Requirement

PCI DSS 6.4.3

The payment-page script requirement in plain terms: an inventory of authorized scripts, a written justification for each, and a record of who approved it.

What the requirement asks for

A payment page may only load scripts that someone has authorized. For each of those scripts there must be a written justification — what it does, and why it has to run on that page — and a named person who approved it. An inventory that a system generated and nobody signed is not the record.

What the evidence looks like

An assessor asks to be shown three things that stay together: the list of scripts that ran on pages in payment scope, the justification written against each one, and who approved it. A change to an authorized script is a new decision, not an edit of the old one.

Which pages are in scope

The pages that collect or transmit payment-card data. On a hosted checkout that is often a small set of URL patterns the merchant declares. The SAQ type they validate under decides how far that set reaches; it is not something a scanner can infer from the storefront.

What Tagnovo produces, and what it does not

Tagnovo is not a QSA and does not certify compliance. It produces the inventory, the authorization record and the change evidence that an assessor asks to see.Tagnovo Manifest is the product that does it.