The Hidden Trap in the PCI DSS SAQ A Changes
ID: a862d738-d7ce-5cbd-8220-ebac17f09665
STIX ID: report--a862d738-d7ce-5cbd-8220-ebac17f09665
Feed Name: TrustedSec blog
TrustedSec explains that PCI SSC updated SAQ A by removing explicit requirements 6.4.3 and 11.6.1 and replacing them with a new eligibility criterion requiring merchants to confirm their site is "not susceptible" to script-based attacks (e.g., web skimming/Magecart). The post details who is affected (iFrame-hosting eCommerce merchants), the ambiguity around whether protection must be site-wide or page-specific, recommended options to remain eligible (continue implementing 6.4.3/11.6.1, obtain processor attestation, perform targeted web application testing, deploy/configure a WAF, use CSP/SRI), and urges merchants to consult QSAs ahead of the April 1, 2025 deadline.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
