Script Inventory

PCIComplianceHubLast updated

The written list of every script permitted on a payment page, each with a justification for its presence, required by Requirement 6.4.3. It is what an assessor compares an observed page against, so a script running in the browser but absent from the inventory is a finding whether or not it is malicious. Inventories drift quickly, because tag managers and marketing tools add scripts without any code deployment.

Applies to. Any entity with a payment page it controls, and a provider for the scripts inside its own embedded form.
Example. A record listing each script by its source, who owns it, why the page needs it and when it was last reviewed. 'Marketing uses it' is not a justification. 'Records add-to-cart conversions for the paid search programme; no alternative without it' is.
Limits. An inventory records what is permitted; it does not detect what is running. Comparing it against the page as the browser assembles it is a separate step, and a tag manager changes the answer without any deployment. The standard prescribes no format and no review interval for the inventory itself, only that it exists, covers every script, and carries a written business or technical justification for each.