Card Present vs. Card Not Present Transactions Explained
Visa's own schedule prices a card-present debit sale at 0.80% and the identical card online at 1.65%. Here is why the gap exists and what to do.
By Gray Merchants Team

- Visa's published April 2026 schedule prices a consumer check card from an exempt issuer at 0.80% plus $0.15 for card-present retail against 1.65% plus $0.15 for card not present, more than double the percentage rate on the identical card.
- Keying a card at your own counter is priced like e-commerce, not like a swipe. CPS/Retail Key Entry runs 1.65% plus $0.15, so the discount is really for electronic authentication rather than physical presence.
- For debit from issuers with $10 billion or more in assets, Regulation II caps interchange at 0.05% plus $0.21 regardless of channel, so card-present and card-not-present cost the same on regulated debit.
- EMV closed the card-present authentication gap by generating a one-time code per transaction, but it does nothing online, where the merchant only ever sees static reusable data.
- The Federal Reserve found chip adoption from 2015 to 2016 accompanied falling in-person fraud alongside rising remote fraud, with remote going from 48.0% to 61.1% of card fraud by value in one year. The Fed says accompanied, not caused, and has published no equivalent comparison since.
- 3D Secure is the card-not-present counterpart and shifts fraud liability to the issuer when authentication succeeds. The EU mandates it under PSD2 while the US leaves it to merchant discretion.
- Card-not-present businesses face stricter underwriting and more reserves because the acquiring bank carries the loss on disputes, and dispute volume is structurally higher without point-of-sale identity verification.
The card-present vs card-not-present distinction is the single biggest driver of what a sale costs you to process. A card-present transaction is one where the physical card is at the point of sale and gets dipped, tapped, or swiped. A card-not-present transaction is everything else: online, over the phone, by mail order, or through a stored card on file. The difference costs you real money on every sale, and you can see exactly how much in Visa's own published rates.
The Price Gap, Straight From Visa's Schedule
Visa publishes its full US interchange schedule as a public document. The current edition is dated April 18, 2026. Here's what it lists for a consumer check card from an exempt issuer (Visa, 2026):
| Program | Rate |
|---|---|
| CPS/Retail (card present) | 0.80% + $0.15 |
| CPS/Card Not Present | 1.65% + $0.15 |
| CPS/e-Commerce Basic | 1.65% + $0.15 |
| CPS/e-Commerce Preferred Retail | 1.60% + $0.15 |
Same card. Same issuer. More than double the percentage rate depending on how the sale happened. On a $100 transaction that's about $0.95 in the store against about $1.80 online.
That gap is not your processor marking you up. It's interchange, set by the network and paid to the card-issuing bank, and it exists because the two channels carry genuinely different fraud risk.
The Detail That Surprises Retailers
Look at one more line from the same schedule: CPS/Retail Key Entry, Debit runs 1.65% + $0.15.
That's a transaction where the card is physically in front of you and your staff typed the number in instead of dipping it. It costs the same as a pure e-commerce sale.
So the discount isn't really for the card being present. It's for the card being electronically authenticated at the moment of sale. A chip read proves the card is genuine. A typed number proves nothing, whether the customer is standing in front of you or calling from another state.
If your terminal is unreliable and staff key transactions to get through a queue, that habit is costing you roughly double the interchange on every keyed sale. It's one of the cheapest things to fix in a retail operation.
Regulated Debit Ignores the Channel Entirely
Here's a wrinkle worth knowing, because it changes the calculus depending on your customer base.
For debit cards from covered issuers, Regulation II caps interchange at $0.21 plus 0.05 percent of the transaction, plus a $0.01 fraud-prevention adjustment where eligible (Federal Reserve). Covered issuers are banks with $10 billion or more in assets.
Visa's schedule reflects that. Every regulated line, card present or card not present, reads 0.05% + $0.21. The channel makes no difference at all.
So the card-present advantage only shows up on exempt debit and on credit. When a customer pays with a debit card from a large bank, your cost is the same whether they're in the store or on your website. That's a Durbin artifact, not a network judgment about risk, and it means the size of your card-present savings depends partly on which banks your customers use.
Why the Fraud Risk Actually Differs
The underlying reason is authentication, and the dividing line is EMV.
An EMV chip generates a one-time code for every transaction, so copied data can't be reused to clone a card. That's why counterfeit fraud collapsed once chip terminals became standard, and it's covered in more depth in our guide to what EMV is. Globally, the overwhelming majority of card-based transactions now run on EMV chip.
None of that helps online. In a card-not-present sale there is no chip to interrogate. The merchant has a number, an expiry date, a security code, and an address, all of which are static data that can be stolen and reused. That's the entire problem in one sentence.
The October 2015 US liability shift is where this became visible in the data. The Federal Reserve's last standalone payments fraud study found that accelerated adoption of chip authentication from 2015 to 2016 accompanied a reduction in the value of in-person card fraud, but that this reduction occurred alongside an increase in the value of remote card fraud (Federal Reserve, 2018).
