9F61

CVC3 (Track2)

CVC3 (Track2) is a dynamic, per-transaction verification value computed specifically for the magnetic-stripe-mode contactless flow of Kernel 2 - its entire purpose is to give a mag-stripe-style transaction some of the replay resistance that chip transactions get from the Application Cryptogram (9F26), since a plain, static magnetic-stripe track doesn't have anything equivalent on its own. It's related to the Track 2 the card supplies in this mode (9F60, referenced alongside it) and to a further tag (9F6B) that supplies additional track data for the same flow, together forming the mag-stripe-mode data set Kernel 2 assembles instead of a full chip-mode template. Like tag 56, this is a Kernel 2 (Mastercard PayPass) tag specifically - it exists because PayPass supports a mag-stripe-compatible contactless mode as well as a full qVSDC chip-equivalent mode, and CVC3 is what makes the weaker of those two modes still meaningfully harder to clone than a genuine, static magnetic stripe. A terminal or host that treats a CVC3-protected mag-stripe-mode transaction as having no dynamic protection at all is underestimating exactly the security property this tag was added to provide. See EMV Contactless Book C-2.

Interactive decoder

Paste a hex value for this tag to decode it in your browser. Nothing is sent anywhere.

Binary (2): 3C7A

This tag is not a bitmap; the decoder shows a format-based interpretation.

Decoded example

Example value: 3C7A

Related tags

Properties

Tag9F61
NameCVC3 (Track2)
FormatBinary
Length2 bytes
SourceCard (ICC)
Templates77
BooksEMV Contactless Book C-2

Frequently asked questions

What is EMV tag 9F61?
CVC3 (Track2) is a dynamic, per-transaction verification value computed specifically for the magnetic-stripe-mode contactless flow of Kernel 2 - its entire purpose is to give a mag-stripe-style transaction some of the replay resistance that chip transactions get from the Application Cryptogram (9F26), since a plain, static magnetic-stripe track doesn't have anything equivalent on its own. It's related to the Track 2 the card supplies in this mode (9F60, referenced alongside it) and to a further tag (9F6B) that supplies additional track data for the same flow, together forming the mag-stripe-mode data set Kernel 2 assembles instead of a full chip-mode template. Like tag 56, this is a Kernel 2 (Mastercard PayPass) tag specifically - it exists because PayPass supports a mag-stripe-compatible contactless mode as well as a full qVSDC chip-equivalent mode, and CVC3 is what makes the weaker of those two modes still meaningfully harder to clone than a genuine, static magnetic stripe. A terminal or host that treats a CVC3-protected mag-stripe-mode transaction as having no dynamic protection at all is underestimating exactly the security property this tag was added to provide. See EMV Contactless Book C-2.
What format and length does EMV tag 9F61 use?
Tag 9F61 uses the Binary format and is normally 2 bytes long.
Is tag 9F61 provided by the card or the terminal?
Tag 9F61 (CVC3 (Track2)) is provided by the Card (ICC).

Sources

  • C-2-Kernel-2-V2.11-Final-June-2023, p. 368

Receive site updates

Subscribe to receive site updates directly to your email

We won't send spam. You can unsubscribe at any time.