Short answer

In the Worldpay test environment the CVV field takes any 3-digit value on a valid test card. Worldpay's own examples use 123. The sandbox does not send the CVV to an issuer, so a match or mismatch result does not come from a real card.

Test values Worldpay documents

  • Card number 4444333322221111 (Visa test PAN)
  • Card number 5555555555554444 (Mastercard test PAN)
  • Expiry: any future date, for example 01/2039
  • CVV: 123

Worldpay revises the test card list from time to time. Check the test data page in your Worldpay developer account before you run a suite. Copies on third-party sites go stale.

What the sandbox checks

The test gateway validates structure, not cardholder identity. It checks four items:

  • The PAN passes the Luhn check and matches a listed test card.
  • The expiry is a valid future date.
  • The CVV holds 3 digits for Visa and Mastercard, 4 for American Express.
  • Amount and currency sit inside the limits set on the test merchant code.

CVV response codes

Live issuers return a CVV result with the authorization. Standard codes are M (match), N (no match), P (not processed), U (unknown), S (not present on the card) and I (invalid). In the sandbox these values come from the test card setup, not from a check at a bank. Some Worldpay test cards map to a fixed CVV result so you can test your handling of N or U.

PCI rules that cover CVV

PCI DSS Requirement 3.2 bars storage of sensitive authentication data after authorization. CVV2, CVC2 and CID fall in that group. The rule covers test data too, because the same code path handles test and live traffic. Store the CVV result code if you need it for dispute records. Do not store the CVV value.

Common errors

  • Wrong digit count. American Express test cards take a 4-digit CID.
  • CVV field sent on a card-on-file or recurring transaction. Card schemes do not allow that.
  • Expiry date in the past. Test cards still reject it.
  • Test PAN from an old list. The gateway returns a card-not-supported error.

Known limits

The sandbox cannot confirm live behavior. A live CVV check runs at the issuer, and the result travels back in the authorization response. No processor can read or return the CVV of a real card. Sources that offer CVV data for live cards are describing stolen data, not test data.