Home › Intelligence › Brief
BREACH BRIEF🟠 High Advisory

PCI DSS 4.0.1 Makes Application Inventory, Script Change Detection, and Authenticated Scanning Mandatory for 2026

All 51 former best‑practice items in PCI DSS 4.0 are now scored, forcing organisations to prove continuous inventory of custom apps/APIs, script‑change detection on payment pages, and authenticated scanning. Failure to produce this evidence will be a scored gap in the 2026 assessment, highlighting the need for continuous control mapping and audit‑ready evidence.

LiveThreat™ Intelligence · 📅 August 27, 2026· 📰 blog.qualys.com
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
blog.qualys.com

PCI DSS 4.0.1 Application Requirements Become Mandatory for 2026 Assessments

What Happened – Effective 31 Mar 2025 the 51 former “best‑practice” items in PCI DSS 4.0 were upgraded to scored requirements. All 2026 assessments must now verify inventory of every custom app and API, continuous protection of public‑facing apps, payment‑page script management, authenticated scanning, and risk‑based prioritisation (Requirements 6 & 11).

Why It Matters for Compliance & Audit Readiness

  • The new scored controls create a control‑gap risk that auditors will flag if you cannot prove an up‑to‑date inventory or change‑detection for payment‑page scripts.
  • Continuous evidence (e.g., automated discovery, authenticated scans) is now a mandatory audit artifact under PCI DSS 4.0.1, mirroring SOC 2’s evidence‑collection expectations.
  • Mapping these application controls to a Control‑Mapping framework lets you generate the same continuous proof used in SOC 2 audits, reducing duplicate effort.

Who Is Affected – Payment‑card merchants, SaaS platforms that process card data, and any organisation subject to PCI DSS (financial services, e‑commerce, hospitality, etc.).

Recommended Actions

  • Deploy an automated inventory tool that continuously discovers custom apps and APIs.
  • Enable authenticated scanning for all public‑facing applications and integrate findings into your PCI‑ASV workflow.
  • Implement a script‑change detection mechanism on every payment page and retain logs as audit evidence.
  • Align the new PCI controls with your existing SOC 2 control map to reuse evidence across frameworks.

Source: Qualys Blog – PCI DSS 4.0.1 Application Requirements You’re Being Assessed On in 2026

Technical Notes – The PCI DSS 4.0.1 updates focus on Requirements 6.4.3 (full script inventory) and 11.6.1 (unauthorised‑change detection). No specific CVE is cited; the change is a policy‑level control expansion that forces continuous application‑security monitoring.

📰 Original Source
https://blog.qualys.com/product-tech/2026/08/27/pci-dss-4-0-1-application-requirements-youre-being-assessed-on-in-2026 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →