PCI DSS

PCI DSS 6.4.3 and 11.6.1: payment page script controls explained

Two PCI DSS v4 requirements target attacks that skim card data from payment pages in the browser. Here is what each asks for, who it applies to and what assessors want to see.

Short answer

PCI DSS requirement 6.4.3 requires every script on a payment page to be authorised, integrity-checked and inventoried with a justification. Requirement 11.6.1 requires a mechanism that detects unauthorised changes to the page's security-impacting HTTP headers and script contents as received by the browser. Both became mandatory on 31 March 2025.

Key takeaways

  • 6.4.3 is about knowing and approving every script; 11.6.1 is about detecting changes.
  • Both apply to scripts as the customer's browser receives them, including third-party scripts.
  • Since 31 March 2025 they are removed from SAQ A, replaced by an eligibility criterion.
  • They still apply under SAQ A-EP, SAQ D and a Report on Compliance.

Why these requirements exist

E-skimming attacks inject or modify JavaScript on a payment page so card data is copied to an attacker as the customer types. The server can be untouched; the attack happens in the browser. Requirements 6.4.3 and 11.6.1, introduced in PCI DSS v4 as future-dated requirements, target exactly this.

What each requirement asks for

6.4.311.6.1
GoalOnly authorised, unaltered scripts runUnauthorised changes are detected
CoversAll scripts loaded and executed on the payment pageSecurity-impacting HTTP headers and script contents as received by the browser
Must showAuthorisation method, integrity method, inventory with written justificationA change- and tamper-detection mechanism that alerts personnel
FrequencyOngoingAt least weekly, or as set by a targeted risk analysis

Who they apply to

In January 2025 the PCI Security Standards Council removed 6.4.3 and 11.6.1 from SAQ A, effective 31 March 2025, and replaced them with an eligibility criterion: merchants must confirm their site is not susceptible to attacks from scripts that could affect their e-commerce systems. The requirements remain in the standard and apply under SAQ A-EP, SAQ D and Reports on Compliance. The Council has since revised related guidance, so check the current FAQs before deciding which applies to you.

Checklist

Evidence for 6.4.3 and 11.6.1

0 of 7 done

Common gaps assessors find

  • The inventory lists scripts on the checkout page but misses those loaded by tag managers.
  • A content security policy exists but reports only, and nobody reviews the reports.
  • Monitoring watches the server copy of the page, not what the browser receives.

Frequently asked questions

Do PCI DSS 6.4.3 and 11.6.1 apply to SAQ A merchants?

Not as line items since 31 March 2025. They were removed from SAQ A and replaced with an eligibility criterion that the merchant's site is not susceptible to script attacks. They still apply under SAQ A-EP, SAQ D and Reports on Compliance.

Sources

  1. Important updates announced for merchants validating to Self-Assessment Questionnaire A, PCI Security Standards Council
  2. Big changes for SAQ A: 2025 updates for 6.4.3 and 11.6.1, SecurityMetrics