Web Application
PCIComplianceHubLast updated
An application reached through a browser or through web services, whether over the internet or on a private network. A public-facing web application is one the internet can reach, and PCI DSS singles those out for protection against attacks.
Applies to. Every entity with a public-facing web application in scope, which includes every e-commerce merchant serving its own checkout or the page around an embedded one.
Example. A merchant's checkout site is a public-facing web application. 6.4.1 requires it to be protected either by reviewing it for vulnerabilities at least annually and after changes, or by an automated technical solution that detects and prevents web-based attacks, and 6.4.2, mandatory since 31 March 2025, requires the automated solution, such as a web application firewall, in front of it.
Limits. The web application is not the same thing as the payment page on it: 6.4.3 and 11.6.1 govern the scripts and headers of payment pages specifically, while 6.4.1 and 6.4.2 govern the application as a whole. An internal web application is still an application under 6.2 and 6.3, without the public-facing controls. Bespoke web applications also need secure coding under 6.2.4, which names the injection attacks a web application faces.