When the PCI Security Standards Council (PCI SSC) released PCI DSS v4.0, one of the most notable changes was the introduction of two new requirements—6.4.3 and 11.6.1—designed to mitigate client-side exploits such as Magecart attacks and other vulnerabilities that could expose cardholder data. Given that JavaScript is the dominant client-side scripting language of the Web, these measures were intended to strengthen security on payment pages.
The new requirements were:
Recognising the complexity of implementation—particularly for e-commerce merchants—the PCI SSC had initially future-dated these requirements to take effect after March 31, 2025. However, in an unexpected shift, the Council has now removed these requirements from SAQ A—the self-assessment questionnaire used by e-commerce merchants who fully outsource payment processing to a third party.
At first glance, many e-commerce businesses may welcome this decision, particularly those that had already begun investing time and resources into meeting these requirements. However, are they truly off the hook?
Let’s take a closer look.
While PCI SSC has removed 6.4.3 and 11.6.1 from SAQ A, they have introduced a new eligibility criterion:
Merchants must confirm that their site is not susceptible to attacks from scripts that could compromise their e-commerce system(s).
The PCI SSC does not specify how merchants should verify or demonstrate compliance with this criterion. Additionally, for SAQs validated by a Qualified Security Assessor (QSA), there is no clear guidance on how this requirement should be evidenced.
This raises an important question—if there were a simple way to verify script security, why were 6.4.3 and 11.6.1 introduced in the first place?
Until the PCI SSC provides further clarification, merchants may need to take proactive measures to demonstrate compliance with the new SAQ A eligibility criterion. Potential methods of validation could include:
At 1 Sequence Cyber we are closely monitoring updates from the PCI SSC and will keep our clients informed as further guidance becomes available. If you have any concerns about your compliance status or need assistance, feel free to reach out to us
📧 Email: contact@1sequencecyber.com
📞 Phone: 020 3130 1723
📍 Address: 381 Acorn House, Midsummer Boulevard, Milton Keynes, MK9 3HP
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper
Copyright © 2025 1 Sequence Cyber. All Rights Reserved