Skip to content
Ready to get started, Let's Go! Talk to Sales

Glossary

Card-not-present (CNP)

Card-not-present is a transaction category in which the physical card is not read by the merchant (eCommerce checkouts, phone and mail orders, and recurring billing), making the merchant responsible for verifying the cardholder remotely.

Any transaction where the card number is entered rather than read is card-not-present: an online checkout, a saved card charged for a subscription renewal, a phone order keyed into a virtual terminal. CNP is where eCommerce lives, and where most card fraud lives, because a stolen card number is enough to attempt a purchase.

The economics and the risk

The networks price the risk in. CNP interchange rates run meaningfully higher than card-present rates (often half a percentage point or more on the same card), and fraud liability sits with the merchant by default: if a cardholder claims a CNP charge was unauthorized, the resulting chargeback is generally the merchant’s loss unless liability shifted. The defensive toolkit is what separates well-run CNP operations from loss-makers: AVS checks the billing address against the issuer’s records, CVV proves the buyer had the physical card details, 3-D Secure authenticates the cardholder and shifts fraud liability to the issuer, and velocity rules and fraud scoring catch card-testing attacks before they run up authorization fees.

Recurring billing adds its own CNP problems: cards expire and get reissued, so account-updater services and network tokens exist to keep subscriptions alive without asking customers to re-enter details.

Why it matters

For online-first businesses, CNP capability is the processor evaluation: authorization rates on clean traffic, quality of fraud tooling, AVS/CVV/3DS support, and how stored credentials are tokenized and kept current. Small differences in approval rates compound: a point of authorization rate on $1 million a month is $10,000 in revenue.

QorPay processes CNP transactions on QorCommerce with AVS, CVV, 3-D Secure, and tokenized credential storage, alongside its card-present and ACH capabilities.