Defend your site against client-side JavaScript threats and streamline PCI DSS v4.0.1 compliance — without adding friction to the user experience.
What’s changed in PCI DSS v4.0.1 for client-side JavaScript
The PCI Security Standards Council updated SAQ A eligibility in PCI DSS v4.0.1. SAQ A merchants no longer validate specifically to Requirements 6.4.3 and 11.6.1. Instead, to use SAQ A you must confirm your entire website is secure against script-based attacks — not just payment pages. PSPs and merchants using SAQ A-EP or SAQ D must still meet 6.4.3 and 11.6.1.
How Akamai helps you meet PCI script security requirements
Whether you validate with SAQ A and need whole-site client-side protection, or you must demonstrate conformance to 6.4.3 and 11.6.1, Akamai Client-Side Protection & Compliance provides purpose-built controls and audit evidence:
Automated script inventory and authorization on payment pages, with predefined justifications and policy rules to document script purpose.
Real-time, in-browser behavior analysis of all executing scripts to detect anomalous or unauthorized actions.
Change detection for script behavior, HTTP headers, and payment page protections to identify tampering.
Dedicated PCI dashboards and alerts to speed response and supply auditors with clear evidence.
External QSA validation confirming how the solution addresses PCI DSS v4.0 requirements for vulnerability management and monitoring/testing. Get the QSA validation white paper.
If you require server-side protections as well, Client-Side Protection & Compliance pairs with Akamai App & API Protector to deliver holistic defense across client and server.
Stop web skimming and Magecart on payment pages
Modern skimming, formjacking, and Magecart campaigns run in the browser, targeting third-party scripts and supply chains. Client-Side Protection & Compliance:
Instruments real-user sessions to monitor script execution at runtime.
Uses machine-learning risk assessment to flag suspicious data access or exfiltration.
Sends real-time, prioritized alerts with mitigation guidance.
Enables one-click mitigation to immediately restrict malicious scripts from accessing or exfiltrating sensitive data (e.g., cardholder data, credentials, PII).
Get full visibility into third‑party JavaScript behavior
Gain the client-side visibility traditional server-side tools can’t provide:
Comprehensive script inventory with continuous behavior tracking.
Intelligence on which scripts access sensitive data, where data could flow, and potential blast radius.
Detection of Common Vulnerabilities and Exposures (CVEs) and recurring threat patterns.
Risk scoring and detailed incident reports to accelerate triage and response.
Client-Side Protection & Compliance complements a WAF. Because WAFs analyze server-side traffic, they can’t see attacks that execute solely in the end user’s browser. This solution closes that blind spot.
How it works
Set up: Add a lightweight script to monitored pages. No meaningful impact on performance.
Assess: Continuously monitor script actions from the browser; ML analyzes risk of unauthorized behavior.
Alert: Receive real-time, prioritized alerts with context and recommended actions.
Mitigate: Block or restrict suspicious scripts instantly to prevent data exfiltration.
Why this approach
Built for PCI workflows: Purpose-built tooling for script inventory, justification, change tracking, and evidence collection aligned to PCI DSS v4.0/v4.0.1.
Runtime detection and response: Behavior-based monitoring in real time — beyond static allowlists or tag governance alone.
Flexible, CDN-agnostic deployment: Works on or off Akamai Connected Cloud; supports complex sites and single-page applications.
Performance-conscious: Designed for minimal overhead; no manual updates needed when your site changes.