AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / US compliance

US compliance

PCI DSS 4.0.1 for a Small Merchant: The Questionnaire Changed, and So Did Your Checkout Page

PCI DSS 4.0.1 small business guide: what became mandatory on 31 March 2025, what changed in SAQ A, and why the scripts on your checkout page are your problem.

Sam KhanSam Khan The Cyber ExpertFounder and CEOSeptember 2, 2026 · 6 min read

The letter from the bank

The owner of a specialty food store with six employees and a busy website opens a letter from her acquiring bank on a Wednesday. It says the store is "non-validated" for PCI DSS and a monthly non-compliance fee will begin next cycle. She is confused, because she filled out the PCI questionnaire last year, the same one as every year, and ticked every box.

She calls the bank. The representative explains, patiently, that the form she filled out no longer exists. Version 4.0.1 replaced it, the short questionnaire she used to qualify for changed in January 2025, and there is a new question about her website she needs to answer.

The question is about scripts. Which scripts run on the checkout page? She calls her web developer. He lists them from memory: the payment provider's form, a reviews widget, a live chat bubble, two advertising pixels, a font loader, and something from a plugin he cannot quite place. Seven scripts, from six companies, on the page where customers type their card numbers. Nobody has ever looked at that list before, including him.

She never touches a card number. The payment provider handles all of that. She thought that was the whole point.

It is most of the point. The rest of the point is the seven scripts, and one of them being replaced by a thief's copy is how card numbers get stolen from stores that never store card numbers.

What the heck does this mean

PCI DSS is the card brands' rulebook for anyone who accepts card payments. It is not a law. It is a contract you signed with your acquiring bank, which is why the bank sends the letters.

Version 4.0.1 is the current edition. Most of its new requirements were "future-dated" for two years so merchants could prepare, and that grace period ended on 31 March 2025.

An SAQ is a self-assessment questionnaire, the form a small merchant completes instead of an on-site audit. SAQ A is the shortest one, for merchants who hand card entry entirely to a payment provider through a hosted page or an embedded frame.

Payment-page script requirements are the new part. Requirements 6.4.3 and 11.6.1 say a merchant must know every script on the payment page, justify each, and detect changes. In January 2025 the Council took those two, plus 12.3.1, out of SAQ A and replaced them with an eligibility test: your site must not be open to attacks from scripts that could affect the payment page.

Skimming is the attack this is about. A criminal alters one of those scripts, the page looks identical, and a copy of every card number goes to the criminal while the real one goes to the payment provider. The store owner never sees it. Neither does the customer, until the fraud starts.

The numbers that matter

Fifty-one future-dated PCI DSS v4.x requirements became mandatory on 31 March 2025, according to the PCI Security Standards Council's 2025 guidance. Every one of them now applies to a merchant validating for the first time under 4.0.1.

The Council revised SAQ A in January 2025 to remove requirements 6.4.3, 11.6.1 and 12.3.1 and replace them with an eligibility criterion about payment-page script attacks, per the PCI SSC's 2025 announcement. That is the new question the bank's representative was describing.

34% of firms report at least one account takeover incident per month, according to the Barracuda 2026 Email Threats Report. A stolen store-admin login is the fastest way to put a bad script on a checkout page, which is why the admin panel matters as much as the page.

What to do this week

  1. Ask your payment provider, in writing, exactly how the card form reaches your customers: a redirect to their page, an embedded frame they host, or fields your site renders. The answer decides which SAQ you complete, and the bank will want to see it. (CIS 3 Data Protection)
  2. Inventory every script on the checkout page. Have the developer open the page, list each script, its source company and its purpose, and date the list. If nobody can explain a script, it does not belong on that page. (CIS 16 Application Software Security)
  3. Cut the checkout page to the minimum. Reviews, chat and advertising pixels can live on every other page of the store. Move them, and put what remains under a content security policy so the browser refuses scripts from anywhere else. (CIS 16 Application Software Security)
  4. Lock the store admin: MFA for every login, delete the accounts of former staff and former developers, and update the platform and every plugin. The thief's route to your checkout page is usually a password. (CIS 4 Secure Configuration of Enterprise Assets and Software)
  5. Search for card numbers where they should not be: the shared inbox, order notes, the notepad by the phone where someone takes the occasional phone order. Delete them and change the process. (CIS 3 Data Protection)
  6. Complete the current SAQ, attach the provider's letter and the script inventory, and answer the bank with a date. Fees stop when validation arrives, not when you mean to get to it. (CIS 4 Secure Configuration of Enterprise Assets and Software)

Where AccuSights fits

We read the SAQ so you do not have to guess. Our assessment tells a small merchant which questionnaire applies, what the eligibility criterion means for your actual checkout page, and what is on the page that should not be. Our team implements the controls at a reasonable rate: the script inventory and content security policy, the admin hardening, the scanning that catches the changed script before the bank's fraud team does, and protection of the assets that run the store. The Cyber Hygiene Test takes three minutes; a call with an engineer takes fifteen.

Questions people ask

What is the deadline for PCI DSS 4.0.1? It has passed. The 51 future-dated requirements in version 4.x became mandatory on 31 March 2025, and the revised SAQ A has been the current questionnaire since January 2025. If your last self-assessment was completed on an older form, your acquiring bank will treat you as out of date, which is what the non-compliance fee letters are about.

Does using a payment gateway make me PCI compliant? No. It makes you eligible for a shorter questionnaire, if the gateway delivers the card form in a way that keeps card numbers off your site and your site is not open to script attacks on the payment page. You still have to confirm that eligibility, complete the questionnaire, and protect the parts you control: the store admin, the page the card form sits on, and any card data that leaks into email or order notes.

What happens if I fail PCI compliance? Two things, in order. Your acquiring bank charges monthly non-compliance fees and can eventually terminate your merchant account, which for an online store means no way to take payment. If cards are stolen through your site, the card brands' fines and the cost of forensic investigation land on you through the bank, and they are not sized for a six-person business.

You do not store card numbers. Good. Now go count the strangers standing next to the customer who is typing one.

Controls this post maps to

CIS 16 Application Software SecurityCIS 4 Secure Configuration of Enterprise Assets and SoftwareCIS 3 Data Protection

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.