Skip to main content
Blog
Blog

VikingCloud approves cside for PCI DSS requirement 6.4.3 and 11.6.1

cside has partnered with VikingCloud to perform a deep technical assessment of the security solutions we offer under the enterprise plan, within the scope of PCI compliance. With proper implementation, our products meet requirements 6.4.3 and 11.6.1.

Apr 24, 2025 2 min read
cside-vikingcloud-partnership-cover-image
Table of Contents

TL;DR: VikingCloud QSA validation for PCI DSS 4.0.1 script control

  • Marketing vs assessment: Most PCI vendors publish a whitepaper they wrote themselves and call it validation. That is marketing, not assessment. A real QSA sign-off comes from a firm that audits your solution against the standard and puts its name on the finding.
  • VikingCloud's finding: VikingCloud, the largest global PCI compliance and security firm and Mastercard partner, ran a deep technical assessment of the cside enterprise platform. Their conclusion: the cside runtime script observability and agentless solution detected script changes via hashed values and blocking configurations, and demonstrated capability to meet PCI DSS 6.4.3 and 11.6.1 when deployed correctly.
  • What to ask vendors: If you are shortlisting client-side PCI tools, ask each vendor for a QSA firm's signed technical evaluation, not a self-published whitepaper. If VikingCloud's finding on cside is what you need, the detailed report is on the cside trust portal.

Short on time? See cside PCI Shield. It covers everything below in one deployment.

VikingCloud (formerly Sysnet) is the largest global PCI compliance and security firm. VikingCloud has partnerships with Mastercard and is the Qualified Security Assessor to some of the largest multinationals worldwide.

cside has partnered with VikingCloud to perform a deep technical assessment of our enterprise security solution and the scope of PCI compliance. With proper implementation, our product meets requirements 6.4.3 and 11.6.1.

VikingCloud: "During its analysis, VikingCloud confirmed that the cside Proxy and agentless solution detected the changes of the website scripts, using hashed values and/or "Blocking" configurations for specific website scripts, and demonstrated the capability to meet PCI DSS requirements 6.4.3 and 11.6.1. The technical evaluation and testing supported the finding that the solution meets the above requirements when deployed correctly. VikingCloud concluded that the solution offers protection against unauthorized script execution and prevents unauthorized changes to web-facing applications. The integration of cside platform may enable organizations to fulfill specific PCI DSS requirements and add an additional security layer for web applications."

Related reading: our PCI DSS 6.4.3 and 11.6.1 compliance guide · PCI DSS 6.4.3 and 11.6.1 solution comparison

Download the detailed report on our trust portal.

Simon Wijckmans
Founder & CEO

Founder and CEO of cside. Previously a product manager on Cloudflare Page Shield (now Cloudflare Client-Side Security). Co-chair of the W3C Anti-Fraud Community Group and a Forbes 30 Under 30 honoree. Building accessible security against client-side attacks, web security is not an enterprise-only problem.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead