Requirements 6.4.3 and 11.6.1 were removed from SAQ A on 31 March 2025 and an eligibility criterion was added for merchant pages with embedded processor forms—not redirects. What that confirmation asks and how PCI SSC says it can be supported.
PCI SSC FAQ 1588 and PCI DSS v4.0.1 SAQ A r1
The authorization, integrity-assurance and inventory obligations for every script loaded and executed in the consumer's browser, as a working checklist.
PCI DSS v4.0.1 requirement 6.4.3
Download a practical CSV inventory for recording each payment-page script, its owner, authorization decision, business justification, integrity-assurance method, evidence reference and review date.
PCI DSS v4.0.1 requirement 6.4.3
What the change-detection mechanism has to evaluate, how often it has to run, and why an unbroken record of late checks does not satisfy the requirement.
PCI DSS v4.0.1 requirement 11.6.1
The technical half of 5.4.1 is stopping people from sending mail as you. What SPF, DKIM and DMARC have to look like before that claim holds.
PCI DSS v4.0.1 requirement 5.4.1
SAQ A, A-EP or D depends on how payment data reaches the processor. Since March 2025, an SAQ A merchant embedding a processor form also has a script-security eligibility criterion; redirect and fully outsourced flows do not.
PCI DSS v4.0.1 self-assessment questionnaires