Skip to main content
Tessera
Requirements Free check Terms
PCI DSS reference

PCI DSS 6.4.3 payment-page script inventory template

Download a practical CSV inventory for recording each payment-page script, its owner, authorization decision, business justification, integrity-assurance method, evidence reference and review date.

Standard: PCI DSS v4.0.1 requirement 6.4.3. This is a plain-language reference, not legal advice, and it does not determine your PCI DSS compliance or which questionnaire applies to you. Your acquiring bank sets your reporting obligations.

The short checklist

  1. Create one row for every script loaded and executed on each in-scope payment page.
  2. Name an accountable owner and record an explicit authorization decision.
  3. Write the business or technical justification rather than relying on a vendor name.
  4. Record the integrity-assurance method and a reviewable evidence reference.

What the template records

The downloadable CSV separates observed facts from human decisions. Page URL, script source and host identify what was seen. Owner, authorization status and justification record why it belongs. Integrity method, evidence reference, reviewer, review time and change ticket make the decision reviewable later. Replace the example row; do not treat it as evidence.

  • Use a stable absolute script source where possible.
  • Identify tag-manager children as separate scripts, not one opaque container.
  • Use authorized, rejected or pending-review consistently.
  • Link to evidence your assessor can actually access and retain.

How to populate it without overstating the scan

Tessera's free check can download the script elements present in served HTML as CSV or JSON. That gives you a starting inventory, not an authorization decision and not a complete browser execution trace. Add runtime-observed scripts from browser tooling or another approved process, then have the accountable owner complete the decision columns.

Keep it current

An inventory is useful only when it follows changes. Make updating the row part of the same approval that adds, removes or changes a script. Preserve the old decision with the change record, re-run the bounded check, and review the page again after tag-manager or payment-provider changes.

Primary source

Read the source rather than a summary of it, including this one: PCI DSS v4.0.1, requirement 6.4.3 — https://www.pcisecuritystandards.org/document_library/?class=pcidss&doc=pci_dss.

What the free check can and cannot tell you

The free check reads the HTML your server returns. It inventories script elements and observed integrity attributes, but it does not inspect HTTP response headers or fetch remote script bytes. Live 11.6.1 monitoring separately fingerprints selected response headers and referenced script contents. The free check does not run the page in a browser, and neither does live monitoring. A script injected at runtime by another script is outside what Tessera can see, and no static check can tell you whether a script is authorized — only you know that.

Reviewed August 2026. The standard and the questionnaires change; confirm against the current text before relying on anything here.

Download the 6.4.3 script inventory CSV template

Build a served-HTML inventory from your payment page

Preview the synthetic 6.4.3 remediation pack before deciding whether the paid artifact fits your review.

Related

  • SAQ A embedded payment forms: the script-security confirmation
  • PCI DSS 6.4.3: managing the scripts on your payment page
  • PCI DSS 11.6.1: change and tamper detection on payment pages
  • PCI DSS 5.4.1: anti-phishing controls and your sending domain
Tessera
Independent software from Toledo Technologies LLC.
Terms Privacy Refunds