Payments Glossary · Technology & Rails

Card-Present vs Card-Not-Present

Also called CP, CNP, card not present, keyed transaction, in-person vs online

Card-present means the card was physically read. Card-not-present means it wasn't. The second costs more and puts fraud liability on you.

What it is

A card-present transaction is one where the physical card was read by a terminal — tapped, dipped or swiped — with the cardholder there. Card-not-present covers everything else: online checkout, phone orders, keyed entry, invoices, recurring billing and card-on-file charges. The distinction drives two things. First, cost: CNP interchange is materially higher because the issuer is taking more fraud risk. Published rate cards show the gap plainly — PayPal prices card-present well below its virtual terminal, and Square prices in person below keyed entry; Visa's April 2026 schedule pricing Commercial Card Not Present at 2.70% + $0.10. Roughly 90 to 110 basis points is a typical spread. Second, liability. In card-present transactions, the EMV liability shift generally puts counterfeit fraud on the issuer if you dipped or tapped. In card-not-present, the merchant bears fraud liability by default. That's the entire reason 3-D Secure exists — it's the mechanism for shifting CNP liability back to the issuer.

Why it matters to your business

The split between your card-present and card-not-present volume is one of the highest-leverage numbers in your business and almost nobody knows theirs. Every point of volume you move from keyed to card-present or to a customer-completed payment link saves roughly a point of rate and removes fraud liability. For local services businesses this is especially concrete. A field technician keying a card back at the office pays CNP rates and owns the fraud risk. The same technician tapping the customer's card on a phone at the job site pays card-present rates and doesn't. Same money, same customer, different bucket.

Where it gets contested

The CNP category absorbed the fraud that EMV pushed out of physical stores, and merchants have been carrying it ever since without any corresponding rate relief. Small merchants lost an estimated 3.4% of revenue to fraud in 2025, mid-market lost 4.5% — up 40% year over year — and the true cost per dollar of fraud in US retail and eCommerce, including investigation and recovery, is around $4.61. Meanwhile only 37% of merchants use vendor-provided AI or ML fraud tools, and adoption is slipping even as losses rise. The second complaint is that many merchants are paying CNP rates unnecessarily. A restaurant taking a phone order and keying the card, a contractor collecting a deposit over the phone, a B2B seller keying from an emailed PO — all of these could often be converted to a payment link the customer completes themselves, which is cheaper, safer and eligible for 3-D Secure. The defense of higher CNP pricing is sound: the issuer genuinely can't verify who's holding the card, fraud rates are genuinely higher, and someone has to price that. The problem is that merchants aren't shown which bucket their volume falls into, so they can't manage the mix.

How to check it yourself

Ask your processor for last month's volume split between card-present, keyed and eCommerce. Then identify the largest chunk of keyed volume and ask one question: could that customer have tapped, or completed a payment link themselves? Every yes is roughly a point of rate and a fraud liability you no longer carry.

Receipts

Claims above that are checkable, with where to check them. Published so you do not have to take anyone's word for it.

  • PayPal publishes 2.29% + $0.09 card present, a higher virtual terminal rate, and 3.49% + $0.09 keyed

    paypal.com ↗
  • Square publishes 2.6% + 15¢ in person versus 3.5% + 15¢ manual entry and 3.3% + 30¢ online on the Free plan

    squareup.com ↗
  • Small merchants lost 3.4% of revenue to fraud in 2025 and mid-market lost 4.5%, up 40% YoY; true cost per $1 of fraud in US retail/eCommerce is $4.61; only 37% of merchants use vendor-provided AI/ML fraud tools

    nmi.com ↗