Script Authorization
PCIComplianceHubLast updated
The Requirement 6.4.3 control that every script loading and executing on a payment page is explicitly approved before it runs, with a written business justification recorded for why it is there. The point is to make the presence of each script a decision rather than an accident. It is one of three obligations in that requirement, alongside assuring script integrity and maintaining an inventory.
Applies to. Any entity with a payment page it controls, and a provider for the scripts inside its own embedded form.
Example. A change request adds a fraud-scoring script to checkout. It names the script, its source and why it is needed; someone with authority approves it; the inventory gains a line. That is authorisation. If the vendor later changes the script's contents at the same address, that is an integrity question, not an authorisation one.
Limits. The guidance allows authorisation to be confirmed after a change where confirming it beforehand is impractical, but the wording is 'as soon as possible after', not at the next scheduled review. Authorisation can be a manual or an automated process. A CSP allow list is one way of enforcing the decision; it does not replace the record of who made it and why.
In PCI DSS v4.0.1. 6.4.3 (Payment page script inventory)
Sources. PCI DSS v4.0.1 (June 2024)