customer uses a physical card or eligible contactless credential at a payment terminal, while a card-not-present (CNP) transaction happens remotely, such as online, in an app, by phone or by mail. Card-present payments generally have lower fraud exposure because EMV chips, contactless cryptograms and PINs can help prove the payment instrument was present. CNP payments carry higher identity and credential-theft risk, so merchants commonly use AVS, CVV/CVC, 3D Secure, tokenization and risk scoring. Liability depends on the card network, region, authentication method and whether the merchant followed required security rules.

Every card payment looks simple from the customer side: tap, insert, enter card details and pay. Behind that checkout, however, payment networks classify transactions differently depending on whether the payment credential is presented through an approved physical acceptance device or submitted remotely. The two broad categories are card-present (CP) and card-not-present (CNP) transactions.

That distinction matters because it affects fraud risk, security controls, processing cost, dispute exposure and, in some circumstances, liability. A physical chip transaction can provide strong evidence that a genuine payment device was present. An online transaction cannot rely on the same physical proof, so it needs different signals to answer a harder question: is the person entering these card details really the legitimate cardholder?

For merchants, understanding card present vs card not present payments is not just payment terminology. It is a practical fraud-prevention skill. The safest strategy is to use the security controls designed for each channel instead of treating every card payment the same way.

What Is a Card-Present Transaction?

A card-present transaction is a payment in which the customer uses a payment credential through an in-person point-of-sale environment. Typical examples include inserting an EMV chip card, tapping a contactless card or eligible mobile wallet at a terminal, or, where still supported, swiping a magnetic-stripe card.

The important idea is not simply that the customer is standing in a store. What matters is that the payment is captured through an acceptance method that can provide card-present transaction data. Modern chip and contactless transactions generate dynamic information that helps issuers distinguish a legitimate transaction from copied static card data.

  • In-store chip payments at a POS terminal.
  • Contactless tap-to-pay transactions using a physical card.
  • Eligible mobile-wallet payments made at a contactless terminal.
  • In-person payments processed through certified card-reading hardware.
  • Magnetic-stripe transactions in environments where they remain permitted, although they provide weaker security than EMV chip or contactless payments.

What Is a Card-Not-Present Transaction?

A card-not-present transaction occurs when the merchant processes a card payment without reading the physical card through an in-person card terminal. Ecommerce is the most familiar example, but CNP also includes many app payments, payment links, recurring card-on-file payments, telephone orders and mail-order transactions.

In a CNP checkout, the merchant usually receives payment credentials or a token rather than physical evidence that the card itself is present. This creates a different risk profile. Stolen card details can sometimes be entered by someone who has never possessed the actual card, which is why CNP fraud detection relies heavily on identity, device, behavioral and authentication signals.

  • Website and ecommerce checkout payments.
  • Mobile-app purchases where the card is entered or stored remotely.
  • Payment links and hosted checkout pages.
  • Telephone and mail-order payments.
  • Recurring or subscription payments using stored credentials.
  • Some merchant-initiated transactions after a cardholder has established the payment relationship.

Card Present vs Card Not Present: Key Differences

Factor

Card Present (CP)

Card Not Present (CNP)

Where it happens

Physical POS or in-person acceptance environment

Online, app, phone, mail or remote checkout

Card verification

Card/chip/contactless data can be read by a terminal

Physical card is not read by the merchant

Typical security

EMV chip, contactless cryptograms, PIN, terminal security

AVS, CVV/CVC, 3D Secure, tokenization, device and behavioral risk signals

Fraud exposure

Generally lower with modern EMV acceptance

Generally higher because stolen credentials can be used remotely

Fees

Often lower because risk is generally lower

Often higher because risk and chargeback exposure are generally higher

Disputes

Can involve lost/stolen card or counterfeit-card scenarios

Frequently tied to unauthorized ecommerce use, account takeover or friendly-fraud disputes

Liability

Depends on network rules, EMV compliance and transaction details

Often sits with the merchant unless a qualifying authentication/liability-shift rule applies

Why Card-Not-Present Fraud Is Usually Higher Risk

The biggest security difference between CP and CNP transactions is proof of possession. With an EMV chip transaction, the terminal and card can participate in cryptographic processing that is difficult to reproduce using only a stolen card number. In a remote checkout, the merchant cannot inspect the card or rely on a chip-terminal interaction.

