Questions? Talk to a real person

Card-Not-Present (CNP) Transactions: What They Are & How They Work

Card-not-present (CNP) transactions are payments made using a customer’s card details without a physical card being presented to the merchant. This includes online purchases, phone orders, recurring subscriptions, and invoices paid remotely. Because the card isn’t available for verification, merchants face different costs, fraud risks, and compliance requirements than they would with in-person payments.

Those risks are only growing: industry reports show that card-not-present fraud continues to rise as eCommerce expands, making it one of the most common forms of payment fraud. Knowing how to accept CNP payments effectively, without driving up costs or absorbing losses, is essential for any business. We’ll go over everything you need to know about CNP transactions, including what they are, how they work, and why they matter for your business.

Key Takeaways

  • CNP transactions are riskier and more prone to fraud than card-present transactions. Consequently, processing rates for CNP transactions are typically higher due to the associated security risks.
  • Card-present fraud liability can vary based on EMV and network rules, while merchants typically bear liability for fraudulent CNP chargebacks unless protections apply.
  • Because of their riskier nature, CNP merchants must adhere to strict compliance requirements, including PCI DSS, and implement authentication protocols such as encryption and tokenization.

What Is a Card-Not-Present (CNP) Transaction?

A card-not-present transaction is a payment transaction where a physical payment card is not presented to the merchant at the time of purchase. The transaction is handled on the backend the same way as traditional credit card processing. Still, the payment is completed remotely—such as online, over the phone, or via invoice, by entering card details or using stored payment credentials.

Examples of CNP Transactions

Some common examples of card-not-present transactions include:

  • eCommerce. When a customer places an order on a website or an online store and pays for it by entering their card information online.
  • Mail order. When a customer fills out a form, enters their payment information, and mails it to the business to place the order.
  • Phone order. When a customer places an order over the phone and shares their payment information with the store associate.
  • Subscription or recurring payments. When a customer signs up for a subscription or membership (e.g., a gym membership or magazine subscription), they provide their billing information to be stored in the merchant’s system. Thereafter, automatic payments are deducted at previously agreed-upon intervals.
  • Invoices. When a customer pays for an invoice using their previously stored billing details or a payment link from the merchant.

Card-Present vs Card-Not-Present Transactions

The main difference between card-present (CP) and card-not-present (CNP) transactions is that in CP transactions, a physical payment card (or a digital wallet on a smartphone or other mobile device) is present to the merchant and interacts with a payment terminal via swipe, tap, or dip.

However, in a CNP transaction, no physical card is presented to the merchant. Since card information is entered remotely, CNP transactions are riskier and more prone to fraud than CP transactions. Consequently, underlying interchange costs and total processing expenses for CNP transactions are often higher because of increased fraud risk.

FeatureCard-Present (CP) TransactionsCard-Not-Present (CNP) Transactions
How payment is madeSwipe (magstripe), dip (EMV chip), or tap (NFC/contactless).Card details are entered manually online, over the phone, or via invoice/payment link.
Common environmentsRetail stores, restaurants, in-person events, and pop-ups.eCommerce websites, phone orders, recurring billing, and mail orders.
Authentication methodEMV chip validation, contactless tokenization, sometimes PIN or signature.CVV, AVS (address verification), 3D Secure, and tokenization.
Fraud risk levelLower fraud risk through physical card interactions and chip security.Higher fraud risk due to the card not being physically verified.

How Much Do CNP Transactions Cost?

According to official card network fee schedules, there isn’t a single published “card-not-present (CNP) cost.” Still, the underlying interchange fees set by Visa and Mastercard show that CNP transactions typically carry higher interchange fees than card-present transactions due to increased fraud risk and the lack of chip verification.

For example, Visa’s published interchange reimbursement fee schedule includes distinct rates for CNP transactions (often above 2% of the transaction value plus a fixed amount) that acquirers pay to the issuing bank, forming the baseline cost that merchants indirectly incur when accepting online or keyed-in payments.

