logo

Top 5 Mistakes SAQ A-EP Merchants Are Making in 2025 That Will Knock Them Out of PCI 4.0 Compliance

ID: cbcf0fe0-f217-5b31-a404-9ba47630daa8

STIX ID: report--cbcf0fe0-f217-5b31-a404-9ba47630daa8

Feed Name: Security Boulevard

Date Published: 2025-01-04

Date Updated: 2026-04-22

Author: mykola myroniuk

...
...

This advisory warns SAQ A-EP e-commerce merchants that PCI DSS 4.0.1 introduces mandatory controls—particularly Requirements 6.4.3 (comprehensive script inventory and monitoring) and 11.6.1 (real-time detection and alerts)—and that many organizations mistakenly rely on self-assessments or TPSP iframes, annual scans, or poor documentation. It outlines five common mistakes (assuming scripts are out-of-scope, ignoring 6.4.3, neglecting 11.6.1, relying on annual scans, and failing to keep audit trails) and recommends implementing automated script discovery, continuous monitoring with alerting, centralized logging, and documented audit trails to maintain compliance and reduce breach risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.