Payment page monitoring watches the scripts on your checkout every day, keeps the written reason for each one, and tells you when something new appears. It is the part of PCI DSS 6.4.3 that a single check cannot do, because every word of that requirement is about time.
What it does
Once a day we load your payment page and read what came back. Then we compare it against every previous day.
- It dates every script. Not "you have seven scripts" but "this one first appeared on 14 September". That sentence is what an assessor asks for, and no one-off check can produce it.
- It holds your justifications. Requirement 6.4.3 asks for a business reason, in writing, for every script on the page. Nobody can write those for you. We keep them, show which scripts are still missing one, and flag it the moment a script turns up without a reason.
- It records that it looked. Every page carries a note of which days a scan reached it and which days it did not. A quiet week means we checked and nothing moved, rather than that something broke in March and stopped reporting.
- It emails you when something changes, and emails you every week when nothing has. The second one is the harder half, and it is the half that proves the first one still works.
- It watches how the page is served. HTTPS, HSTS, Content Security Policy, framing, and your certificate's issuer and expiry date. If one of those is weakened after having been in place, that is a change and you hear about it.
- It hands you the evidence. A dated inventory of every script, who serves it, when it was first seen and the reason you wrote, as a spreadsheet or as a report you can print and put in front of an assessor.
What it is not
We would rather be straight about the edges of this than have you find them later.
- It is not a pass or a fail, and it is not an ASV scan. Our ASV accreditation covers external vulnerability scanning, which is a separate service with a separate report. This service produces an inventory and a record of changes, and it never issues a verdict on your site.
- It reads the page as it is delivered. That means the scripts written into your HTML and the headers around them. Scripts that a tag manager adds after the page starts running are the known gap, and rather than pretend otherwise, every report states how much of the page each scan actually covered.
- It cannot write your justifications. Only you know why a marketing tag is on a checkout page. The service holds the answers and chases the blanks; the answers are yours.
- It does not remove anything. We tell you what is there. Deciding what comes off the page is your call, and taking a script off is usually the better answer than justifying it.
Why it has to be more than once
A digital skimmer is a few lines of JavaScript added to a checkout page. It reads the card fields and sends what it sees to an address the attacker controls. The page still works. The order still completes. Nothing looks wrong to you or to your customer.
The code usually arrives through something your page already trusts, such as a tag manager, a chat widget or an analytics library that was compromised upstream. An inventory written once and filed is accurate for about as long as it takes somebody to update one of those.
Requirement 11.6.1, which sits alongside 6.4.3 and shares its mandatory date of 31 March 2025, asks for a mechanism that alerts staff to unauthorised changes to your payment page and its headers, run at least weekly. Knowing that something appeared on the checkout last Tuesday is the whole point, and a document in a folder cannot tell you that.
More on what requirement 6.4.3 asks for.
What it costs
There are two ways to buy payment page monitoring. As an option on a scanning subscription, chosen when you sign up, at $20 a quarter or $64 a year on top of the scan. Or on its own, without a scan, at $24 a quarter or $77 a year.
| Plan | Scanning | With monitoring | Add-on |
|---|---|---|---|
| Quarterly | $59 | $79 | +$20 per quarter |
| One year | $188 | $252 | +$64 per year |
The annual add-on works out cheaper than four quarters of it, in the same shape as the scanning plans. One payment page per subscription. If you need several watched, tell us how many and we will come back with a price.
Try the free check first
Our free payment page check will read your checkout page once, right now, and list the scripts written into its HTML along with the ones served from a domain other than yours. No sign-up, and nothing is published.
It is the same reading that monitoring does, done once instead of every day, and it is the quickest way to see whether there is anything on your checkout worth watching. Most people are surprised by at least one entry on that list.
Sign up for payment page monitoring, or add it to a scanning subscription if you want a scan with it.