The usual mistake
Filing last year's pen-test PDF against 11.6.1 because both mention "security" and "payment pages". An assessor who has read the clause will ask for the weekly record.
Requirement 11.6.1 is continuous by construction. An annual test can find a hole that was there on the day. It cannot notice a script that was swapped and swapped back inside a week.
Last reviewed against PCI DSS v4.0.1 in September 2026.
| Yearly penetration test | What 11.6.1 asks for | |
|---|---|---|
| How often | Once, on a booked date | At least every seven days |
| What it looks at | Whatever the tester can reach that week | The payment page as the customer's browser received it |
| A script added on Tuesday and removed on Thursday | missed | a dated change record |
| Headers as delivered | Sometimes, if the tester thought to record them | Part of the requirement |
| Skimmer that sleeps for automated browsers | Often served the clean page | Needs a reading from a real visitor's browser |
| Evidence an assessor can file | A report for that engagement | A baseline, weekly checks, change records, and who was alerted |
A penetration test is better at finding a logic flaw, an open admin path, or a misconfigured origin. Tagnovo does not do that work and will not pretend to. If your acquirer asked for a pen test, you still need the pen test.
What it is not: a substitute forrequirement 11.6.1. The wording is about unauthorized change to payment pages, detected at least weekly, as received. That is a different job.
Filing last year's pen-test PDF against 11.6.1 because both mention "security" and "payment pages". An assessor who has read the clause will ask for the weekly record.
A baseline of authorized scripts, timestamped checks, every change, and who reviewed it.How Manifest produces that pack.
We are not a QSA and this is not advice. Ask your acquirer what evidence they want to see for 11.6.1. Three sentences that get that answer in writing.
A baseline of authorized scripts, timestamped checks, every change, and who reviewed it. Tagnovo is not a QSA and does not certify compliance.