ISO 8583 Parser
online lookup

ISO 8583 DE22 POS / PAN Entry Mode Decoder

These three digits set the security tier of the transaction — which drives both the interchange rate and who eats the fraud.

05
Digits 1–2 · PAN entry mode
Chip (ICC), CVV reliable
1
Digit 3 · PIN entry capability
PIN entry capable
CodeMeaning
00Unknown
01Manual key entry
02Magnetic stripe read
03Bar code
04OCR
05Chip (ICC), CVV reliable
07Contactless chip (EMV)
10Credential on file
80Fallback from chip to magnetic stripe
81E-commerce
90Magnetic stripe, full track read
91Contactless magnetic stripe
95Chip, CVV/iCVV unreliable
CodeMeaning
0Unspecified
1PIN entry capable
2Not PIN entry capable
8Reserved
9Capable but PIN not used this time

It matters more than it looks

The first two digits of DE22 say how the card number got in: swiped, dipped, keyed, tapped, or entered online with no card present. The third says whether the terminal can take a PIN.

Those digits map directly onto two things that cost real money: the interchange tier (more secure entry modes generally price lower) and fraud liability. For the same disputed transaction, a chip read and a keyed entry can land liability on opposite parties.

Two values worth watching

80 (fallback from chip to magstripe) means the card has a chip but reading it failed, so the terminal fell back to the stripe. This is a classic fraud technique — a counterfeit card carries a deliberately dead chip to force the fallback. Risk engines usually tighten rules on fallback transactions, and many issuers decline cross-border fallbacks outright.

95 (chip present but CVV unreliable) deserves the same attention: the data came from a chip, but the verification value cannot be trusted, so treat the risk as closer to a magstripe transaction than a chip one.

A common scenario: the cardholder insists they inserted the card, yet the transaction was processed as magstripe and priced wrong. Check DE22 — if it reads 80, the terminal failed to read the chip and fell back. The problem is at the terminal or the card, not the issuer.

Three characters or twelve, and it changes what you are reading

DE22 is n-3 in the 1987 edition of ISO 8583 — two digits of PAN entry mode plus one of PIN entry capability, which is what the decoder above expects. From the 1993 edition the field is an-12 and is called the point of service data code: twelve characters carrying twelve separate subfields, of which the card-reading method is only one.

Both are in use at once. Authorization messages are 1987-format, so a three-character DE22 is what you see on the authorization leg. Clearing records are 1993-format, so the same transaction carries the twelve-character version there. A value that looks malformed is often the other edition read with the wrong expectation rather than bad data.

The consequence for triage: you cannot compare a DE22 from an authorization log with a DE22 from a clearing file position by position. The reading method is in the first two characters of the short form and at a different offset in the long one. Every value in both forms, and which reading shifts fraud liability, is in POS entry mode codes.

Blocked at work? This table and 13 other tools also come as self-contained HTML files that run from your disk, with no network at all — for the machines that cannot reach this site. Offline edition, US$39 one-time.