CyberSecurityBoardThreat Intel · CVEs · Products
Cyber Certifications

PCI DSS v4.0.1: New Requirements for Payment Page Script Security

June 25, 2026

PCI DSS v4.0.1 introduced requirements 6.4.3 and 11.6.1, mandating that merchants inventory, authorize, and verify the integrity of all scripts on payment pages, and detect tampering with page content and HTTP headers. These requirements address web skimming and Magecart attacks, with SAQ A merchants needing to prove their sites are not susceptible to script attacks.