Payment-page security
PCI DSS 4.0.1 checklist for e-commerce websites
E-commerce security under PCI DSS 4.0.1 requires more than using a hosted payment provider. Merchants must understand their validation scope and responsibilities for payment-page scripts, authorization, integrity, inventories, tamper detection, access, vulnerabilities, vendors, and evidence. Requirements 6.4.3 and 11.6.1 became effective March 31, 2025.
Payment-page script management
Change and tamper detection
Future-dated controls became effective
Start with scope and responsibility
Document the checkout flow, payment provider, redirects, iframes, scripts, tags, apps, hosting, DNS, administrators, developers, and service providers. Identify which party operates each component and which evidence supports the merchant's validation method.
A platform's PCI status does not automatically answer every merchant responsibility. Custom scripts, tag managers, apps, external forms, compromised administrators, and changed integrations can alter risk and scope.
Control browser-side scripts
Maintain an inventory of scripts on payment pages, document why each is necessary, authorize changes, and implement an integrity method appropriate to the architecture. Remove obsolete tags and restrict who can publish through tag managers or theme code.
Use change and tamper detection that evaluates the payment page and relevant headers at the required frequency. Define alert ownership and response instead of collecting alerts nobody reviews.
Build an evidence calendar
Track quarterly scans where applicable, access reviews, patching, vulnerability remediation, provider attestations, incident exercises, script reviews, change-detection evidence, policy reviews, and annual validation.
Confirm requirements with a qualified assessor or the acquiring bank when scope or validation is uncertain. This guide is operational information, not a compliance determination.
Primary sources
This page separates sourced facts from North Star's operational guidance. Check the current source before relying on a changing price, rule, list, or technical standard.
Questions businesses ask
Is every Shopify store automatically finished with PCI work?
Shopify provides a PCI-compliant platform, but merchants still need to understand their own configuration, staff, apps, scripts, integrations, access, and validation responsibilities.
Why are payment-page scripts important?
Compromised or unauthorized browser-side scripts can change payment pages or capture data, which is why authorization, integrity, inventory, and change detection matter.
Can North Star certify PCI compliance?
North Star can assist with technical implementation and evidence. Formal validation requirements should be confirmed with the acquiring bank or a qualified assessor.
Turn the research into an operating plan
North Star can help assess the environment, define scope, document ownership, implement controls, and verify the result.
Review an e-commerce implementation