PCI DSS v4.0.1

The client-side requirements, explained plainly

Requirements 6.4.3, 11.6.1 and 5.4.1 govern the scripts running on your payment page and the mail sent as your domain. This is what each one asks for, what changed for SAQ A merchants on 31 March 2025, and a free check you can run against your own page.

One correction worth reading first. Requirements 6.4.3 and 11.6.1 were removed from SAQ A on 31 March 2025. PCI SSC FAQ 1588 says the replacement script-security eligibility criterion applies when a processor payment form is embedded in the merchant page; it does not apply to processor redirects or fully outsourced payment flows. If you are about to sign that confirmation, start here.

SAQ A embedded payment forms: the script-security confirmation

Requirements 6.4.3 and 11.6.1 were removed from SAQ A on 31 March 2025 and an eligibility criterion was added for merchant pages with embedded processor forms—not redirects. What that confirmation asks and how PCI SSC says it can be supported.

PCI SSC FAQ 1588 and PCI DSS v4.0.1 SAQ A r1

PCI DSS 6.4.3 payment-page script inventory template

Download a practical CSV inventory for recording each payment-page script, its owner, authorization decision, business justification, integrity-assurance method, evidence reference and review date.

PCI DSS v4.0.1 requirement 6.4.3

Which PCI SAQ applies to an e-commerce site?

SAQ A, A-EP or D depends on how payment data reaches the processor. Since March 2025, an SAQ A merchant embedding a processor form also has a script-security eligibility criterion; redirect and fully outsourced flows do not.

PCI DSS v4.0.1 self-assessment questionnaires

Check your own page, free

The check lists script elements present in the served HTML, flags those served from a domain you have not authorized, and shows which have no observed integrity attribute. No account, and you can paste your page source instead of giving us a URL if the page sits behind a login.

The free check reads served HTML but does not inspect response headers or fetch remote script bytes. Live 11.6.1 monitoring adds those observations. Neither path runs the page in a browser, and only you can decide whether a script is authorized.

Run the free check