An analysis of Visa’s interchange reimbursement fees in 2026 shows that card-not-present interchange rates are typically 10 to 70 basis points (0.10% to 0.70%) higher than comparable card-present transactions, with premium rewards cards and non-qualified transactions often carrying the largest increases.

Similarly, Mastercard’s card-not-present transactions typically carry interchange rates that are about 0.3% to 1.0% higher, according to its 2026 interchange bulletin

While the exact difference varies by card type, merchant category, and transaction details, the takeaway is clear: accepting card-not-present payments generally costs more than accepting in-person payments. To learn more about how these fees work and what you can do to reduce them, check out our guides on credit card processing fees and how to reduce credit card processing fees.

What Are The Hidden Fraud Risks Behind CNP Transactions?

Card-not-present fraud losses in the US are projected to reach $12.87 billion by 2026, according to a Mastercard report. As online and remote payments become increasingly common, fraudsters have more opportunities to exploit stolen card data, and unfortunately, it’s typically the merchants who bear the chargeback liability.

CNP fraud occurs when a fraudster gains access to a cardholder’s payment information, such as their card number, expiry date, CVV/CVC, etc., and uses it to make unauthorized purchases. Fraudsters may obtain such access through data breaches, phishing attacks, malware, and other unscrupulous means.

Beyond chargebacks and lost revenue, elevated fraud rates can also create challenges with your payment processor:

  • Rolling reserves and held funds: Payment processors may withhold a percentage of your revenue as a reserve to offset potential chargeback losses if your fraud or chargeback rates increase.
  • MATCH list exposure: Merchants with consistently high chargeback ratios risk being added to the MATCH list, an industry database that can make it difficult to obtain a new merchant account for up to five years.

Compliance and Security for CNP Merchants

Because of their riskier nature, CNP merchants must adhere to the following compliance requirements:

  • PCI Compliance. Any merchant who processes, stores, or transmits card data must comply with the Payment Card Industry Data Security Standard (PCI DSS). As part of this, they may need to complete an annual Self-Assessment Questionnaire (SAQ) and an Attestation of Compliance (AOC). In addition, they should not store any sensitive data after authorization, such as CVV/CVC codes.
  • AVS. Merchants should use an address verification service (AVS) to verify whether the customer-entered billing address matches the one registered with the issuing bank.
  • CVV/CVC. Merchants should also verify card security codes during CNP transactions to confirm that the user actually possesses the card.
  • 3D Secure. 3D Secure (3DS) is an authentication protocol from Visa, Mastercard, and other networks that verifies the cardholder’s identity at checkout, often through a one-time passcode or biometric prompt. It’s highly recommended that merchants processing CNP transactions implement 3D Secure authentication to add an additional layer of identity verification.
  • Encryption and tokenization. Merchants must ensure that all payment data is encrypted before transmission, and that sensitive data is replaced with unique “tokens” when stored.

How to Accept CNP Payments in Your Business

To accept card-not-present payments, merchants typically need a payment gateway or processor that can handle remote transactions. These systems allow businesses to collect card details through online checkout pages, virtual terminals, invoicing tools, or recurring billing platforms. Once a gateway or payment platform is set up, merchants can accept CNP payments through several channels and implement security measures such as AVS checks, CVV verification, encryption, and tokenization to help reduce the risk of fraud.

Online

  • To accept CNP payments online, merchants need to set up a payment gateway and integrate it with their website or eCommerce platform. The gateway provides a secure checkout page where customers can enter their payment details and complete a purchase.
  • To reduce fraud risk, capture key billing information, such as the card number, expiration date, billing address, and CVV, during checkout. Address Verification Service (AVS) checks can help confirm that the customer-entered billing address matches the one on file with the issuing bank. Fraudsters are less likely to have access to all billing details associated with a legitimate cardholder account, which can help weed out fraudulent transactions to some extent.

