The short checklist
- Create one row for every script loaded and executed on each in-scope payment page.
- Name an accountable owner and record an explicit authorization decision.
- Write the business or technical justification rather than relying on a vendor name.
- Record the integrity-assurance method and a reviewable evidence reference.
What the template records
The downloadable CSV separates observed facts from human decisions. Page URL, script source and host identify what was seen. Owner, authorization status and justification record why it belongs. Integrity method, evidence reference, reviewer, review time and change ticket make the decision reviewable later. Replace the example row; do not treat it as evidence.
- Use a stable absolute script source where possible.
- Identify tag-manager children as separate scripts, not one opaque container.
- Use authorized, rejected or pending-review consistently.
- Link to evidence your assessor can actually access and retain.
How to populate it without overstating the scan
Tessera's free check can download the script elements present in served HTML as CSV or JSON. That gives you a starting inventory, not an authorization decision and not a complete browser execution trace. Add runtime-observed scripts from browser tooling or another approved process, then have the accountable owner complete the decision columns.
Keep it current
An inventory is useful only when it follows changes. Make updating the row part of the same approval that adds, removes or changes a script. Preserve the old decision with the change record, re-run the bounded check, and review the page again after tag-manager or payment-provider changes.
Primary source
Read the source rather than a summary of it, including this one: PCI DSS v4.0.1, requirement 6.4.3 — https://www.pcisecuritystandards.org/document_library/?class=pcidss&doc=pci_dss.
What the free check can and cannot tell you
Reviewed August 2026. The standard and the questionnaires change; confirm against the current text before relying on anything here.
Download the 6.4.3 script inventory CSV template
Build a served-HTML inventory from your payment page
Preview the synthetic 6.4.3 remediation pack before deciding whether the paid artifact fits your review.