Reflectiz has received validation from PCI Qualified Security Assessor Integrity360 Europe for its ability to help merchants meet new PCI DSS v4.0.1 requirements regarding third-party script security.
Key Points
- PCI DSS v4.0.1 requirements 6.4.3 and 11.6.1 mandate that merchants inventory, authorize, and monitor the integrity of all payment-page scripts.
- Integrity360 Europe confirmed that the Reflectiz platform effectively detects unauthorized script behavior and provides audit-ready evidence for compliance assessments.
- The platform utilizes agentless monitoring to track script behavior in real-time, addressing the risk of supply-chain attacks where malicious code is injected via trusted vendors.
- Reflectiz data indicates that approximately 30% of payment-page scripts undergo changes within any two-week period, making manual compliance tracking unsustainable.
- Merchants using payment iframes must now prove their checkout pages are not susceptible to script hijacking to satisfy updated PCI SSC guidelines.