PCI DSS payment-page security & scanning.
Card data is increasingly stolen right in the customer's browser, through tampered scripts on the payment page — e-skimming. PollySec watches your payment page and your public surface, and gives you both the protection and the evidence for PCI DSS v4.0.1 — including the new e-commerce requirements 6.4.3 and 11.6.1.
What you get for PCI DSS
PCI DSS v4.0.1 raised the bar for e-commerce with two new, mandatory requirements — payment-page script control (6.4.3) and tamper detection (11.6.1). PollySec delivers 6.4.3 today — payment-page script inventory and integrity checks — with 11.6.1 tamper monitoring on the roadmap, alongside the surrounding vulnerability, encryption and exposure requirements.
Payment-page discovery
Finds the payment page — and the page that embeds the payment iframe — where e-skimming (Magecart) attacks actually happen.
Script inventory in a real browser
Inventories every script and third-party origin loaded in the customer's browser — the foundation for knowing exactly what runs on your checkout.
Integrity & security-header checks
Verifies script integrity (SRI) and evaluates Content-Security-Policy, HSTS, X-Frame-Options and more — as the browser actually receives them.
Tamper & change monitoring (on the roadmap)
Baseline-vs-current comparison of payment-page scripts and security headers, alerting when something is added, changed or removed — the continuous 11.6.1 control we are building next.
Script authorization & inventory export
Approve each script with a business or technical justification, and export a complete script inventory as audit evidence.
External vulnerability scanning
Finds vulnerabilities, known CVEs and exposed services across your public surface; runs on schedule and after a significant change.
Encryption & certificates
Checks TLS strength, certificate validity and that weak or outdated protocols are not in use.
End-of-life software detection
Surfaces components and versions past vendor security support that no longer receive fixes.
Internal vulnerability scanning
Scans from inside the network via a local sensor — authenticated and unauthenticated — without data leaving your environment.
The quarterly ASV scan attestation (Requirement 11.3.2) may only be issued by a PCI-accredited Approved Scanning Vendor. PollySec provides this through an accredited ASV partner, while running the continuous monitoring and remediation support around it.
The new e-commerce requirements: 6.4.3 & 11.6.1
Mandatory since March 2025, these requirements target e-skimming — malicious scripts that capture card data in the shopper's browser. They demand that you know, authorize and monitor every script and security header on your payment page.
6.4.3
Authorize, integrity-check and inventory every payment-page script
11.6.1 · roadmap
Detect and alert on unauthorized changes to scripts and security headers, at least weekly — the continuous control we are building next
PCI DSS for Swedish e-commerce
Every Swedish merchant that accepts card payments falls under PCI DSS. PollySec — built by a Swedish company — gives small and mid-sized retailers continuous payment-page protection and the technical evidence to show their work, whether they run in our cloud or fully self-hosted. One platform also carries the NIS2 and ISO 27001 evidence story.
PollySec supports your PCI DSS work with continuous technical monitoring and evidence — it is not an ASV attestation, not a QSA assessment, and not a guarantee of compliance. Your acquiring bank and QSA determine final validation.
Stop e-skimming before it reaches checkout.
Book a 20-minute demo — we'll scan a live payment page with you and show the script inventory and header posture on the spot.