8 Steps to Cut CNP Risk for Merchants: Card Present vs Card Not Present
8 Steps to Cut CNP Risk for Merchants: Card Present vs Card Not Present

Card-present (CP) transactions happen when a physical card gets tapped, swiped, or dipped in front of the customer, verified through EMV chip technology. Card-not-present (CNP) transactions happen remotely, online, by phone, or through a stored card on file, without that physical verification step. The practical fallout: CNP carries higher fraud exposure, wider fee ranges, and liability rules that usually favor issuers over merchants unless tools like EMV and 3-D Secure are in play.
TL;DR:
- CNP transactions face significantly higher fraud risks due to online testing of stolen card data and often carry higher fees and liability for merchants.
- Fraud prevention tools like 3-D Secure, tokenization, AVS, and behavioral analytics work best when layered, with passive signals screening initial risk and active challenges reserved for high-risk cases.
- Recurring billing remains classified as CNP regardless of initial payment method, so fraud exposure and liability follow the stored card or account.
- Proper hardware, software, and process updates, such as current EMV terminals and enforced AVS/CVV checks, are critical to reducing liability and fraud in both CP and CNP transactions.
- Integrating risk scoring across all transactions and using a single, orchestrated approach helps merchants minimize losses and maintain smooth conversion without unnecessary friction.
Table of Contents
- Card Present vs Card Not Present: The Side-by-Side Breakdown
- Why Is Card-Not-Present Fraud So Much Higher?
- What Controls Actually Prevent Card-Not-Present Fraud?
- Operational Checklist for Accepting Both Payment Types
- How Merchant Solutions Corp Supports CP and CNP Acceptance
- The Real Competitive Edge in Payment Security
- Get Payment Processing Built for CP and CNP Risk
- Where to Learn More About CNP Standards and Fraud Data
- Sources
- FAQ
Card Present vs Card Not Present: The Side-by-Side Breakdown
The gap between these two transaction types isn’t academic. It determines who eats the cost when something goes wrong, and how much you pay just to accept the payment in the first place.
| Factor | Card Present (CP) | Card Not Present (CNP) |
|---|---|---|
| Card & cardholder present | Yes, physically at terminal | No, remote channel |
| Verification method | EMV chip, PIN, tap | AVS, CVV, 3-D Secure, tokenization |
| Common fraud types | Counterfeit cards, stolen physical cards | Credential stuffing, phishing, account takeover |
| Relative fraud risk | Lower | Higher |
| Typical fee range | Generally lower for card-present transactions | Generally higher for card-not-present transactions |
| Chargeback liability | Often shifts to issuer with EMV | Merchant liable unless 3DS authenticates |
| Typical use cases | Retail counters, restaurants, kiosks | Ecommerce, phone orders, recurring billing |
| PCI implications | Terminal and network scope | Broader scope unless tokenized |
A few things jump out once you look at this side by side:
- Recurring billing and subscriptions stay classified as CNP even if the first payment was taken in person, so the fraud exposure follows the card on file, not the original sale.
- Buy-online-pickup-in-store (BOPIS) orders are technically CNP at checkout, but they introduce a second verification moment at pickup that many merchants skip.
- Fee ranges above are just that. Your actual rate depends on industry classification, processing volume, and risk profile.
- A single high-ticket CNP order can carry more fraud risk than a full day of CP counter sales.
Why Is Card-Not-Present Fraud So Much Higher?
CNP fraud has scaled fast alongside ecommerce growth. Juniper Research projected retailers would lose roughly $130 billion to digital CNP fraud between 2018 and 2023, a scale that reflects how much easier it is to test stolen card data online than to walk it into a store.
Statistic Callout: Industry data cited by the U.S. Payments Forum shows CNP fraud losses climbing into the tens of billions annually, a direct result of card data theft outpacing the physical fraud that EMV chips have largely shut down.
Fraudsters lean on a handful of repeatable attack patterns:
- Credential stuffing — testing stolen username and password combinations against checkout pages.
- Phishing — tricking cardholders into handing over card details directly.
- Account takeover — hijacking an existing customer profile with saved payment methods.
- Friendly fraud — legitimate cardholders disputing charges they actually made.
- Automated bot attacks — scripts testing thousands of card numbers for validity in minutes.
Liability mechanics shape who absorbs these losses. EMV adoption shifted most in-person counterfeit-card liability to whichever party didn’t support chip technology. Online, 3-D Secure works similarly: when a transaction is authenticated through 3DS and the issuer approves it, liability for that dispute typically shifts away from the merchant. Skip 3DS, and you’re often on the hook regardless of fault. That reality directly affects your reserve requirements, chargeback ratios, and how underwriters price your account.
What Controls Actually Prevent Card-Not-Present Fraud?
Merchants have more tools available than most realize, and stacking them correctly matters more than picking just one.
3-D Secure, especially the newer 3DS2 protocol, adds an authentication layer between the cardholder and issuer. It also tends to improve conversion versus older 3DS versions because it uses richer device signals to approve legitimate customers without an extra challenge step.
AVS (Address Verification Service) and CVV checks confirm billing details and the card’s security code. Neither is bulletproof on its own. Stolen data dumps frequently include both, so treat them as one layer, not a complete defense.
