Payment Page Security: Embracing PCI 6.4.3 and 11.6.1
Blog post from Basis Theory
PCI DSS 4.0 requirements 6.4.3 and 11.6.1 became mandatory at the end of March 2025 to reduce e-skimming threats such as Magecart, which can steal payment data through compromised third-party resources or injected scripts. Requirement 6.4.3 calls for an inventory of payment-page scripts, documented authorization and justification for each, and integrity verification, while 11.6.1 requires monitoring and alerts for unauthorized payment-page changes. The guidance highlights Subresource Integrity (SRI) and Content Security Policy (CSP) as relevant web standards, and states that Basis Theory provides published JavaScript-library hashes for SRI and CSP-based reporting for its Elements customers. Organizations must apply comparable controls to all other third-party scripts, with removing unnecessary resources presented as a way to reduce attack surface. SAQ A merchants are exempt from the specific requirements but must attest that their e-commerce systems are not vulnerable to script-based attacks.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.