Promotional banner

That does not mean online payments are inherently unsafe. It means they require a different security stack. Strong CNP security combines several weak and strong signals so that an attacker who has only a card number, expiration date and even a security code still faces additional barriers.

  • Credential theft from phishing, malware or data breaches.
  • Account takeover where an attacker abuses a legitimate customer account.
  • Automated testing of stolen card details across ecommerce sites.
  • Use of compromised payment credentials from another country or device.
  • Friendly-fraud or first-party misuse disputes where a legitimate purchaser later challenges the charge.

Card-Present Fraud Risks

Card-present payments have strong security advantages, but they are not fraud-proof. Fraud can involve stolen physical cards, manipulated terminals, magnetic-stripe fallback, skimming, social engineering or unauthorized use before a cardholder reports the card missing.

EMV chip technology significantly improved the security of in-person payments because a chip transaction can generate dynamic transaction data instead of relying only on reusable magnetic-stripe information. Contactless EMV payments similarly use dynamic security values. Merchants should therefore favor chip and contactless acceptance and treat unusual fallback behavior as a risk signal.

  • Use EMV chip or contactless acceptance wherever available.
  • Keep POS terminals patched, physically secured and inventoried.
  • Monitor repeated fallback to magnetic stripe or manual entry.
  • Train staff to recognize damaged, altered or suspicious payment devices.
  • Protect POS environments against malware, tampering and unauthorized access.

Card-Not-Present Fraud Detection

Card-not-present fraud detection works best as a layered decision system rather than a single pass/fail check. Merchants should combine payment data, authentication results, device intelligence and behavioral patterns to estimate whether the customer is legitimate.

1. Address Verification Service (AVS)

AVS compares parts of the billing address supplied during checkout with address data available to the issuer. A match can support a legitimate transaction, while a mismatch can increase risk. AVS is useful, but it should not be treated as proof of identity because legitimate customers can move, mistype information or use addresses that do not match perfectly.

2. CVV or CVC Checks

The card security code helps indicate that the shopper has access to card information beyond the primary account number. A valid CVV/CVC result is helpful, but stolen credentials can include the code, so it should be one signal among many.

Promotional banner

3. 3D Secure Authentication

EMV 3-D Secure allows merchants and issuers to exchange transaction and risk information so the issuer can authenticate the cardholder when appropriate. Low-risk transactions may pass through frictionlessly, while higher-risk transactions can trigger step-up verification. Depending on the card network, region and authentication outcome, qualifying 3DS transactions can also shift certain fraud liability away from the merchant.

4. Device and Behavioral Signals

Fraud systems can evaluate whether the device, browser, IP geography, account history, purchasing pattern and checkout behavior are consistent with the customer. No single device signal is decisive; the value comes from combining many signals into a risk assessment.

5. Velocity and Transaction Monitoring

Repeated payment attempts, rapid purchases, multiple cards on one account, many accounts on one device or unusual order values can indicate automated testing or account abuse. Velocity rules can slow or block suspicious activity before losses accumulate.

Liability: Who Pays When Fraud Happens?

Liability is one of the most misunderstood differences between card-present and card-not-present payments. There is no single rule that applies to every transaction worldwide. The outcome depends on card-network rules, region, transaction type, authentication, merchant configuration and whether the merchant followed applicable acceptance requirements.

For card-present payments, EMV liability rules can protect merchants that correctly process chip-enabled cards through compliant terminals in qualifying scenarios. If a merchant fails to use appropriate EMV technology when it should have been used, liability can shift toward the merchant in certain counterfeit-fraud cases.

For card-not-present payments, merchants often carry more fraud and chargeback exposure because the physical card cannot be verified. However, qualifying 3D Secure authentication can provide a liability shift for certain fraud disputes. Visa, for example, describes Visa Secure as supporting liability shift for authenticated or attempted-authentication ecommerce transactions, subject to program rules and exceptions.

