Home / Companies / Basis Theory / Blog / Post Details
Content Deep Dive

Payment Page Security: Embracing PCI 6.4.3 and 11.6.1

Blog post from Basis Theory

Post Details
Company
Date Published
Author
Basis Theory
Word Count
872
Company Posts That Month
7
Language
English
Hacker News Points
-
Post removed?
No
Summary

PCI DSS 4.0 requirements 6.4.3 and 11.6.1 became mandatory at the end of March 2025 to reduce e-skimming threats such as Magecart, which can steal payment data through compromised third-party resources or injected scripts. Requirement 6.4.3 calls for an inventory of payment-page scripts, documented authorization and justification for each, and integrity verification, while 11.6.1 requires monitoring and alerts for unauthorized payment-page changes. The guidance highlights Subresource Integrity (SRI) and Content Security Policy (CSP) as relevant web standards, and states that Basis Theory provides published JavaScript-library hashes for SRI and CSP-based reporting for its Elements customers. Organizations must apply comparable controls to all other third-party scripts, with removing unnecessary resources presented as a way to reduce attack surface. SAQ A merchants are exempt from the specific requirements but must attest that their e-commerce systems are not vulnerable to script-based attacks.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.