Skip to main content
Blog
Blog

PCI Compliance 4.0.1: A Practical Implementation Guide Webinar

We partnered up with VikingCloud, the largest global PCI compliance QSA and security firm on 2 webinars giving you the full context and info to implement PCI DS 4.0.1. With a special focus on requirements 6.4.3 & 11.6.1.

Jun 26, 2025 Updated Jul 19, 2026 2 min read
webinar-image-cover
Table of Contents

TL;DR

  • PCI DSS 4.0.1 webinar with VikingCloud: cside partnered with VikingCloud, the largest global PCI compliance QSA and security firm, on two webinars covering how to implement PCI DSS 4.0.1, with a special focus on requirements 6.4.3 and 11.6.1.
  • Key takeaway: The sessions stress that 6.4.3 and 11.6.1 are already enforceable and apply even to SAQ A merchants, and that being compliant is not the same as being secure.

We partnered up with Viking,Cloud, the largest global PCI compliance QSA and security firm on 2 webinars giving you the full context and info to implement PCI DS 4.0.1. With a special focus on requirements 6.4.3 & 11.6.1.

Form not showing? - click here

Some topics we covered:

PCI DSS 4.0.1 is already enforceable

Many organizations are behind in adopting these changes, especially the requirements 6.4.3 & 11.6.1 which became effective in early 2025.

SAQ A merchants are not exempt from real risks

Even though SAQ A avoids most technical requirements, client-side attacks can still target payment pages, especially through iframes, redirects, or 3rd-party scripts.

6.4.3 and 11.6.1 apply even if you're SAQ A

Many SAQ A setups load 3rd-party scripts in user browsers. These scripts can be tampered with, so monitoring is essential, despite the "light" SAQ categorization.

Compliance ≠ Security

You can be technically compliant but still vulnerable. Proactive threat detection matters more than check-the-box approaches.

Tools alone won't save you

Organizations need a blend of technology + process + people to implement PCI 4.0.1 properly.

Some questions we answered:

"We are a Level 1 service provider providing JavaScript UIs. How can we protect against issues on the merchant's side, which we don't control?"

Could we have suffered a client-side attack without knowing it? What if the breach happened months ago, and we've since made changes?"

"I'm a risk consultant. Should I raise this with IT and the C-suite?"

"I use Stripe. Am I safe?"

Webinar slide summarizing audience questions on PCI DSS 4.0.1 and client-side security for SAQ A merchants
A slide out of the webinar
Second webinar slide continuing the audience Q and A on client-side attack risk for SAQ A merchants and service providers
A second slide out of the webinar
Simon Wijckmans
Founder & CEO

Founder and CEO of cside. Previously a product manager on Cloudflare Page Shield (now Cloudflare Client-Side Security). Co-chair of the W3C Anti-Fraud Community Group and a Forbes 30 Under 30 honoree. Building accessible security against client-side attacks, web security is not an enterprise-only problem.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

Book a personalized demo to see:

How to achieve PCI DSS requirement 6.4.3 & 11.6.1 compliance in 1 day
Why third-party scripts are a security risk for you and your visitors
Monitoring privacy and consent leakage (GDPR, CCPA) across every third party
Stopping signup abuse, account sharing, and chargeback fraud with device intelligence
Detecting and controlling AI agents and bots hitting your site in real time

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead