PCI-DSS v4.0.1 is now enforced: Is your storefront actually compliant?

If your store accepts card payments, PCI-DSS v4.0.1 has already changed what you are required to do, and most stores have not caught up yet. Since 31 March 2025, all requirements are fully enforceable. Two of them shift the compliance burden from server-side security to client-side visibility in a way previous versions never did.
Most stores have a gap here. The challenge is that closing it manually is close to impossible at the pace modern eCommerce moves.
What PCI-DSS v4.0.1 actually requires
PCI-DSS (Payment Card Industry Data Security Standard) is the global security standard that any business accepting card payments must comply with. It sets the baseline for how cardholder data is protected, from your server infrastructure down to what runs in the customer's browser at checkout.
Non-compliance carries real consequences:
- Fines from card networks ranging from $5,000 to $100,000 per month depending on the severity and duration of the violation.
- Liability for fraudulent transactions if a breach occurs while non-compliant.
- Potential suspension of your ability to accept card payments entirely.
Version 4.0.1, now the only active version of the standard, introduced two requirements that most stores are still not meeting:
Requirement 6.4.3 requires every script running on your payment pages to be authorised, inventoried, and justified. Requirement 11.6.1 requires you to detect unauthorised changes to content delivered to your customer's browser.
Together, they shift the compliance burden from server-side security to client-side visibility. And that is where most stores have a gap.
Why manual checks cannot keep up
A modern checkout does not load one script. It loads dozens: analytics platforms, tag managers, personalisation engines, chat widgets, payment providers, ad pixels. Each one is managed by a different team, updated on a different schedule, and capable of changing without anyone on your side knowing.
A quarterly manual review might catch what was there three months ago. It will not catch the script that changed last Tuesday, or the one injected by a compromised third-party vendor overnight.
That is exactly how modern payment skimmers operate. The Sansec team uncovered one that hid its data exfiltration inside WebRTC traffic, invisible to standard network monitoring and completely undetectable by a point-in-time review. By the time a manual check would have found it, card data had already left the browser.
PCI-DSS v4.0.1 requires continuous detection precisely because periodic reviews are not enough. The standard has caught up with the threat. The question is whether your tooling has.
You can’t secure, or prove compliance for code you can’t see.
How AuditIQ closes the compliance gap
Meeting Requirement 6.4.3 and 11.6.1 continuously, not just at audit time, requires four things working together:
- JavaScript inventory. Tracks every script executing across your store, flagging new, changed, or unauthorised scripts the moment they appear on your payment pages.
- CSP violation monitoring. Detects unauthorised scripts, XSS attempts, and Magecart skimming attacks trying to run in the browser, with full context on what triggered each violation.
- File integrity monitoring. Identifies every server-side file change on Magento or Adobe Commerce, whether from a misconfiguration, a bad deploy, or a malicious intrusion.
- Continuous malware detection. Scans for known malware signatures, suspicious code patterns, and unauthorised injections silently introduced through compromised third-party vendors.
Together, these four give you the client-side visibility PCI-DSS v4.0.1 requires and a continuous record you can point to at audit time.
Compliance is a by-product of visibility
The mindset shift v2 encourages is simple: stop treating PCI-DSS v4.0.1 as a form to fill in once a year and start treating it as a continuous state you can see at any moment.
When you have a live inventory of every script, real-time violation alerts, and a continuous record of what changed and when, compliance stops being a scramble before the audit. It becomes something you can simply demonstrate, at any point, to anyone who asks.
1. For merchants Most stores accepting card payments today have a client-side compliance gap, and most do not know it. The scripts running on your checkout pages are changing faster than any manual process can track. Continuous visibility is not just a compliance requirement; it is the only realistic way to know your store is secure between audits.
2. For agencies Most of your clients have the same gap, and most have not been told about it yet. Walking into that conversation with a live script inventory and real-time violation data is both a service and a positioning move. It turns a compliance requirement into a reason clients stay, and a reason new ones sign.
Showing them what is running on their checkout pages is often all it takes to start that conversation. Try AuditIQ eCommerce monitoring tool for free and close the compliance gap before your next audit.
About the author
Dan Garner writes from AuditIQ's experience monitoring eCommerce performance, SEO, security, and reliability issues across Magento, Shopify, WooCommerce, and Adobe Commerce stores.