ANS-1077 · ACCOUNTING & FINANCIAL CONFIGURATION
How to Configure NetSuite for Credit Card Transactions Without CCV2?
NetSuite allows merchants to process credit card transactions without a CCV2/CSC number, offering flexibility while maintaining PCI compliance through tokenization and configurable verification rules.
Short answer
NetSuite does not store CCV2/CSC numbers for PCI compliance but allows processing transactions without them. Merchants can configure Credit Card Verification (CSC) Rules within Payment Processing Profiles to define how transactions are handled when a CCV2 is missing or invalid, balancing security with customer convenience, especially for recurring payments.
Scenario
Merchants often need to process credit card transactions where the Card Verification Value (CCV2) or Card Security Code (CSC) is not provided, particularly for recurring billing or stored card payments. Understanding how NetSuite handles these situations, including PCI compliance and configurable verification rules, is crucial for maintaining secure and efficient payment processing.
Solution
NetSuite is designed to handle credit card transactions while adhering to PCI compliance standards. The Card Verification Value (CCV2) or Card Security Code (CSC) is never stored within the merchant system. When a customer provides their CCV2 number, NetSuite uses it for the credit card verification process but does not retain it.While CCV2 is a valuable security feature against credit card fraud, its submission is not always mandatory for processing a transaction. Merchants benefit from including this information during the initial transaction as it demonstrates an extra layer of fraud protection, which can be advantageous in dispute resolution.NetSuite provides robust configuration options to manage transactions without a CCV2 number. Merchants can choose to process or refuse credit card transactions that do not include a valid CCV2.To configure these rules:
Navigate to
Setup > Accounting > Payment Processing Profiles.Edit the relevant Gateway profile.
Go to
Order Verification Settings.Access
Credit Card Verification (CSC) Rules.Within these settings, administrators can define rules for various scenarios, including when the CCV2 number doesn't match, no CCV2 number is submitted, the CCV2 is not supported by the cardholder bank, or the CCV2 service is not available. Verifying the CCV2 on the first transaction helps confirm the card's legitimacy, reducing fraud risk. For subsequent transactions with the same customer and card, re-verification of the CCV2 is typically unnecessary.It is important to note that NetSuite is allowed to store a customer's credit card number because the system stores tokenized or encrypted card numbers, not the raw Primary Account Number (PAN), ensuring PCI compliance. The absence of CCV2 verification for subsequent transactions is not a PCI compliance issue, as CCV2 verification is not universally mandatory. This decision often reflects a balance between enhanced security and customer convenience. Implementing strict CCV2 verification can provide a more secure environment but may require contacting customers for additional purchases. Conversely, a more lenient approach offers greater convenience for future orders. Ultimately, CCV2 acts as a fraud protection system, not a mechanism to ensure customer permission for every transaction.For merchants offering recurring services, such as monthly subscriptions, applying CCV2 verification on every recurring transaction is impractical. Most major credit card companies generally encourage CCV2 usage on the initial transaction but do not require it for subsequent recurring payments.
Expert NetSuite Support
Need help with this NetSuite issue?
Accounting & Financial Configuration consulting and configuration support
