Short answer
PCI DSS requirement 6.4.3 requires every script on a payment page to be authorised, integrity-checked and inventoried with a justification. Requirement 11.6.1 requires a mechanism that detects unauthorised changes to the page's security-impacting HTTP headers and script contents as received by the browser. Both became mandatory on 31 March 2025.
Key takeaways
- 6.4.3 is about knowing and approving every script; 11.6.1 is about detecting changes.
- Both apply to scripts as the customer's browser receives them, including third-party scripts.
- Since 31 March 2025 they are removed from SAQ A, replaced by an eligibility criterion.
- They still apply under SAQ A-EP, SAQ D and a Report on Compliance.
Why these requirements exist
E-skimming attacks inject or modify JavaScript on a payment page so card data is copied to an attacker as the customer types. The server can be untouched; the attack happens in the browser. Requirements 6.4.3 and 11.6.1, introduced in PCI DSS v4 as future-dated requirements, target exactly this.
What each requirement asks for
| 6.4.3 | 11.6.1 | |
|---|---|---|
| Goal | Only authorised, unaltered scripts run | Unauthorised changes are detected |
| Covers | All scripts loaded and executed on the payment page | Security-impacting HTTP headers and script contents as received by the browser |
| Must show | Authorisation method, integrity method, inventory with written justification | A change- and tamper-detection mechanism that alerts personnel |
| Frequency | Ongoing | At least weekly, or as set by a targeted risk analysis |
Who they apply to
In January 2025 the PCI Security Standards Council removed 6.4.3 and 11.6.1 from SAQ A, effective 31 March 2025, and replaced them with an eligibility criterion: merchants must confirm their site is not susceptible to attacks from scripts that could affect their e-commerce systems. The requirements remain in the standard and apply under SAQ A-EP, SAQ D and Reports on Compliance. The Council has since revised related guidance, so check the current FAQs before deciding which applies to you.
Checklist
Evidence for 6.4.3 and 11.6.1
0 of 7 done
Common gaps assessors find
- The inventory lists scripts on the checkout page but misses those loaded by tag managers.
- A content security policy exists but reports only, and nobody reviews the reports.
- Monitoring watches the server copy of the page, not what the browser receives.
Frequently asked questions
Do PCI DSS 6.4.3 and 11.6.1 apply to SAQ A merchants?
Not as line items since 31 March 2025. They were removed from SAQ A and replaced with an eligibility criterion that the merchant's site is not susceptible to script attacks. They still apply under SAQ A-EP, SAQ D and Reports on Compliance.
Sources
- Important updates announced for merchants validating to Self-Assessment Questionnaire A, PCI Security Standards Council
- Big changes for SAQ A: 2025 updates for 6.4.3 and 11.6.1, SecurityMetrics