Get Demo
↑

PCI DSS Requirement 6: Secure Software Development and Payment Page Scripts (6.4.3)

PCI DSS v4.0.1 Requirement 6 - secure SDLC, vulnerability ranking and patching, public-web protection, payment page script control (6.4.3), change control.

Published: September 2026 Compliance · PCI DSS 8-12 min read

PCI DSS Requirement 6 in v4.0.1 is titled Develop and Maintain Secure Systems and Software. It spans secure SDLC for bespoke/custom software, vulnerability ranking and patching, public-facing web application protection, payment page script control (6.4.3), and production change management.

Related: VAPT for PCI DSS (primarily Requirement 11) · Requirement 2.

v4.0.1 gotcha - 6.3.3: PCI SSC clarified that installing patches/updates within 30 days applies to critical vulnerabilities (aligned with v3.2.1 language), not the broader “critical or high” wording that appeared in early v4.0 materials.

Requirement 6 Structure

Clause
Focus
6.1
Processes and mechanisms for secure systems and software
6.2
Bespoke and custom software developed securely
6.3
Security vulnerabilities identified and addressed
6.4
Public-facing web applications protected against attacks (includes 6.4.3 scripts)
6.5
Changes to system components managed securely

Deep Dives

How CyberSilo Helps

Map PCI DSS v4.0.1 Controls to Continuous Evidence

CyberSilo CSA and ThreatHawk SIEM help US merchants and service providers collect QSA-ready evidence across the 12 requirements.

Frequently Asked Questions

What is the difference between 6.4.3 and 11.6.1?

6.4.3 manages authorization, integrity, and inventory of payment page scripts loaded in the consumer browser. 11.6.1 (covered in a later Requirement 11 guide) adds change-and-tamper detection for payment pages/HTTP headers as received by the browser.

Does 6.3.3 require all high patches within 30 days?

Under PCI DSS v4.0.1, the one-month install window applies to critical vulnerabilities (PCI SSC reverted the earlier “critical or high” wording). Other applicable patches follow a timeframe you define.

Who owns third-party payment page scripts?

6.4.3 applies to scripts loaded from your environment and from third/fourth parties. You still need authorization, integrity assurance, and a justified inventory for each script.

PCI DSS hub · PCI DSS v4.0.1: What Changed · USA v4.0.1 services

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!