Script Inventory
PCIComplianceHubLast updated
The written list of every script permitted on a payment page, each with a justification for its presence, required by Requirement 6.4.3. It is what an assessor compares an observed page against, so a script running in the browser but absent from the inventory is a finding whether or not it is malicious. Inventories drift quickly, because tag managers and marketing tools add scripts without any code deployment.
Applies to. Any entity with a payment page it controls, and a provider for the scripts inside its own embedded form.
Example. A record listing each script by its source, who owns it, why the page needs it and when it was last reviewed. 'Marketing uses it' is not a justification. 'Records add-to-cart conversions for the paid search programme; no alternative without it' is.
Limits. An inventory records what is permitted; it does not detect what is running. Comparing it against the page as the browser assembles it is a separate step, and a tag manager changes the answer without any deployment. The standard prescribes no format and no review interval for the inventory itself, only that it exists, covers every script, and carries a written business or technical justification for each.
In PCI DSS v4.0.1. 6.4.3 (Payment page script inventory)
Related. Script Authorization, Payment Page Script, Change-and-Tamper Detection Mechanism, Baseline (Change Detection)
Sources. PCI DSS v4.0.1 (June 2024)