A card verification pattern set is the group of format and consistency rules a payment system applies to card verification data before an authorization request moves forward. It defines what a valid CVV, CVC, CVV2, CVC2, or CID value looks like, where that value is expected to appear, and how it must line up with the card number, expiration date, and service code on file.
What the pattern set covers
A pattern set is not a single check. It is a bundle of rules that a gateway, processor, or fraud engine runs in sequence, usually in milliseconds.
- Character class: digits only. Letters, spaces, and symbols fail the pattern.
- Length: three digits for most brands, four digits for American Express CID.
- Field position: the code is printed on the card, either in the signature panel or near the card number.
- Presence rules: which transaction types require the value and which may be submitted without it.
- Match rules: the submitted value must equal the value the issuer holds for that account.
The verification values behind the pattern
Card verification data comes in two families. The first is encoded on the magnetic stripe or chip and is read during a card-present transaction. The second is printed on the card itself and is typed in during a card-not-present transaction, such as an online order.
Credit Card Testing: What It Is and How Merchants Stop It
Issuers generate these values and tie them to the account. Merchants are expected to pass the value through for verification and then discard it. The pattern set is what lets a system reject a malformed or obviously mismatched value before it ever reaches the issuer.
Pattern checks versus the account number check
It helps to separate the verification pattern set from the checks applied to the primary account number.
- The account number is validated with a check-digit routine that catches transposed or mistyped digits.
- The expiration date is checked for a valid month and a date that has not passed.
- The issuer range is compared against known bank identification numbers.
- The verification value is checked for format first, then sent for a match against the issuer record.
A failure at any stage can stop the transaction before authorization.
How processors report the result
After the issuer responds, most processors return a simple result for the verification check: match, no match, not processed, or not supported. A match means the values agree. It does not mean the person submitting the transaction is the cardholder, and it does not mean the transaction is safe to approve on its own.
Why the pattern set matters for fraud control
Pattern validation removes a large volume of low-quality attempts at almost no cost. Truncated fields, wrong lengths, non-numeric entries, and repeated mismatches are all signals that a fraud model can weight. Used alongside address verification, device signals, velocity checks, and order history, the verification pattern set becomes one input in a layered decision rather than a standalone gate.
Compliance notes
Payment card industry rules treat card verification values as sensitive authentication data. Merchants and service providers are not permitted to store them after a transaction is authorized. That means the pattern set should live in the validation and routing layer, with no logging of the raw value. Audit trails should record only the result, never the data itself.
Common mistakes
- Assuming every brand uses a three-digit value.
- Treating a match result as proof of identity.
- Writing the value into application logs, error messages, or analytics events.
- Applying a single fixed pattern to all card brands instead of per-brand rules.
- Ignoring the not-processed and not-supported results, which need separate handling from a hard mismatch.