Requirement
PCI DSS 11.6.1
What the requirement asks for, how a change-detection mechanism is expected to behave, and the evidence an assessor asks to be shown.
What the requirement asks for
A mechanism that notices when the scripts or HTTP headers a payment page delivers are not the ones that were authorized, and alerts someone who can do something about it. A weekly screenshot is not that mechanism.
How a change-detection mechanism is expected to behave
Each authorized script is fingerprinted. A hash that no longer matches is a change, whether or not the file name stayed the same. Headers are recorded as the browser received them, not as the origin intended to send them — a CDN or a tag manager in the middle is still a change the page saw.
How often it has to run
Often enough that a change cannot sit unnoticed through a reporting period. At the end of that period a named person attests to what was observed and what they reviewed. The attestation is a human record; the detections are what it is attesting to.
What Tagnovo produces, and what it does not
Tagnovo is not a QSA and does not certify compliance. It produces a dated record of every change observed in the period and who reviewed it.Tagnovo Manifest is the product that does it.