What Does a CVV Length Test Check?

A CVV length test checks that the card security code field accepts the right number of digits for each card network and rejects everything else. Visa, Mastercard, and Discover use 3 digits. American Express uses 4. A pass means the field blocks 2 digits, blocks letters or symbols, and blocks a 5th digit on a 3-digit card.

read more

The test covers the input element, the validation rule, and the error message the shopper sees. It runs in the browser or the app, before anything reaches the payment gateway.

more on this topic

How Many Digits Does Each Card Network Use?

Three is the default. American Express is the exception that trips most builds.

cvv length test for compliance

  • Visa: 3 digits (CVV2)
  • Mastercard: 3 digits (CVC2)
  • Discover: 3 digits (CID)
  • American Express: 4 digits (CID), printed on the front above the card number
  • Diners Club and JCB: 3 digits
  • UnionPay: 3 digits

Card networks set these lengths and they do not change per issuer or per country. A 4-digit code on a Visa is not an Amex code in disguise. It is a typo or a paste error.

CVV Length Test Success: A Guide to Buying CVV Online

Which HTML Attributes Control CVV Length?

Five attributes cover the field.

  • maxlength="4" caps typing at four characters, which keeps 3-digit codes valid and stops a 5th digit.
  • inputmode="numeric" opens the number pad on phones.
  • autocomplete="cc-csc" lets browsers and password managers fill the code.
  • pattern="[0-9]*" rejects letters on browsers that honor patterns.
  • aria-describedby points screen readers at your error text.

Use type="text", not type="number". Number inputs add spinner arrows, accept the letter e, and strip leading zeros on some browsers. A code like 077 is valid and a number field can eat the 0.

Do not lean on maxlength by itself. It stops typed input but not pasted text in every browser, so validate the value on submit too.

Test Cases for the CVV Field

Run this list in Chrome, Safari, Firefox, and one mobile browser.

  1. Submit an empty field. Expect a clear error, not a silent failure.
  2. Enter 1 digit and 2 digits. Expect rejection.
  3. Enter 3 digits on a Visa test card. Expect acceptance.
  4. Enter 4 digits on a Visa test card. Expect rejection or an inline warning.
  5. Enter 4 digits on an Amex test card (starts 34 or 37). Expect acceptance.
  6. Type letters such as abc. Expect them to be blocked or flagged.
  7. Type symbols, a space, or a hyphen. Expect rejection after trim.
  8. Paste "1 2 3" and "123 ". Expect the same result as clean input.
  9. Autofill from a password manager. Check that the value lands in the field and passes validation.
  10. Enter 000 and 099. Expect acceptance, since leading zeros are valid.
  11. Toggle the mask. Confirm the digits are readable when revealed.
  12. Submit on a slow connection. Confirm the button state stops double posts.

Edge Cases That Break CVV Length Checks

Most CVV bugs come from the same short list.

  • Whitespace: trim before you measure length, or "123 " fails as 4 characters.
  • Leading zeros: store the value as a string. Numbers drop the 0 and shrink the length.
  • Full-width digits: Japanese and Chinese keyboards can send full-width characters that look like digits and fail a numeric check.
  • Card type changes: a shopper types 3 digits, then swaps to an Amex. The field must allow a 4th digit after the swap.
  • Zoom: at 200% zoom on a small screen, a fixed-width field can hide the 4th digit.
  • Screen readers: an error that only changes border color is invisible. Announce it in text.

Should the UI Infer the Card Type?

You can guess the network from the first digits of the card number. Amex starts with 34 or 37, so a 4-digit limit is safe once you see that prefix.

The safer default is to allow 3 or 4 characters in the field and enforce the exact length at submit. Shoppers who fix a typo in the card number do not get stuck with a field that refuses the 4th digit.

If you do infer, recheck on every keystroke in the card number field. A stale inference causes the bug where the 4th digit will not type.

Why the CVV Is Never Stored

PCI DSS treats the CVV as sensitive authentication data. It cannot be stored after authorization, even encrypted, which means the length check is the only check your system gets.

That rule shapes the UI. Do not log the field value, do not cache it in local storage, and clear it after the form posts. A length test that writes the code into an analytics event breaks the standard.

FAQ

Is a CVV always 3 digits?

No. Visa, Mastercard, Discover, JCB, and UnionPay use 3 digits. American Express uses 4. Build for both and you will not break on Amex orders.

Should the CVV field use type="number"?

No. type="number" adds spinners, allows e and +, and can strip a leading zero. Use type="text" with inputmode="numeric" and a pattern check.

Does the CVV use the Luhn algorithm?

No. Luhn checks the card number. The CVV has no check digit, so length plus numeric-only is the full client-side rule.

How do I test CVV length without a live card?

Use the test card numbers your payment provider publishes in its sandbox. Amex test numbers start with 34 or 37, which lets you exercise the 4-digit path.