PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

PCI DSS Requirement 11.6.1 — Payment page change and tamper detection

Requirement 11.6.1 is the detective control that pairs with 6.4.3. A mechanism must alert personnel when the HTTP headers or the content of the payment page as received by the consumer browser are modified without authorisation, and it must be evaluated at least once every seven days.Timing: Future-dated requirement in PCI DSS v4.0 — mandatory for all assessments since 31 March 2025.

Who it applies to

E-commerce merchants whose payment page is delivered or assembled by their own systems
Service providers responsible for payment page delivery

What Requirement 11.6.1 asks for

Paraphrased from PCI DSS v4.0.1. Read the standard itself for the authoritative wording and testing procedures.

Deploy a change- and tamper-detection mechanism for the payment page as received by the consumer browser.
Alert personnel to unauthorised modification of HTTP headers and page content.
Evaluate the payment page at least weekly, or at a frequency defined by a documented targeted risk analysis.

Evidence an assessor expects

Configuration of the detection mechanism showing the payment pages it monitors
Sample alerts and the ticket trail showing they were investigated
Evidence of the evaluation frequency — weekly, or a completed targeted risk analysis supporting a different interval
A defined list of the personnel who receive and action alerts

Common mistakes

Monitoring the server-side file system only. The requirement is about the page as the consumer's browser receives it.
Deploying detection with no alert routing or investigation record.
Using a risk-based frequency without the documented targeted risk analysis to support it.

Not sure whether Requirement 11.6.1 is in your scope?

Which requirements you must answer depends on the SAQ that applies to your environment. The free SAQ selector walks the official PCI SSC decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Paraphrased from PCI DSS v4.0.1 (PCI Security Standards Council). Independent summary; not endorsed by PCI SSC. Refer to the PCI SSC Document Library for the authoritative standard.