The share numbers make it concrete. In 2015, remote fraud was less than half of all card payments fraud by value at 48.0%. By 2016 most fraudulent card payments by value were remote, at 61.1%, while most legitimate payments by value were still in person. That's a crossover in a single year.
Worth being careful about the causal claim, since the Fed was. It says the two things accompanied each other, not that one caused the other. The honest reading is that chip adoption made card-present fraud much harder while remote fraud kept climbing, and the balance tipped. Anyone telling you EMV simply pushed fraud online is stating more than the data does.
Also worth flagging: that study covers 2016. The Fed has not published an equivalent standalone card-present versus card-not-present fraud comparison since, so anyone quoting you a current federal figure for this is quoting a decade-old one.
What Closes the Gap Online
Since you can't put a chip in a web form, the card-not-present channel needs different tools.
3D Secure is the closest equivalent. It authenticates the cardholder with their issuing bank before authorization, and a successfully authenticated transaction generally shifts fraud liability to the issuer. Visa reports that authenticated transactions show roughly a 45% reduction in fraud, at 11 basis points against 20 basis points for non-authenticated e-commerce, and a 9% lift in authorization approval rates (Visa). Treat those as Visa's own numbers for Visa's own product, but they're network-published rather than vendor marketing.
In the EU, Strong Customer Authentication under PSD2 has been mandatory since September 2019 (European Commission, 2019). The US has no equivalent mandate, so American merchants choose whether and when to use it.
AVS and CVV checks are the baseline. They're weak on their own and strong as filters.
Tokenization protects stored card data, which matters enormously for recurring billing where you hold credentials on file.
Qualifying for better CNP programs is worth real money. Notice from the table above that CPS/e-Commerce Preferred Retail prices below CPS/e-Commerce Basic. Preferred programs carry qualification requirements, and the schedule itself doesn't spell them out, so this is a question for your processor rather than something you can look up. Most merchants never ask which program their transactions actually hit.
Why Underwriting Treats You Differently
If you're a card-not-present business, your merchant account application gets read differently, and it's not arbitrary.
The acquiring bank carries the loss if you fail and disputes come in. A CNP business has higher expected dispute volume, no in-person identity verification at the point of sale, and often ships goods after the payment clears. That combination is why CNP merchants more often see reserves, lower initial limits, or placement in high risk categories.
It also raises the stakes on your dispute rate, since disputes are measured against your merchant ID and monitored by programs that don't care why your channel is riskier.
What to Actually Do About It
- Stop keying cards that could be dipped. Same-day fix, roughly halves interchange on those sales.
- Ask your processor which CNP interchange programs you qualify for, and what data you'd need to send to reach the cheaper ones.
- Run AVS and CVV on every CNP sale, and decline mismatches on higher-value orders.
- Consider 3D Secure selectively on large or first-time orders rather than across the board, so you get the liability shift where it matters without the checkout friction everywhere.
- Fix your billing descriptor. A recognizable name prevents the disputes that CNP businesses accumulate simply from customers not recognizing a charge.
If you run both channels, price them separately in your own accounting. Blending them hides the fact that your online sales may be carrying a materially different cost and dispute profile than your counter sales.
Frequently Asked Questions
Why do online transactions cost more to process?
Because interchange is priced by risk and there's no chip to authenticate the card. Visa's published schedule prices card-present debit at 0.80% and card-not-present at 1.65% for the same exempt-issuer card.
Is a keyed transaction card present or card not present?
For pricing purposes it's treated like card not present. Visa's CPS/Retail Key Entry debit rate is 1.65% + $0.15, the same as e-commerce, even though the card is physically there.
Does EMV protect my online sales?
No. EMV proves a physical card is genuine at the point of sale. Online you need different tools, primarily 3D Secure for authentication and tokenization for protecting stored card data.
Do card-present and card-not-present cost the same on debit?
For debit from large regulated issuers, yes. Regulation II caps that interchange regardless of channel, so both read 0.05% + $0.21. The gap only appears on exempt debit and on credit.
Am I liable for fraud on card-not-present sales?
Usually yes, unless you authenticated the transaction through 3D Secure and it qualified for the liability shift. That's the main reason to use it.
Can I reduce my card-not-present interchange?
Sometimes. Better CNP programs price lower than basic ones and have data qualification requirements. Ask your processor which you currently hit and what would move you up.
Why is my e-commerce merchant account harder to get approved?
Because the acquiring bank carries the loss on disputes, and card-not-present businesses statistically generate more of them. That's also why reserves are more common on CNP accounts.
Running card-not-present volume and paying for it twice, in rates and in disputes? Apply free for a 24 to 48 hour decision, or talk to a specialist about which interchange programs your transactions should be hitting.
Gray Merchants Team
Gray Merchants is a payment ISO that places merchant accounts across every risk level, from low-risk retail and e-commerce to 67+ high-risk verticals. The editorial team writes on high-risk merchant accounts, chargeback defense, MATCH/TMF remediation, and ACH processing, whether you are new, scaling, switching processors, or rebuilding after a decline.