9F60

CVC3 (Track1)

CVC3 (Track1) is the track 1 counterpart to the CVC3 (Track2) already covered in this dictionary (9F61): the same dynamic, per-transaction verification value, computed for Kernel 2's mag-stripe-mode contactless flow, but folded into the track 1 discretionary data instead of track 2's. Related to 9F6A (which the card also uses in the same mag-stripe flow) alongside 9F61, it exists because some host systems built for legacy magnetic-stripe processing read both tracks rather than just one, and a mag-stripe-mode contactless transaction needs to give each of those host paths the dynamic protection it expects, in the exact data location each one already knows how to parse. Because it mirrors 9F61's role so closely, the two are best understood as a pair rather than as independent fields: a terminal or host validating one but not the other has left half of the intended replay protection unchecked, which is a much easier gap to miss than a single obviously-missing field would be. See EMV Contactless Book C-2.

Interactive decoder

Paste a hex value for this tag to decode it in your browser. Nothing is sent anywhere.

Binary (2): 5D2E

This tag is not a bitmap; the decoder shows a format-based interpretation.

Decoded example

Example value: 5D2E

Related tags

Properties

Tag9F60
NameCVC3 (Track1)
FormatBinary
Length2 bytes
SourceCard (ICC)
Templates77
BooksEMV Contactless Book C-2

Frequently asked questions

What is EMV tag 9F60?
CVC3 (Track1) is the track 1 counterpart to the CVC3 (Track2) already covered in this dictionary (9F61): the same dynamic, per-transaction verification value, computed for Kernel 2's mag-stripe-mode contactless flow, but folded into the track 1 discretionary data instead of track 2's. Related to 9F6A (which the card also uses in the same mag-stripe flow) alongside 9F61, it exists because some host systems built for legacy magnetic-stripe processing read both tracks rather than just one, and a mag-stripe-mode contactless transaction needs to give each of those host paths the dynamic protection it expects, in the exact data location each one already knows how to parse. Because it mirrors 9F61's role so closely, the two are best understood as a pair rather than as independent fields: a terminal or host validating one but not the other has left half of the intended replay protection unchecked, which is a much easier gap to miss than a single obviously-missing field would be. See EMV Contactless Book C-2.
What format and length does EMV tag 9F60 use?
Tag 9F60 uses the Binary format and is normally 2 bytes long.
Is tag 9F60 provided by the card or the terminal?
Tag 9F60 (CVC3 (Track1)) is provided by the Card (ICC).

Sources

  • C-2-Kernel-2-V2.11-Final-June-2023, p. 368

Receive site updates

Subscribe to receive site updates directly to your email

We won't send spam. You can unsubscribe at any time.