Short answer
A CVV test for PCI DSS checks if a system stores, logs, or transmits card verification values. PCI DSS v4.0 Requirement 3.3.1 states that sensitive authentication data is not stored after authorization. CVV2, CVC2, CVV, and CID are part of sensitive authentication data. A system that passes does not keep the 3-digit or 4-digit value in any form: plaintext, encrypted, hashed, or inside a log file.
What counts as sensitive authentication data
- Full magnetic stripe data, track 1 and track 2.
- Card verification value: CVV2 (Visa), CVC2 (Mastercard), CID (American Express), CVV (Discover).
- PIN and PIN block.
The PAN is not sensitive authentication data. The PAN can be stored if it is protected under Requirements 3.4 and 3.5.
What Requirement 3.3.1 says
PCI DSS v4.0 Requirement 3.3.1 prohibits storage of sensitive authentication data after authorization. The rule applies when the data is encrypted. One exception exists. Issuers and companies that support issuing services may store sensitive authentication data if they have a documented business need. That path adds Requirements 3.3.1.1, 3.3.1.2, and 3.3.1.3 for encryption, key management, and access control.
Version 3.2.1 used the same rule under Requirement 3.2. The numbering changed. The scope did not.
How a CVV storage test is run
- Map every system that touches an authorization request: checkout code, payment gateway, order database, call recording, help desk ticket, and application logs.
- Search for the field name and for patterns. Look for cvv, cvc, cvv2, and cid, and for 3-digit or 4-digit values next to a PAN.
- Review database schemas, column names, and backup files.
- Review log output from the authorization path. Requirement 3.3.1 covers logs and files, not just database tables.
- Check call recordings and agent notes. A spoken CVV that is recorded counts as stored data.
- Confirm the value is dropped from memory after the authorization response.
Test environments versus live data
Sandbox and certification environments use test PANs supplied by the card brands. A test PAN does not carry a live CVV. Testers set an arbitrary 3-digit value, and that value has no link to a real account. Live PANs and live CVVs do not belong in a test environment. PCI DSS Requirement 6.4.3 and the scoping rules in Requirement 12.5.2 cover this separation.
Evidence an assessor will ask for
- Data flow diagram of the authorization path.
- Query output showing no CVV column or row exists.
- Log samples from the same path.
- Code review notes for the checkout and gateway integration.
- Penetration test report under Requirement 11.3.
- Quarterly ASV scan reports under Requirement 11.3.2.
Common failure points
Typical causes are debug logging left on, an order table that captures the full request body, a call center that records the whole call, and a support tool that stores ticket text. Each one fails Requirement 3.3.1 even when the production database is clean.
Frequency
PCI DSS requires an annual assessment. Requirement 12.5.2 requires a review of scope at least every 12 months and after a change to the cardholder data environment. A CVV storage test belongs in the annual cycle and in the change process.