Q&A with a QSA: How to Pass Requirements 6.4.3 & 11.6.1 (PCI DSS)
Get direct answers from QSAs and a web security engineer on how to pass PCI DSS client-side requirements without guesswork or overbuilding. Together with MegaplanIT we break down what auditors expect, where teams get stuck, and how to implement a solution that holds up during your assessment.
Hosted By:
Marc Jackson QSA, Compliance Manager MegaplanIT
Michael Ciunci QSA, Security Consultant MegaplanIT
Simon Wijckmans CEO & Founder cside
What you will learn
Why PCI DSS added client-side security requirements (and what changed in 2025)
What QSAs actually look for in 6.4.3 & 11.6.1 evidence
How to determine your PCI scope (SAQ A, A-EP, D, etc.) and what it means for you
How AI agents bring a new threat to payment pages
A practical roadmap to become compliant without wasting engineering time
In the Q&A we covered:
Can I be compliant in 30 days?
When I sit down with a QSA to be interviewed on these particular requirements, what do they ask?
Does script monitoring need to happen on every page load? Or is sampling enough?
Can I complete my SAQ without using a QSA?
How much historical evidence do QSAs expect before an audit?
I'm using a scanner that monitors my site, no code or installation required. Am I covered?
Can PCI compliance impact cyber insurance or liability?
Access the Webinar
Fill out the form below to access the webinar recording instantly.