The biggest takeaway from this year's PCI NA meeting: compliance and security are converging. PCI requirements, 11.6.1 especially, are pushing organizations to prove their controls actually stop attacks, not just that the paperwork is complete.
E-commerce skimming, payment page monitoring, and artificial intelligence dominated conversations at this year's PCI Community Meeting in North America.
Our team of assessors, forensic investigators, and payment security specialists spent three days talking with merchants, acquirers, payment brands, and fellow QSAs.
.jpeg)
Here are the themes we heard most often and what they mean for organizations working toward PCI DSS v4.0.1 compliance:
Requirement 11.6.1 is still unsettled
What is required to comply with PCI requirements 6.4.3 and 11.6.1?
PCI requirement 11.6.1 requires merchants to have a change- and tamper-detection mechanism in place to routinely detect unauthorized changes to HTTP headers and the contents of payment pages as the customer's browser receives them. It pairs with requirement 6.4.3, which calls for an inventory, authorization and integrity checks for every script on the payment page.
SecurityMetrics Shopping Cart Monitor can help address both PCI requirements 6.4.3 and 11.6.1.
What issues are there surrounding 11.6.1?
Requirement 11.6.1 remains one of the most debated requirements in PCI DSS v4.0.1.
Security assessors still don't share a common standard for how change- and tamper-detection on payment pages should be implemented.
For example, merchants often hear varying responses from assessors about questions like:
- Which pages are in scope? Only the payment page or the whole path to checkout?
- Is a weekly scan of your checkout page enough, or do we need to monitor what actually runs in the customer's browser?
- What counts as an acceptable baseline, and how are authorized changes approved?
Until the industry agrees, merchants should document why they chose their approach and confirm it with their QSA early, before the assessment starts.
What solutions exist on the market for 6.4.3 and 11.6.1?
As part of our presence at the North America Community Meeting, we demoed Shopping Cart Monitor (SCM). SCM was intentionally designed to make the compliance process easier, particularly when meeting requirements 6.4.3 and 11.6.1.
Shopping Cart Monitor works by:
- Creating a snapshot of what the checkout process looks like
- Flagging any abnormal or suspicious scripts that appear during checkout
- Reporting them directly to the organization for review
- Minimizing false positives
- Causing zero disruptions to business
SCM is an agentless solution and doesn’t require the web development team that a code-based solution would. And since it’s agentless, it can't be tampered with or subverted, making it the more secure option.
What forensic investigations reveal about 11.6.1 monitoring
SecurityMetrics Sr. VP John Bartholomew (JB) in his tech talk “PCI Requirement 11.6.1 Monitoring: Lessons Learned” argued that many monitoring approaches meet the letter of 11.6.1 but miss real attacks. His examples came straight from our forensic investigations.
His core message: a monitoring tool built only to check a compliance box is not the same as a security control that catches skimmers. Based on what our investigators see in breached environments, effective monitoring needs four things.
1. Watch the whole shopping journey, not just the payment page
Attackers don't always target the checkout page. Skimmers are injected earlier in the journey, on product or cart pages, or they redirect shoppers to a fake alternate payment form. Monitoring limited to the payment page won't see them.
2. Interact with the page the way a shopper does
Simply loading a page, as a common crawler or spider does, doesn't trigger every script. Some skimmers load only when a form is filled in, or only for visitors in certain locations. Monitoring has to move through the cart and checkout like a real customer to see what actually runs.
3. See everything the browser does
Scripts are only part of the picture. Monitoring should also cover cookies, local storage, HTTP and WebSocket traffic, WebRTC and browser memory. JB showed examples of:
- A trusted marketing analytics script, typically ignored, that had been quietly changed to steal card data
- A stealth skimmer that used WebRTC to load itself, or to hide stolen data inside a media stream
4. Resist tampering, and learn from past attacks
Monitoring that runs as a visible script or agent on the page can be spotted and bypassed by attackers, and AI may make that easier. JB also stressed that analysis should draw on lessons from past forensic cases. Some attacks we've investigated left nothing on the page at all, including:
- Conditional scripts that behave normally until specific conditions are met
- Stolen admin credentials used to send encrypted payment data to the attacker's server, with no skimmer visible in the browser
For merchants, the takeaway is to ask how a monitoring solution would catch attacks like these, not just whether it satisfies 11.6.1 on paper.
