PCI DSS 4.0 for ecommerce: what changed for payment pages
What PCI DSS 4.0 requires for ecommerce payment pages — script inventory, authorisation and integrity, and change detection — and how to comply.
What PCI DSS 4.0 requires for ecommerce payment pages — script inventory, authorisation and integrity, and change detection — and how to comply.
Requirement 6.4.3
Every script on the payment page must be inventoried with a business justification, authorised, and its integrity assured — for example with CSP and Subresource Integrity.
RELATED GUIDEHow to stop spam and bot attacks on Adobe Commerce Cloud → Harden your Magento storeSecurity audits, patching and PCI-DSS 4.0 script controls.Get a free security audit →Requirement 11.6.1
You must have a mechanism to detect unauthorised changes to HTTP headers and scripts on payment pages, with alerts and at least weekly checks (or as defined by your risk analysis).
How to comply
- Inventory all checkout scripts
- Remove unnecessary third-party scripts
- Implement Content Security Policy
- Use Subresource Integrity where possible
- Deploy script and header change monitoring
- Document everything for your assessor
Common mistakes to avoid
How we help with security
Frequently asked questions
Does this apply if I use Stripe or Adyen?
It depends on your integration; embedded fields and redirects still have page-level requirements. Check with your QSA.
When did these become mandatory?
The future-dated requirements became mandatory from 31 March 2025.
Can you prepare evidence?
Yes — our PCI Ready package includes an evidence pack.