"We use a hosted checkout, so we're covered." One of the most common sentences in payment compliance — and one of the most reliably wrong in 2026, the year most merchants close out their first full assessment cycle under PCI DSS v4.0.1's e-commerce requirements without the transition allowances that got them through 2025.
What Actually Changed
Requirement 6.4.3 governs script management on payment pages; Requirement 11.6.1 mandates tamper detection, evaluated at least weekly. Both target Magecart-style script injection — the gap between "the processor is compliant" and "nothing malicious is running on the page the customer sees." Mandatory since March 31, 2025.

The Walk-Back That Made This Confusing
In January 2025, the PCI SSC removed 6.4.3 and 11.6.1 as literal checklist items for SAQ A — but replaced them with a broader eligibility test: your entire site, not just the payment page, must be safe from script attacks. Responsibility splits by setup: iframe embeds make you responsible for the parent page; server-side redirects mean the requirements don't apply; fully outsourced setups carry no responsibility at all.

Where This Actually Bites
The trap isn't the processor's part of the page — it's everything else: a marketing pixel, a chat widget, an A/B test script nobody looped compliance in on. Any of those can change your SAQ eligibility. Also: only an official Attestation of Compliance counts — a vendor's "certificate" isn't PCI SSC-authorized.

Your Assessment Type Depends on Volume, Not Just Setup
Level 1 (6M+ transactions/year) needs a full QSA-led Report on Compliance; Levels 2-4 scale down from there. A business that's scaled past a volume threshold without revisiting its assessment type is a common, avoidable gap.
Subscription Businesses Have an Extra Layer to Get Right
For recurring-billing merchants, tokenization — letting the processor store the card and handing you back a token — keeps your own infrastructure almost entirely out of cardholder-data scope.

What to Actually Do About It
Confirm your SAQ type in writing. Get written script-protection confirmation from iframe providers. Audit and inventory every checkout-page script. Verify you're holding a real AOC, not a marketing certificate.
MMG Corporation works with high-risk merchants across EU markets navigating exactly this kind of compliance detail.
Get in touchThis article was researched and written with the help of AI tools as part of our content process, and reviewed and fact-checked by the MMG team before publication.