It’s essential to establish a baseline of security by having an expert check the health of your ecommerce site. That’s why our forensic investigators use Shopping Cart Inspect (SCI) to help provide a baseline to security, as well as give merchants:
- A prioritized list of vulnerabilities
- A ranking of your vulnerabilities from medium to high-risk based on the CVSS scale
- Description of malicious javascript
- Identification of suspicious URLs on your website
- Expert remediation recommendations and techniques
- 24/7 technical support for remediation
E-commerce skimming and recovery are top of mind
The questions we heard most often at our booth were about shopping cart malware: how to detect it, and what to do after it's found.
That tracks with what our forensic team sees. E-commerce skimming remains one of the most common causes of card data compromise for online merchants, and attackers keep adjusting their techniques to avoid detection.
Several attendees also told us that they value real-world forensic intelligence over theory. This is because how breaches actually happen impact how security teams need to prepare.
Acquirers want to see risk across their whole portfolio
Large acquirers are looking for ways to measure the security risk of every merchant in their portfolio.
That theme came up repeatedly in the Council's Data and Environment Task Force, where SecurityMetrics participates alongside acquirers and payment brands. Annual self-assessment questionnaires (SAQ) tell an acquirer whether a merchant says it's compliant. They don't show which merchants are already breached or have weak security practices in place.
That’s where SecurityMetrics Spectre AI can help acquirers.
“Spectre AI from SecurityMetrics is a beyond-PCI tool that can go through an entire portfolio (all of your URLs). It comes back with a prioritized risk assessment based on real, exploitable vulnerabilities” said JB during his presentation.
How can acquirers use Spectre AI?
Spectre AI gives you an unprecedented look into your merchant portfolio, showing you who is most at risk of a data breach, who lacks key compliance safeguards, and whose ecommerce site is most in danger.
With Spectre AI in place, you can prevent costly breaches before they happen. Check out our demo of Spectre AI for a peek into what it can do for you and how it will keep your portfolio secure and satisfied.
AI was the topic nobody could avoid
Nearly every conversation touched on AI. Attendees wanted to know how to keep up with it, and how it should be used in compliance and security programs.
We heard AI discussed on both sides of the fight:
- AI as a tool for defenders. AI can help merchants work through compliance questions, and help acquirers sort large portfolios by risk. If AI agents are trained on real forensic cases, they might also be able to flag suspicious script behavior faster than manual review. AI that only restates the requirements won't tell you whether your website is compromised.
- AI as a tool for attackers. AI has the capability to build e-skimmers that could detect and evade visible monitoring tools. These skimmers might be able to constantly change to avoid signature-based detection.
Franchises and small merchants still need clearer guidance
Two groups came up again and again as underserved: franchise systems and small, specialized businesses.
Franchise systems
Hospitality and fuel franchisors told us they want a simple way to help franchisees validate compliance. Each location is often its own merchant, but a breach at one location can hurt the whole brand. Franchisors are looking for a program they can offer across locations without running compliance for each one themselves.
Small, specialized merchants
A payments partner described confusion in the dental community about card-present compliance requirements.
It's a common pattern. Small practices and shops take card payments every day, but PCI DSS can feel written for someone else. Plain-language guidance on which SAQ applies, and what the terminal and network requirements mean, would go a long way.
Around the booth
Thanks to everyone who stopped by. Our custom t-shirts went fast, the Compliance Cat broke the ice, and the lounge chairs got plenty of use between sessions. Our booth drew a steady crowd all week.

.jpeg)
We were also pleased to be joined by Jeremy King, former Regional VP, EMEA of the PCI SSC.
We also enjoyed recording conversations for the SecurityMetrics Podcast with Principal Security Analyst Jen Stone. Watch for upcoming episodes featuring voices from the PCI community.
What's next
The biggest takeaway from this year's meeting: compliance and security are converging. The requirements, 11.6.1 especially, are pushing organizations to prove their controls actually stop attacks, not just that the paperwork is complete.
If you have questions about 11.6.1, payment page monitoring or your PCI DSS assessment, talk to our team. You can also learn more about SecurityMetrics Shopping Cart Monitor.




