Skip to main content
Blog
Blog

PCI DSS compliance checklist 2026: Requirements 6.4.3 and 11.6.1 explained

Requirements 6.4.3 and 11.6.1 became mandatory in March 2025. Here is what belongs on a modern PCI DSS compliance checklist, and how to automate it.

Jul 29, 2026 6 min read
PCI DSS compliance checklist 2026: Requirements 6.4.3 and 11.6.1 explained

TL;DR: PCI DSS compliance checklist for 2026

  • Two new items for every SAQ variant touching a payment page: 6.4.3 (authorize and inventory every script) and 11.6.1 (detect unauthorized modification).
  • SAQ-A merchants on redirect or iframe are not exempt. Both apply because your parent page loads the scripts.
  • Enforcement started 31 March 2025. QSAs now fail assessments where the merchant cannot produce evidence for both.

12 PCI DSS requirements — a compliance checklist

What Requirements 6.4.3 and 11.6.1 actually cover

The PCI DSS framework spans twelve requirement domains covering network security, access control, encryption, monitoring, and policy. Most of them predate the current version of the standard. Requirements 6.4.3 and 11.6.1 are the additions in PCI DSS v4.0 that address a risk earlier versions left uncovered: client-side script attacks on payment pages.

Requirement 6.4.3 covers script management. Every script loaded on a payment page has to be inventoried, carry a documented business justification, be explicitly authorised, and have its integrity verified on an ongoing basis. It applies to all scripts, including those loaded from third-party vendors.

Requirement 11.6.1 covers change and tamper detection. It requires a mechanism that detects and alerts on unauthorised changes to payment page HTTP headers and content. The standard sets a weekly floor, but continuous monitoring is what QSAs now expect to see as evidence.

Together these two form the client-side portion of the checklist for any merchant that accepts card payments on a web page.

Requirement 6.4.3 checklist

Each row below maps a 6.4.3 control to the manual way of satisfying it and the automated equivalent.

ItemRequirementManual approachAutomated with cside
Script inventoryList all scripts on payment pagesManual audit per deploy cycleAutomated, continuous
Business justificationDocument reason for each scriptSpreadsheet per script, updated manuallyPrompted on new script detection
Authorisation statusEach script confirmed authorisedSign-off process per deployAuto-flagged for review on change
Integrity verificationHash/integrity check per scriptManual hash comparison per cycleReal-time hash monitoring, per session

Requirement 11.6.1 checklist

Requirement 11.6.1 is about catching change quickly and being able to prove you caught it.

ItemRequirementManual approachAutomated with cside
Change detectionMonitor headers and scripts for changesScheduled scans (weekly minimum)Real-session, continuous
Alert mechanismAlert on any detected changeScheduled email reportReal-time alert, under a minute
FrequencyMinimum weekly, continuous preferredManual weekly checkContinuous, every session
Evidence for QSADocumented alert and response recordsManual log compilation (4 to 16 hours)Report export in seconds

PCI DSS compliance cost by merchant level

Annual PCI compliance cost scales with merchant level. The ranges below reflect the total programme cost, of which client-side tooling for 6.4.3 and 11.6.1 is one line item.

Merchant levelAnnual compliance cost
Level 4 (SME)$5K to $25K
Level 3$50K to $150K
Level 2$100K to $500K
Level 1 (enterprise)$1.5M to $5M

Source: PCI Security Standards Council / Verizon PCI Compliance Report.

Tooling that covers 6.4.3 and 11.6.1 script monitoring typically accounts for 15 to 25 percent of the total. Automation cuts both the tooling cost and the engineering hours that manual checklist work would otherwise consume.

A working checklist workflow

Manual vs automated: what the checklist looks like in practice

A manual approach to the 6.4.3 and 11.6.1 checklist means a script audit at every deployment, a spreadsheet-based authorisation workflow, periodic hash comparisons, and a log-compilation exercise before every QSA review. For a merchant running 20 to 50 third-party scripts on its payment pages, that adds up to roughly 15 to 30 engineering days a year.

The manual process also carries a detection lag. If a supply chain attack modifies a trusted script overnight, a weekly scan will not catch it until the next scheduled run. A QSA reviewing 11.6.1 evidence will ask what the maximum detection window was, and a seven-day window reads very differently from a one-minute window.

Automating the checklist collapses that window to under a minute. The tooling handles inventory, hash monitoring, change alerting, and report generation continuously, with no manual step between deployment cycles.

How cside PCI Shield automates the full checklist

cside PCI Shield implements the full 6.4.3 and 11.6.1 checklist from a single script tag.

On the 6.4.3 side, it keeps a continuous script inventory, flags new or changed scripts for authorisation review, and hashes every payload in real browser sessions using 100+ signals, holding high accuracy across incognito, VPN, and cookie-clearing sessions.

On the 11.6.1 side, it monitors HTTP headers and payment page content in live sessions, fires an alert within a minute of any unauthorised change, and keeps a timestamped alert log formatted for QSA review. Reports export in seconds rather than the hours a manual log compilation takes.

The methodology has been validated by an independent QSA (VikingCloud), and PCI Shield has a strong track record across customer audits. The same timestamped integrity log doubles as chargeback dispute evidence: showing exactly when a script was clean and when a change occurred strengthens a dispute package.

Further reading

As of 2026-07-29, treat this as operational guidance, not legal advice. Confirm the exact control language with your QSA, counsel, or risk owner.

Requirement 6.4.3 & 11.6.1 in one view

Mike Kutlu
Client-Side Security Consultant

Client-side security consultant at cside. 10+ years of experience implementing technology solutions for enterprises (previously at Oracle, Cloudflare, and Splunk). Now helping teams use client-side intelligence to catch & reduce fraud.

FAQ

Frequently Asked Questions

A PCI DSS compliance checklist covers the twelve requirement domains of the standard: network security, account data protection, vulnerability management, access control, monitoring, and policy. Since March 2025, the checklist also includes Requirements 6.4.3 and 11.6.1, which mandate script inventory, authorisation, integrity verification, and continuous change detection on payment pages.

These two requirements address the client-side formjacking and supply chain script attacks that earlier versions of the standard did not specifically cover.

Requirement 6.4.3 requires that every script loaded on a payment page is inventoried, has a documented business justification, is explicitly authorised by a responsible party, and has its integrity verified on an ongoing basis. It applies to all scripts, including those served by third-party vendors.

Integrity verification has to be continuous, not a one-time check. Tools that hash script payloads in real sessions and alert on changes satisfy this requirement; static script lists and scheduled crawls typically do not.

Requirement 11.6.1 specifies a change-detection mechanism that fires an alert on any unauthorised change to payment page headers or content. It sets a minimum of weekly scanning, but the standard's intent, and the QSA expectation in practice, is continuous monitoring.

Tools that operate in real browser sessions and alert within a minute of a payload change provide a stronger evidence record than weekly scheduled scans, particularly when QSAs ask about the maximum gap between a change event and its detection.

Yes, specifically the 6.4.3 and 11.6.1 components that account for the most ongoing engineering effort. cside PCI Shield handles script inventory, hash monitoring, change alerting, and QSA report generation continuously, reducing the manual engineering effort from 15 to 30 days per year to one or two days.

The tool is available on a free plan with 1,000 API calls per month, and the paid plan starts at $99 per month.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo