Payments glossary · Core

Card-Not-Present (CNP)

A card-not-present (CNP) transaction is a card payment made without the physical card being presented to a terminal, such as an online or in-app purchase, a phone or mail order, or a recurring charge to a stored card.

How Card-Not-Present works

Because the merchant cannot read the chip or ask for a PIN, CNP payments rely on the card number, expiry date and security code, details that can be stolen and reused. That makes CNP transactions attractive to fraudsters, and issuers and acquirers treat them as higher risk. By default the merchant bears the cost of fraudulent CNP transactions through chargebacks, unless the payment was authenticated in a way that shifts liability to the issuer.

The main protections are 3-D Secure authentication, which is also how CNP card payments meet strong customer authentication rules in the EEA and UK; network tokens and correct flagging of stored-card payments; address and security-code checks; and fraud screening. Mail and telephone orders fall outside SCA but cannot use 3-D Secure, so merchants carry more of the risk on them.

CNP status also affects costs and monitoring. In some markets interchange is higher for CNP payments than for in-person ones, and card schemes watch CNP fraud and dispute levels closely: Visa's Acquirer Monitoring Program, for example, counts fraud reports and disputes on card-not-present transactions. Merchants selling online should expect providers to ask about fraud controls, delivery times and refund policies during onboarding.

Compare providers

Related terms

Sources

  1. EMVCo: EMV 3-D Secure
  2. Visa: Visa Acquirer Monitoring Program fact sheet (2025)

← All payments terms