Last Updated: 08-24-2026      

Card-Present (CP) vs. Card-Not-Present (CNP)

In payment processing, chargeback liability determines whether the merchant or the card-issuing bank bears the financial loss when a fraudulent transaction occurs.

Card-Present (CP) Chargeback Liability

Card-Present transactions occur when the physical payment card is scanned, dipped, or tapped at a physical terminal.

The EMV Liability Shift Rule

Historically, issuers held most of the fraud risk. However, with the introduction of EMV chip technology, liability shifts to the party utilizing the lesser security standard:

Card-Not-Present (CNP) Chargeback Liability

Card-Not-Present transactions cover e-commerce, phone orders, mail orders, and mobile apps where the card is not physically handled by a merchant terminal.

The Baseline Merchant Risk

By default, the merchant carries 100% of the chargeback liability for fraud in CNP environments because they cannot physically verify the cardholder's identity.

The 3D Secure (3DS) Liability Shift Exception

To mitigate this risk, merchants can use advanced digital authentication protocols like 3D Secure 2 (3DS2).

Direct Summary Matrix

Transaction Category Scenario / Protocol Implemented Party Liable for Fraud Chargebacks
Card-Present (CP) EMV Chip Card EMV-Compliant Chip Reader Card Issuer
Card-Present (CP) EMV Chip Card Swiped Magnetic Stripe Terminal Merchant
Card-Not-Present (CNP) Standard E-commerce Checkout (No 3DS Authentication) Merchant
Card-Not-Present (CNP) Successful 3D Secure (3DS / 3DS2) Authentication Card Issuer