Skip to content
MDView as Markdown

Compliance

PCI DSS 4.0 brought the browser into scope for the first time. Two requirements govern the security of scripts on payment pages, and Report URI is built to help you meet both and produce the evidence an assessor expects.

  • PCI DSS 6.4.3 - authorise, assure the integrity of, and inventory every script on your payment pages
  • PCI DSS 11.6.1 - continuously detect and alert on unauthorised change to your payment pages
  • PCI DSS Checklist - a step-by-step readiness checklist for both requirements

For a plain-English overview of what these requirements mean, who they apply to, and how SAQ A eligibility works, see the PCI DSS client-side security guide on our main site. For a summary of how Report URI's products map to each requirement, see PCI DSS Compliance.

Need something to hand to your assessor? The PCI DSS 6.4.3 & 11.6.1 evidence pack is a QSA-ready mapping of each requirement to the evidence you can export, available as a page and a branded PDF.

These guides are a practical, product-focused walkthrough. They are not a substitute for advice from your Qualified Security Assessor (QSA), who remains the authority on how any control applies to your environment.