What CVV test instructions cover
CVV test instructions describe how a merchant verifies that a payment gateway handles card verification value checks before accepting real payments. You run these tests in a sandbox account using published test card numbers from your provider. You do not use real card data, and you do not need to store a CVV at any point.
Prerequisites
- A sandbox or test account with your payment gateway
- Test API keys, not live keys
- The provider's list of test card numbers and matching CVV values
- Access to your gateway response logs
Step-by-step CVV test
- Open your provider's sandbox documentation and copy the published test card numbers for your region.
- Set your integration to test mode by swapping live API keys for test keys.
- Submit a test transaction with a test card number and the CVV the provider lists for that card.
- Record the authorization response code in your QA sheet.
- Repeat the transaction with the same test card number and a wrong three-digit CVV.
- Confirm the gateway returns the CVV mismatch decline code your provider documents.
- Submit a test card that has no CVV field value and confirm the response for a missing code.
- Repeat steps three through seven for every card brand you accept.
- Compare each response against the expected result in the provider's test matrix.
- Switch back to live keys only after every case returns the expected code.
Reading the results
- A success code means the gateway accepted the transaction and the CVV matched the test card profile.
- A CVV mismatch code means your integration passes the CVV field and the issuer or simulator rejected it.
- A missing-code response means the CVV field did not reach the gateway. Check your form validation.
- An unexpected success on a wrong CVV means your test mode is off or the simulator is misconfigured.
Handling real card data
PCI DSS rules prohibit storing the CVV after authorization and require encryption in transit. Sandbox testing exists so you never need live card numbers to validate your checkout flow. Keep test card numbers, test keys, and response logs in your QA environment only.