Client-Side Protection & Compliance

Defend your site against client-side JavaScript threats and streamline PCI DSS v4.0.1 compliance — without adding friction to the user experience.

What’s changed in PCI DSS v4.0.1 for client-side JavaScript

The PCI Security Standards Council updated SAQ A eligibility in PCI DSS v4.0.1. SAQ A merchants no longer validate specifically to Requirements 6.4.3 and 11.6.1. Instead, to use SAQ A you must confirm your entire website is secure against script-based attacks — not just payment pages. PSPs and merchants using SAQ A-EP or SAQ D must still meet 6.4.3 and 11.6.1.

Learn more in our overview of the SAQ A update and what it means for your ecommerce site. Read the PCI DSS v4.0.1 SAQ A update.

How Akamai helps you meet PCI script security requirements

Whether you validate with SAQ A and need whole-site client-side protection, or you must demonstrate conformance to 6.4.3 and 11.6.1, Akamai Client-Side Protection & Compliance provides purpose-built controls and audit evidence:

If you require server-side protections as well, Client-Side Protection & Compliance pairs with Akamai App & API Protector to deliver holistic defense across client and server.

Stop web skimming and Magecart on payment pages

Modern skimming, formjacking, and Magecart campaigns run in the browser, targeting third-party scripts and supply chains. Client-Side Protection & Compliance:

Get full visibility into third‑party JavaScript behavior

Gain the client-side visibility traditional server-side tools can’t provide:

Client-Side Protection & Compliance complements a WAF. Because WAFs analyze server-side traffic, they can’t see attacks that execute solely in the end user’s browser. This solution closes that blind spot.

How it works

Why this approach

Resources and next steps

Ready to see it in action or scope your deployment? Contact our team.