9F61
CVC3 (Track2)CVC3 (Track2) is a dynamic, per-transaction verification value computed specifically for the magnetic-stripe-mode contactless flow of Kernel 2 - its entire purpose is to give a mag-stripe-style transaction some of the replay resistance that chip transactions get from the Application Cryptogram (9F26), since a plain, static magnetic-stripe track doesn't have anything equivalent on its own. It's related to the Track 2 the card supplies in this mode (9F60, referenced alongside it) and to a further tag (9F6B) that supplies additional track data for the same flow, together forming the mag-stripe-mode data set Kernel 2 assembles instead of a full chip-mode template. Like tag 56, this is a Kernel 2 (Mastercard PayPass) tag specifically - it exists because PayPass supports a mag-stripe-compatible contactless mode as well as a full qVSDC chip-equivalent mode, and CVC3 is what makes the weaker of those two modes still meaningfully harder to clone than a genuine, static magnetic stripe. A terminal or host that treats a CVC3-protected mag-stripe-mode transaction as having no dynamic protection at all is underestimating exactly the security property this tag was added to provide. See EMV Contactless Book C-2.
Interactive decoder
Paste a hex value for this tag to decode it in your browser. Nothing is sent anywhere.
Binary (2): 3C7A
This tag is not a bitmap; the decoder shows a format-based interpretation.
Decoded example
Example value: 3C7A
Properties
| Tag | 9F61 |
|---|---|
| Name | CVC3 (Track2) |
| Format | Binary |
| Length | 2 bytes |
| Source | Card (ICC) |
| Templates | 77 |
| Books | EMV Contactless Book C-2 |
Frequently asked questions
- What is EMV tag 9F61?
- CVC3 (Track2) is a dynamic, per-transaction verification value computed specifically for the magnetic-stripe-mode contactless flow of Kernel 2 - its entire purpose is to give a mag-stripe-style transaction some of the replay resistance that chip transactions get from the Application Cryptogram (9F26), since a plain, static magnetic-stripe track doesn't have anything equivalent on its own. It's related to the Track 2 the card supplies in this mode (9F60, referenced alongside it) and to a further tag (9F6B) that supplies additional track data for the same flow, together forming the mag-stripe-mode data set Kernel 2 assembles instead of a full chip-mode template. Like tag 56, this is a Kernel 2 (Mastercard PayPass) tag specifically - it exists because PayPass supports a mag-stripe-compatible contactless mode as well as a full qVSDC chip-equivalent mode, and CVC3 is what makes the weaker of those two modes still meaningfully harder to clone than a genuine, static magnetic stripe. A terminal or host that treats a CVC3-protected mag-stripe-mode transaction as having no dynamic protection at all is underestimating exactly the security property this tag was added to provide. See EMV Contactless Book C-2.
- What format and length does EMV tag 9F61 use?
- Tag 9F61 uses the Binary format and is normally 2 bytes long.
- Is tag 9F61 provided by the card or the terminal?
- Tag 9F61 (CVC3 (Track2)) is provided by the Card (ICC).
Sources
- C-2-Kernel-2-V2.11-Final-June-2023, p. 368
Receive site updates
Subscribe to receive site updates directly to your email
We won't send spam. You can unsubscribe at any time.