Over the Phone

  • To accept CNP payments over the phone, merchants typically use a virtual terminal provided by their payment processor or gateway. A virtual terminal allows staff to manually enter a customer’s card details into a secure interface while speaking with them.
  • For security, merchants should follow PCI DSS guidelines when handling card information, verify billing details such as address and CVV, and use secure systems to prevent the improper storage of card data.

Subscription & Recurring Billing

  • To accept recurring CNP payments, merchants need a subscription billing platform or a recurring billing feature within their payment gateway. Customers provide their payment details once, and the system automatically charges the card at scheduled intervals.
  • To protect customer data, merchants should rely on tokenization and encrypted storage through their payment provider, rather than storing raw card numbers themselves. 
  • Merchants can accept CNP payments by sending digital invoices or payment links through their payment gateway or invoicing software. These links direct customers to a secure payment page where they can enter their card details and complete the transaction.
  • For security, merchants should ensure that payment pages use an encrypted connection and that invoices or payment links are sent only through trusted channels, such as email or SMS. Capturing billing details and using verification tools such as AVS can help confirm the payer’s identity.

Card-not-present payments are evolving quickly as payment networks and technology providers introduce new tools to reduce fraud and improve authorization rates. Here are some of the trends and developments to watch:

Network tokenization. This replaces raw card numbers with secure tokens issued by card networks. These tokens reduce the impact of data breaches and help improve approval rates for recurring or stored-credential transactions.

AI-based risk scoring. Modern payment systems can analyze hundreds of signals in real time, including device data, transaction patterns, purchase history, and behavioral indicators. 

Biometric verification. This includes fingerprint or facial recognition through digital wallets and banking apps. Such solutions add another layer of identity confirmation without creating friction for customers.

Intelligent payment routing. These systems automatically route transactions through the optimal processor or network path to increase approval rates and lower processing costs.

Together, these innovations aim to make CNP payments more secure and efficient, helping merchants reduce fraud risk while maintaining a smooth checkout experience for customers.

Final Thoughts on CNP Payments

For most businesses, card-not-present payments are simply part of doing business. Online sales, subscriptions, invoices, and phone orders all rely on CNP transactions.

While they come with higher costs and fraud risks than in-person payments, those challenges can be managed with the right tools and processes. Successful merchants don’t avoid CNP transactions. They use safeguards such as AVS, CVV verification, tokenization, and 3D Secure to reduce fraud, limit chargebacks, and protect customer data. 

For businesses that process CNP payments, Kurv’s suite of payment tools, including payment gateways, virtual terminals, invoicing, and recurring billing solutions, supports remote payments with built-in fraud prevention and compliance features.

Ready to Grow Your Business?

Apply and start accepting payments within a day

Google Ratings

Frequently Asked Questions

Are all online payments card-not-present?

Yes, online payments are typically classified as card-not-present (CNP) transactions because the card is not physically presented to the merchant at checkout. This includes eCommerce, invoices, and keyed transactions, even if added security tools are applied.

Why are CNP processing fees higher?

CNP fees are higher due to increased fraud risk. Without chip verification or in-person interaction, CNP transactions have fewer verification signals and greater chargeback exposure, which often contributes to higher processing costs.

Is a digital wallet transaction card-not-present?

In-store wallet taps are card-present. Online wallet payments are CNP, though typically lower risk.

How can merchants lower CNP rates?

Use AVS, CVV, 3D Secure, tokenization, accurate data submission, and maintain low chargebacks to improve pricing.

What evidence is required to dispute a CNP chargeback?

When it comes to chargeback disputes, merchants typically need proof of authorization, transaction details, billing information, delivery confirmation, and customer communications.

Randall Hayashi

Chief Operating Officer, Kurv

Randall Hayashi, Chief Operating Officer of Kurv, brings 20+ years of experience in operations and strategy, with a track record of scaling startups and managing over $3B in annual payment processing volume. Hayashi focuses on optimizing organi…

More author’s articles →