The practical lesson is simple: merchants should not assume that “3DS means zero liability” or that every chip transaction automatically protects them. Network rules contain exceptions, regional requirements and dispute categories that must be reviewed with the merchant acquirer or payment processor.

Promotional banner

Are Card-Present Transactions More Secure?

In general, yes: modern card-present transactions are considered lower risk because the payment system can verify the presence of a physical payment credential and use EMV security data. That is why in-person transactions often have lower processing costs than CNP payments.

But “more secure” should not be confused with “immune to fraud.” A poorly secured POS system, stolen card, compromised terminal or insecure fallback process can still create losses. Similarly, a well-designed CNP checkout using 3D Secure, tokenization and modern fraud analytics can be highly secure despite lacking physical card presence.

Security Technologies for Card-Present Payments

  • EMV chip: Creates dynamic transaction data that is harder to counterfeit than static magnetic-stripe information.
  • Contactless EMV: Uses short-range tap technology with dynamic security values for eligible payments.
  • PIN verification: Adds a cardholder-verification factor in supported markets and transaction types.
  • Point-to-point encryption: Helps protect payment data as it moves from the payment device through the processing environment.
  • POS monitoring and hardening: Reduces the risk of malware, terminal tampering and unauthorized access.

Security Technologies for Card-Not-Present Payments

  • 3D Secure: Adds issuer-led authentication and can provide liability benefits for qualifying transactions.
  • AVS: Compares billing-address information with issuer records where supported.
  • CVV/CVC: Adds a card-verification signal separate from the main card number.
  • Tokenization: Replaces sensitive account data with a token for supported payment flows and stored credentials.
  • Device intelligence: Assesses browser, device, network and behavioral context.
  • Risk scoring and machine learning: Combines many signals to identify anomalous transactions.
  • Account security: MFA, passkeys, login monitoring and secure password practices help reduce account takeover before checkout begins.

Card Present vs Card Not Present Fees

Payment pricing varies by processor, country, card type and merchant category, but card-not-present transactions often cost more to process because they carry greater fraud and dispute risk. Card-present pricing is frequently lower when a merchant uses modern in-person acceptance technology.

Merchants should compare total risk cost rather than looking only at the headline processing rate. A cheaper payment path can become expensive if it produces more fraud losses, disputes, manual reviews or false declines. The right goal is a balance of authorization rate, conversion, fraud rate and customer experience.

Examples: Card Present vs Card Not Present

Example

Classification

Why

Grocery-store chip purchase

Card present

The customer inserts a chip card into an EMV terminal.

Restaurant contactless tap

Card present

The customer taps a card or eligible wallet at the terminal.

Online clothing purchase

Card not present

The shopper enters payment details on a website checkout.

Subscription renewal

Card not present

The merchant charges a stored credential according to the agreed recurring-payment arrangement.

Telephone order

Card not present

The merchant receives payment details remotely rather than reading the physical card.

Buy online, pick up in store

Usually CNP for the online payment

The sales channel is determined by how the payment is processed, not where the goods are collected.

How Merchants Can Reduce Fraud in Both Channels

  1. Use the strongest acceptance method available. Prefer EMV chip/contactless for in-person payments and modern authenticated checkout controls for remote payments.
  2. Layer security controls. Do not rely on AVS, CVV, device reputation, PIN or any single signal by itself.
  3. Use 3D Secure strategically for ecommerce, especially where regulation, issuer risk or transaction context makes authentication valuable.
  4. Tokenize stored payment credentials and minimize exposure of raw card data.
  5. Monitor fraud and approval rates separately by channel, device, issuer region, product and customer segment.
  6. Investigate unusual fallback, manual-entry and repeated-attempt patterns.
  7. Keep POS systems, ecommerce software, plugins and payment integrations patched.
  8. Train staff and support teams to recognize social engineering, account takeover and suspicious payment behavior.
  9. Review chargeback reason codes and feed the lessons back into fraud rules.
  10. Work with the acquirer or payment processor to understand network-specific liability, 3DS and EMV rules.

