PCI DSS 4.0.1 control guide

PCI DSS Requirement 6.4.3 Script Checklist

PCI DSS Requirement 6.4.3 requires payment-page scripts loaded and executed in the consumer’s browser to be managed. Teams need a method to confirm authorisation, document justification, maintain an inventory and assure integrity.

PCI DSS Requirement 6.4.3: the short answer

DygDog automates technical inventory and integrity observations. Owners still need to approve scripts, record why they are necessary, define scope and validate their compliance approach with an assessor.

What does PCI DSS Requirement 6.4.3 require?

The requirement focuses on scripts on payment pages as received by the consumer’s browser. In practical terms, the entity needs governance around which scripts are allowed, why each is present, how the inventory stays current and what method assures integrity. Use the current PCI SSC standard and assessor guidance as the authority for your environment.

How can DygDog support the four script tasks?

DygDog discovers script elements in fetched payment-page HTML, normalises their sources, marks third-party origins and records SRI/CSP observations. The inventory and fingerprints can support technical evidence, while approvals and business justification remain organisational records.

What should an assessor-ready record contain?

For each script, retain an owner, source, purpose, approval, integrity method and review date. Reconcile DygDog observations with that register and investigate unmatched entries. Keep evidence of remediation and exceptions alongside the technical snapshot.

What DygDog checks

01

Authorisation input

Surfaces observed scripts so owners can reconcile them with approvals.

02

Justification workflow

Provides the technical inventory to pair with a documented business purpose.

03

Inventory evidence

Stores bounded script metadata, origin classification and observation timestamps.

04

Integrity evidence

Reports SRI syntax, crossorigin context, CSP posture and script fingerprints.

Coverage limits to understand

  • DygDog cannot decide whether a script is authorised or necessary.
  • SRI is not technically suitable for every dynamically changing third-party script.
  • Only a qualified assessor can determine whether the complete implementation satisfies your obligations.

Frequently asked questions

Is SRI mandatory for every script under 6.4.3?

The requirement calls for integrity assurance, but the appropriate method depends on the script and implementation. Confirm accepted methods with your assessor and current PCI SSC guidance.

Does an inventory alone satisfy 6.4.3?

No. The requirement also addresses authorisation, justification and integrity assurance.

Can DygDog create the business justification?

No. It supplies technical observations; the organisation that owns the payment page must document why each script is necessary.

See what changed on your payment page

Get an external script inventory now. Pro scans add PCI-mapped evidence and scan-over-scan change detection.

Run your first scan