Last Updated: 08-26-2026      

Card-Present vs Card-Not-Present

A liability shift determines whether the merchant or the card-issuing bank is financially responsible for fraudulent transactions and subsequent chargebacks. The core principle relies on technological adoption: the party supporting the less secure payment method bears the financial loss.

CP - Card-Present transactions occur when the physical payment card is scanned, dipped, or tapped at a physical terminal.

CP - Card-Not-Presenttransactions cover e-commerce, phone orders, mail orders, and mobile apps where the card is not physically handled by a merchant terminal.

Liability Shift: CP vs CNP Transactions

In face-to-face environments, the liability shift is governed by EMV (Europay, Mastercard, and Visa) chip technology. This framework protects merchants who use physical security measures at the point of sale.

The Security Standard

The standard requires reading the embedded EMV chip or accepting contactless payments (NFC) rather than relying on the legacy magnetic stripe, which is easily cloned.

Liability Allocation Rules - Liability Shift in Merchant Services

Card-Not-Present (CNP) Transactions: The 3D Secure (3DS) Shift

In e-commerce, mobile apps, and phone orders, physical cards cannot be inspected. Consequently, the baseline liability inherently rests on the merchant unless specific software protocols are deployed.

The Security Standard

The standard protocol for shifting CNP liability is 3D Secure (3DS), implemented via versions like 3DS 2.0. This authenticated protocol runs real-time risk analysis and may prompt the buyer for biometric authentication or a one-time passcode.

Liability Allocation Rules

Critical Differences Summary: CP vs. CNP

Hardware vs. Software Enforcement

CP liability shifts are bound entirely to physical POS hardware capabilities. CNP liability shifts depend completely on digital payment gateway software integrations.

Baseline Liability Default

In CP environments, a merchant who upgrades their physical terminal is heavily insulated from fraud by default. In CNP environments, the merchant remains default-liable for every transaction unless they actively pass authentication data via protocols like 3DS for that specific session.

Important Exclusions to the Liability Shift

A liability shift only protects against chargebacks categorized as unauthorized fraud (stolen card numbers or counterfeits). It provides no protection against: