What does PCI DSS Requirement 6.4.3 require?
The requirement focuses on scripts on payment pages as received by the consumer’s browser. In practical terms, the entity needs governance around which scripts are allowed, why each is present, how the inventory stays current and what method assures integrity. Use the current PCI SSC standard and assessor guidance as the authority for your environment.
How can DygDog support the four script tasks?
DygDog discovers script elements in fetched payment-page HTML, normalises their sources, marks third-party origins and records SRI/CSP observations. The inventory and fingerprints can support technical evidence, while approvals and business justification remain organisational records.
What should an assessor-ready record contain?
For each script, retain an owner, source, purpose, approval, integrity method and review date. Reconcile DygDog observations with that register and investigate unmatched entries. Keep evidence of remediation and exceptions alongside the technical snapshot.
What DygDog checks
Authorisation input
Surfaces observed scripts so owners can reconcile them with approvals.
Justification workflow
Provides the technical inventory to pair with a documented business purpose.
Inventory evidence
Stores bounded script metadata, origin classification and observation timestamps.
Integrity evidence
Reports SRI syntax, crossorigin context, CSP posture and script fingerprints.
Coverage limits to understand
- DygDog cannot decide whether a script is authorised or necessary.
- SRI is not technically suitable for every dynamically changing third-party script.
- Only a qualified assessor can determine whether the complete implementation satisfies your obligations.
Frequently asked questions
Is SRI mandatory for every script under 6.4.3?
The requirement calls for integrity assurance, but the appropriate method depends on the script and implementation. Confirm accepted methods with your assessor and current PCI SSC guidance.
Does an inventory alone satisfy 6.4.3?
No. The requirement also addresses authorisation, justification and integrity assurance.
Can DygDog create the business justification?
No. It supplies technical observations; the organisation that owns the payment page must document why each script is necessary.