Skip to content
Will your site survive Black Friday? Free peak-readiness audit →
SECURITY

PCI DSS 4.0 for ecommerce: what changed for payment pages

What PCI DSS 4.0 requires for ecommerce payment pages — script inventory, authorisation and integrity, and change detection — and how to comply.

By VISIBI Security team·Reviewed by Saeed Ak, Co-founder & CTO·Updated 29 September 2026·8 min read
QUICK ANSWER

What PCI DSS 4.0 requires for ecommerce payment pages — script inventory, authorisation and integrity, and change detection — and how to comply.

KEY TAKEAWAYS
✓PCI DSS 4.0 adds specific controls for scripts on payment pages.
✓6.4.3 requires inventory, authorisation and integrity of payment page scripts.
✓11.6.1 requires detecting unauthorised changes to payment pages.

Requirement 6.4.3

Every script on the payment page must be inventoried with a business justification, authorised, and its integrity assured — for example with CSP and Subresource Integrity.

RELATED GUIDEHow to stop spam and bot attacks on Adobe Commerce Cloud → Harden your Magento storeSecurity audits, patching and PCI-DSS 4.0 script controls.Get a free security audit →

Requirement 11.6.1

You must have a mechanism to detect unauthorised changes to HTTP headers and scripts on payment pages, with alerts and at least weekly checks (or as defined by your risk analysis).

How to comply

  • Inventory all checkout scripts
  • Remove unnecessary third-party scripts
  • Implement Content Security Policy
  • Use Subresource Integrity where possible
  • Deploy script and header change monitoring
  • Document everything for your assessor

Common mistakes to avoid

✕Waiting until after a breach to act
✕Restoring a backup without fixing the entry point
✕Leaving old plugins, extensions and admin users in place
✕Relying on a single tool instead of layered defences
HOW VISIBI CAN HELP

How we help with security

01ScanFree scan for malware, vulnerabilities and blocklisting.
02Clean & patchEngineers remove threats and close the entry point.
03HardenWAF, 2FA, least privilege and platform hardening.
04MonitorContinuous scanning with unlimited cleanups on our plans.
Get a free security audit →Free · No obligation · Reply within 24 hours

Frequently asked questions

Does this apply if I use Stripe or Adyen?

It depends on your integration; embedded fields and redirects still have page-level requirements. Check with your QSA.

When did these become mandatory?

The future-dated requirements became mandatory from 31 March 2025.

Can you prepare evidence?

Yes — our PCI Ready package includes an evidence pack.

SA
Reviewed by Saeed Ak · Co-founder & CTO25 years engineering high-traffic ecommerce, cloud and security platforms. Written by the VISIBI Security team.Meet the team →
Was this guide helpful?
Share:LinkedInXEmail
RELATED SERVICES

Keep reading

SECURITY · 9 MINHow to stop spam and bot attacks on Adobe Commerce CloudRead →SECURITY · 9 MINWordPress security checklist: 15 steps to protect your site in 2026Read →SECURITY · 8 MINMagecart and card skimming: how to protect your checkoutRead →
FREE · NO OBLIGATION

Harden your Magento store

Security audits, patching and PCI-DSS 4.0 script controls.

Get a free security audit →Talk to a specialist
✓ Senior specialist, not a bot✓ Reply within 24 hours✓ Clients in 18 countries
SECURITY SCAN PREVIEWEXAMPLE
What attackers can see right now
Unpatched vulnerabilities6
Unknown checkout scripts2
Blocklist statusClean
Your free review shows your real numbers.