PCI DSS 4.0.1: Application Requirements You’re Being Assessed On in 2026
ID: 02360fce-47f1-5ffd-b713-24a5ee65a8ab
STIX ID: report--02360fce-47f1-5ffd-b713-24a5ee65a8ab
Feed Name: Qualys Blog
**Executive summary:** The report explains that as of 31 March 2025 the 51 former PCI DSS 4.0 “best practice” requirements are now scored, shifting assessment emphasis to application and API security—especially Requirements 6 and 11—which mandate inventories of custom applications/APIs and payment-page scripts, authenticated and continuous scanning, and tamper-detection. It warns that active e-skimmer/Magecart campaigns have infected thousands of e-commerce domains and resulted in large card data exposures, and positions Qualys TotalAppSec as a solution to continuously discover applications/APIs, inventory payment-page scripts, perform authenticated scanning, detect integrity issues, and feed findings into attestation workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
