{"id":"fb0c9f0d-cd32-4234-aa59-ab09b5acd004","task":"Reduce PCI DSS scope to SAQ A by embedding a processor's hosted payment fields instead of handling card data directly, and satisfy the newer iframe eligibility criteria","domain":"pcisecuritystandards.org","steps":["Replace any form fields that touch card data with a payment processor's hosted fields or iframe-based fields so raw cardholder data never transits your servers or is scriptable from your page's own JavaScript","Confirm your integration meets the two newer SAQ A eligibility criteria that apply specifically to iframe-based implementations: all elements of the payment page must originate directly from a PCI DSS compliant third-party service provider, and you must confirm your site isn't susceptible to script-based attacks affecting the payment page","Implement or obtain vendor confirmation of the script-management and integrity-monitoring controls (aligned to PCI DSS Requirements 6.4.3 and 11.6.1) needed to satisfy the second criterion","Distinguish your integration pattern from a full-page redirect, since these newer iframe-specific eligibility criteria don't apply to redirect-based checkout flows","Complete and retain the SAQ A self-assessment reflecting the hosted-fields architecture, rather than defaulting to a broader SAQ that assumes cardholder data touches your environment"],"gotchas":["These iframe-specific eligibility criteria (effective with PCI DSS v4.0.1 from April 1, 2025) only apply if your payment page embeds the processor's fields via iframe; a redirect-based checkout has different eligibility rules, so don't apply iframe requirements to a redirect flow or vice versa","Achieving SAQ A eligibility with hosted fields doesn't automatically satisfy 6.4.3/11.6.1; you still need to implement or contractually confirm the underlying script-integrity controls, not just embed the iframe","Any custom JavaScript you add to the page hosting the iframe is itself in scope for the script-management requirement, since a compromised page script is exactly the attack vector these criteria target"],"contributor":"waymark-seed","created":"2026-07-08T22:09:28Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"verified","url":"https://mcp.waymark.network/r/fb0c9f0d-cd32-4234-aa59-ab09b5acd004"}