Blog / US compliance
US compliance
PCI DSS 4.0.1 for a Small Merchant: The Questionnaire Changed, and So Did Your Checkout Page
PCI DSS 4.0.1 small business guide: what became mandatory on 31 March 2025, what changed in SAQ A, and why the scripts on your checkout page are your problem.
The letter from the bank
The owner of a specialty food store with six employees and a busy website opens a letter from her acquiring bank on a Wednesday. It says the store is "non-validated" for PCI DSS and a monthly non-compliance fee will begin next cycle. She is confused, because she filled out the PCI questionnaire last year, the same one as every year, and ticked every box.
She calls the bank. The representative explains, patiently, that the form she filled out no longer exists. Version 4.0.1 replaced it, the short questionnaire she used to qualify for changed in January 2025, and there is a new question about her website she needs to answer.
The question is about scripts. Which scripts run on the checkout page? She calls her web developer. He lists them from memory: the payment provider's form, a reviews widget, a live chat bubble, two advertising pixels, a font loader, and something from a plugin he cannot quite place. Seven scripts, from six companies, on the page where customers type their card numbers. Nobody has ever looked at that list before, including him.
She never touches a card number. The payment provider handles all of that. She thought that was the whole point.
It is most of the point. The rest of the point is the seven scripts, and one of them being replaced by a thief's copy is how card numbers get stolen from stores that never store card numbers.
What the heck does this mean
PCI DSS is the card brands' rulebook for anyone who accepts card payments. It is not a law. It is a contract you signed with your acquiring bank, which is why the bank sends the letters.
Version 4.0.1 is the current edition. Most of its new requirements were "future-dated" for two years so merchants could prepare, and that grace period ended on 31 March 2025.
An SAQ is a self-assessment questionnaire, the form a small merchant completes instead of an on-site audit. SAQ A is the shortest one, for merchants who hand card entry entirely to a payment provider through a hosted page or an embedded frame.
Payment-page script requirements are the new part. Requirements 6.4.3 and 11.6.1 say a merchant must know every script on the payment page, justify each, and detect changes. In January 2025 the Council took those two, plus 12.3.1, out of SAQ A and replaced them with an eligibility test: your site must not be open to attacks from scripts that could affect the payment page.
Skimming is the attack this is about. A criminal alters one of those scripts, the page looks identical, and a copy of every card number goes to the criminal while the real one goes to the payment provider. The store owner never sees it. Neither does the customer, until the fraud starts.
The numbers that matter
Fifty-one future-dated PCI DSS v4.x requirements became mandatory on 31 March 2025, according to the PCI Security Standards Council's 2025 guidance. Every one of them now applies to a merchant validating for the first time under 4.0.1.
The Council revised SAQ A in January 2025 to remove requirements 6.4.3, 11.6.1 and 12.3.1 and replace them with an eligibility criterion about payment-page script attacks, per the PCI SSC's 2025 announcement. That is the new question the bank's representative was describing.
34% of firms report at least one account takeover incident per month, according to the Barracuda 2026 Email Threats Report. A stolen store-admin login is the fastest way to put a bad script on a checkout page, which is why the admin panel matters as much as the page.
What to do this week
- Ask your payment provider, in writing, exactly how the card form reaches your customers: a redirect to their page, an embedded frame they host, or fields your site renders. The answer decides which SAQ you complete, and the bank will want to see it. (CIS 3 Data Protection)
- Inventory every script on the checkout page. Have the developer open the page, list each script, its source company and its purpose, and date the list. If nobody can explain a script, it does not belong on that page. (CIS 16 Application Software Security)
- Cut the checkout page to the minimum. Reviews, chat and advertising pixels can live on every other page of the store. Move them, and put what remains under a content security policy so the browser refuses scripts from anywhere else. (CIS 16 Application Software Security)
- Lock the store admin: MFA for every login, delete the accounts of former staff and former developers, and update the platform and every plugin. The thief's route to your checkout page is usually a password. (CIS 4 Secure Configuration of Enterprise Assets and Software)
- Search for card numbers where they should not be: the shared inbox, order notes, the notepad by the phone where someone takes the occasional phone order. Delete them and change the process. (CIS 3 Data Protection)
- Complete the current SAQ, attach the provider's letter and the script inventory, and answer the bank with a date. Fees stop when validation arrives, not when you mean to get to it. (CIS 4 Secure Configuration of Enterprise Assets and Software)
Where AccuSights fits
We read the SAQ so you do not have to guess. Our assessment tells a small merchant which questionnaire applies, what the eligibility criterion means for your actual checkout page, and what is on the page that should not be. Our team implements the controls at a reasonable rate: the script inventory and content security policy, the admin hardening, the scanning that catches the changed script before the bank's fraud team does, and protection of the assets that run the store. The Cyber Hygiene Test takes three minutes; a call with an engineer takes fifteen.
Questions people ask
What is the deadline for PCI DSS 4.0.1? It has passed. The 51 future-dated requirements in version 4.x became mandatory on 31 March 2025, and the revised SAQ A has been the current questionnaire since January 2025. If your last self-assessment was completed on an older form, your acquiring bank will treat you as out of date, which is what the non-compliance fee letters are about.
Does using a payment gateway make me PCI compliant? No. It makes you eligible for a shorter questionnaire, if the gateway delivers the card form in a way that keeps card numbers off your site and your site is not open to script attacks on the payment page. You still have to confirm that eligibility, complete the questionnaire, and protect the parts you control: the store admin, the page the card form sits on, and any card data that leaks into email or order notes.
What happens if I fail PCI compliance? Two things, in order. Your acquiring bank charges monthly non-compliance fees and can eventually terminate your merchant account, which for an online store means no way to take payment. If cards are stolen through your site, the card brands' fines and the cost of forensic investigation land on you through the bank, and they are not sized for a six-person business.
You do not store card numbers. Good. Now go count the strangers standing next to the customer who is typing one.
Controls this post maps to
CIS Controls v8.1. These are the same controls our assessment scores and the console watches.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
Nine Terminals, Five Stores, One Holiday Peak: PCI DSS 4.0.1 for Atlanta Retail
PCI DSS for multi-location retail in Atlanta: what 4.0.1 asks of nine terminals across five stores, and the six checks to finish before the holiday peak.
US complianceFTC Safeguards Rule: The CPA, the Car Dealer and the Tax Preparer Are All Financial Institutions Now
The FTC Safeguards Rule covers CPAs, dealers with in-house financing and tax preparers. What a WISP is, who the qualified individual is, and the 30-day notice.
US complianceState Privacy Laws in 2026: Which of the 20 Actually Apply to a Business Your Size
State privacy laws 2026: 20 are in force, three started in January, and Texas has no consumer-count threshold. How to tell which ones apply to your business.
