Card skimming moved from the till to the browser years ago. Attackers who can change one script on a checkout page can copy every card number typed into it, and the store keeps working normally while it happens. PCI DSS v4.0 responded with two requirements that became mandatory on 31 March 2025.
What 6.4.3 and 11.6.1 ask for
Requirement 6.4.3 asks that every script loaded on a payment page is inventoried, has a written justification, is authorised, and has its integrity assured. Requirement 11.6.1 asks for a mechanism to detect unauthorised changes to the page and its security-relevant headers, and to alert when they happen.
If your payment form is entirely on your provider’s domain, your obligations may be lighter — but the eligibility rules are specific, and many stores that embed payment fields in their own page are not as far out of scope as they assume. Check with your acquirer or a Qualified Security Assessor rather than guessing.
“The tag manager your marketing team loves is now a compliance question.”
What we usually find
Dozens of scripts on the checkout: analytics, reviews, live chat, A/B testing, advertising pixels. Several are loaded through a tag manager that anyone in marketing can edit, which means anyone in marketing — or anyone who phishes them — can publish code to the payment page.
Related engagement Every script on the payment page, accounted for →How to get there
Inventory every script under real conditions, including those loaded indirectly. Remove everything the payment page does not need — usually most of them. For what remains, enforce a Content Security Policy, use integrity checks where scripts are static, and put change detection in place that actually alerts someone. Then test it, by changing a script and checking that the alert fires.