Common Mistakes Merchants Make

  • Treating a CVV or AVS match as proof that the shopper is legitimate.
  • Disabling authentication solely to reduce checkout friction.
  • Using manual card entry for in-person transactions when a proper reader is available.
  • Ignoring repeated EMV fallback or suspicious terminal behavior.
  • Storing more payment data than the business actually needs.
  • Blocking every mismatch instead of using risk-based decisioning, which can create false declines.
  • Assuming liability-shift rules are identical across networks and countries.

Card Present vs Card Not Present: Which Is Better?

Neither transaction type is universally “better.” They support different customer journeys. Physical retailers need card-present acceptance, while ecommerce, subscriptions and remote services depend on CNP payments. Omnichannel businesses need both.

The correct strategy is to secure each channel according to its risk. Use EMV and secure terminals for in-person payments. Use 3D Secure, AVS, CVV, tokenization and risk analytics for online payments. Then measure approval rates, fraud, disputes and customer friction so controls can be adjusted intelligently.

Frequently Asked Questions

What is the difference between card present and card not present?

A card-present transaction uses a physical payment credential through an in-person acceptance device, while a card-not-present transaction is processed remotely, such as online, by phone or through a payment link.

Promotional banner

What is a card-not-present transaction?

A card-not-present or CNP transaction is a remote card payment in which the merchant does not read the physical card at a POS terminal.

What is a card-present transaction?

A card-present transaction is an in-person payment made through a card-reading or contactless acceptance device, such as an EMV terminal.

Why is CNP fraud higher risk?

CNP payments do not provide the same physical-card evidence as chip or contactless POS transactions, so stolen credentials can potentially be used remotely. Merchants therefore need additional identity and risk controls.

Are card-present transactions always safer?

They are generally lower risk when modern EMV technology is used, but they can still be affected by stolen cards, terminal compromise, skimming, social engineering and insecure fallback.

Who is liable for card-not-present fraud?

Merchants often carry significant CNP fraud and chargeback exposure, but qualifying 3D Secure authentication can shift certain fraud liability under applicable network rules. Exact liability varies by network, region and dispute type.

Does 3D Secure prevent all CNP fraud?

No. 3D Secure is an important authentication control, but merchants should combine it with tokenization, risk scoring, device analysis, AVS, CVV and account-security controls.

Is entering a card number manually card present?

Manual entry can be classified differently depending on the payment environment and processor rules. Merchants should not assume that typing card details at a physical location gives the same risk or liability treatment as an EMV card-present transaction.

Is a mobile wallet payment card present or card not present?

A mobile wallet used at a contactless in-person terminal can qualify as card present. A wallet or stored credential used for an online purchase is generally a remote/CNP payment flow. Classification depends on how the transaction is processed.

Why do CNP payments often cost more?

Payment providers often price CNP transactions higher because remote payments generally have greater fraud and chargeback exposure than modern card-present transactions.

Conclusion

Card present vs card not present is one of the most important distinctions in payment security. Card-present payments benefit from physical acceptance technology such as EMV chip and contactless processing. Card-not-present payments trade that physical proof for convenience and reach, so they require stronger remote authentication and fraud detection.

For merchants, the best security model is channel-aware: use EMV correctly in person, use layered CNP fraud controls online, tokenize sensitive payment data, monitor unusual behavior and understand when network liability protections apply. A secure payments program does not try to eliminate every risk signal; it combines the right signals to approve legitimate customers while making fraud more difficult and expensive.

Authoritative Sources to Cite or Verify

  • Stripe, “Card-present vs. card-not-present transactions: What businesses need to know,” updated May 11, 2026.
  • Stripe, “What are card-not-present (CNP) transactions?”, updated April 20, 2026.
  • Visa, “3D Secure: your guide to safer transactions,” Visa Protect.
  • Mastercard, Transaction Processing Rules, sections covering card-not-present ecommerce and Mastercard Identity Check.
  • PCI Security Standards Council resources for protecting payment data and securing ecommerce/payment environments.

Editorial note: Liability rules are network- and region-specific and can change. Avoid promising a universal liability shift. For merchant implementation decisions, confirm current rules with the acquiring bank, payment processor and applicable card-network documentation.