PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

PCI DSS Requirement 6.4.3 — Payment page script management

Requirement 6.4.3 targets digital skimming (Magecart-style attacks). Every script that loads in the consumer's browser on a payment page must be there deliberately, must be protected against unauthorised modification, and must be recorded in a written inventory with a business justification.Timing: Future-dated requirement in PCI DSS v4.0 — mandatory for all assessments since 31 March 2025.

Who it applies to

E-commerce merchants whose own website delivers or assembles any part of the payment page
Service providers that host or deliver payment page content on behalf of merchants

What Requirement 6.4.3 asks for

Paraphrased from PCI DSS v4.0.1. Read the standard itself for the authoritative wording and testing procedures.

Maintain a method to confirm each script loaded on the payment page is authorised.
Maintain a method to assure the integrity of each script — for example subresource integrity, a content security policy, or a change-detection mechanism.
Maintain a written inventory of all scripts on the payment page with a documented business justification for each one.

Evidence an assessor expects

A current script inventory listing every first-party and third-party script on the payment page, its owner and its justification
The technical control that enforces authorisation and integrity (CSP header, SRI hashes, tag-manager allowlist, or monitoring tool output)
Change-management records showing new scripts are reviewed and approved before release
Evidence the inventory is reviewed when the payment page changes

Common mistakes

Treating a tag manager as the inventory. The tag manager is a delivery mechanism; the inventory is a reviewed document.
Listing only third-party scripts. First-party scripts are in scope too.
Assuming SAQ A removes the obligation. SAQ A v4.0.1 carries its own script criterion, and SAQ A-EP includes 6.4.3 in full.

Not sure whether Requirement 6.4.3 is in your scope?

Which requirements you must answer depends on the SAQ that applies to your environment. The free SAQ selector walks the official PCI SSC decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Paraphrased from PCI DSS v4.0.1 (PCI Security Standards Council). Independent summary; not endorsed by PCI SSC. Refer to the PCI SSC Document Library for the authoritative standard.