Tokenization replaces stored card numbers with unusable substitute tokens, which shrinks your PCI DSS scope and limits what a breach actually exposes.
Passive tools, device fingerprinting, behavioral analytics, and velocity checks, screen transactions quietly in the background. Active challenges (OTP codes, 3DS prompts) add friction but stronger proof. The trade-off is real: too many active challenges drive up false declines and cost you legitimate sales.
- Gateway-level: tokenization, AVS/CVV rules
- PSP-level: fraud scoring, velocity checks
- Issuer-level: 3DS authentication decisions
Pro Tip: Layer passive screening first and reserve active challenges for transactions that actually score as high risk. Challenging every customer at checkout is the fastest way to lose sales to cart abandonment.
Operational Checklist for Accepting Both Payment Types
Turning these controls into daily practice takes a short, repeatable list rather than a one-time setup.
- Keep EMV terminals current with firmware updates. Outdated firmware quietly reopens fraud liability you thought you’d shifted.
- Enable 3DS for higher-risk online categories, big-ticket items, first-time customers, international shipping addresses.
- Require AVS and CVV matching on CNP transactions, and flag mismatches for review instead of auto-declining.
- Tokenize every card-on-file setup, especially for recurring billing.
- Use clear, recognizable transaction descriptors on statements. Vague descriptors are a leading cause of avoidable “friendly fraud” disputes.
- For BOPIS orders, verify pickup with photo ID or a single-use pickup code, and hold orders rather than releasing them on request alone. A documented partial-payment and pickup policy gives staff a consistent script to follow.
- Set automated alerts for velocity spikes, multiple failed attempts, rapid-fire orders, unusual ticket sizes.
- Reconcile transactions promptly and keep authentication logs on hand as chargeback evidence.
Pro Tip: A dual-pricing or cash-discount program can offset the fee gap between CP and CNP acceptance without you absorbing the difference quietly in your margins.
How Merchant Solutions Corp Supports CP and CNP Acceptance
Putting this checklist into practice usually means upgrading hardware, software, and processing setup at the same time. Merchantsolutionscorp equips merchants with EMV-ready terminals for in-person acceptance and eCommerce gateway integrations built for tokenized, 3DS-capable online checkout.
- EMV terminals and mobile card readers for counter and curbside sales
- Tokenized card-on-file processing for recurring billing
- Payment links and self-serve kiosks for hybrid CP/CNP flows
- POS integrations built for BOPIS and pickup verification
- Industry-specific setups for high-risk and specialty merchants
Merchants weighing new hardware or a gateway upgrade can review current POS system options or explore ecommerce payment integrations built around these same controls.
The Real Competitive Edge in Payment Security
Most merchants treat CP and CNP fraud tools as separate problems. That’s backwards. The merchants who actually cut losses run one orchestration layer that scores every transaction by risk first, then escalates to 3DS or manual review only when warranted. Passive signals do the heavy lifting; active challenges stay reserved for genuine outliers. The edge isn’t a single tool. It’s clean, consistent transaction data that makes every one of those decisions sharper over time.
— Jonathan
Get Payment Processing Built for CP and CNP Risk
Handling both transaction types well takes hardware and software configured for your actual risk mix, not a generic setup pulled off a shelf. Merchantsolutionscorp is the alternative to piecing together separate vendors for terminals, gateways, and fraud tools. One provider handles EMV-ready POS hardware, tokenized online checkout, and industry-specific configurations for high-risk categories, all under a single onboarding process.
- Get a quote and see your setup mapped out: start with payment processing
Merchants running BOPIS, recurring billing, or high-ticket ecommerce orders can request a tailored review of which controls, 3DS, tokenization, AVS rules, fit their specific transaction mix before signing anything.
Where to Learn More About CNP Standards and Fraud Data
- U.S. Payments Forum CNP mitigation white paper: the fullest catalog of CNP mitigation techniques available.
- Checkout.com’s liability shift explainer: clear breakdown of how EMV and 3DS move chargeback liability.
- Nexiant’s CNP fraud prevention guide: practical detail on tokenization and 3DS2 conversion effects.
- Tapix’s CP vs CNP deep dive: practitioner-level comparison of fraud rates and fee shape.
Sources
FAQ
What Is the Main Difference Between CP and CNP?
Card-present transactions involve a physical card verified at a terminal, usually through EMV chip technology, while card-not-present transactions happen remotely with no physical card check, which raises fraud risk and typically raises fees.
Does 3-D Secure Guarantee Liability Protection?
Not automatically. 3-D Secure shifts liability toward the issuer when a transaction is authenticated and approved through the protocol, but unauthenticated CNP transactions typically leave the merchant liable for disputes.
Is a Recurring Billing Charge CP or CNP?
Recurring and card-on-file charges are classified as CNP for every billing cycle after the first, even if that initial payment happened in person.
How Can Merchants Lower CNP Fraud Without Hurting Conversion?
Layering passive tools, tokenization, AVS/CVV checks, and device signals, ahead of active challenges like 3DS keeps friction low for legitimate customers while still catching high-risk transactions. Merchantsolutionscorp builds these layered controls into its ecommerce payment integrations.