PCI DSS 4.0.1 Drags Checkout Scripts Into Scope, and Most Merchants Aren't Ready

An independent QSA tested Reflectiz against the new client-side rules. The verdict: every script running on your payment page is now an auditable surface.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 2 min read
PCI DSS 4.0.1 Drags Checkout Scripts Into Scope, and Most Merchants Aren't Ready
Share

Key points

  • An independent QSA report tested Reflectiz against those requirements and concluded the platform meets them.
  • A modern checkout routinely loads dozens of third-party scripts, any of which can be modified upstream to skim card data.
  • Neither requirement is satisfied by a Content Security Policy header alone.
  • SAQ A-EP merchants and full ROC level 1 retailers own the script inventory problem; acquirers have begun asking for evidence.

What did the new PCI DSS rules actually change?

That's a meaningful shift. Before, the perimeter ended at the server.

Why does the browser matter so much?

When a shopper types a card number into a checkout, the browser's running far more than the merchant's own code. Analytics tags, a tag manager, a chat widget, a payment iframe, a consent banner: a modern checkout routinely loads dozens of third-party scripts, often pulled in by other third-party scripts. Any one of them can be modified upstream to skim card data.

That attack pattern is called Magecart, and it has a long rap sheet. Variants have hit British Airways, Ticketmaster and hundreds of smaller Shopify and Magento storefronts. The supply-chain angle was reinforced more recently by the Polyfill.io incident, which affected an estimated large number of sites after a permitted vendor silently altered code inside an approved script. A Content Security Policy header can block unknown domains; it can't catch that.

What does a compliant solution actually look like?

The QSA write-up walks through the requirements: continuous inventory of first- and third-party scripts, behavioural baselines per script, change detection on form fields and network beacons, and evidence artefacts an assessor can pull during a Report on Compliance. Reflectiz passed on those criteria. Whether a given merchant needs a dedicated tool or can satisfy assessors another way depends on their SAQ tier.

Should you be worried about the audit math?

A SAQ A merchant who outsources the entire payment page to a PSP iframe is largely off the hook. Everyone else, SAQ A-EP merchants and full ROC level 1 retailers, owns the script inventory problem, and acquirers have started asking for evidence. Forensics firms expect non-compliance findings to surface in volume during the first full assessment cycle under 4.0.1.

This is the beat worth watching: not whether the rules are fair, but whether assessment practices harden fast enough to close the gap. The scripts were always there. Auditors are only now required to look.

© 2026 Threat Vectr