PCI DSS Requirement 6 – Explained 

PCI DSS stands for Payment Card Industry Data Security Standard. It’s a set of globally recognised security requirements designed to ensure that businesses protect payment card data. This article focuses on Requirement 6 of PCI DSS v4.0.1 – what it means, how it’s evolved from version 3.2.1, and what your organisation needs to do to stay compliant. 

For more on PCI DSS, see our Ultimate Guide. 

What is PCI DSS Requirement 6? 

Requirement 6: Develop and maintain secure systems and software 

This requirement ensures that organisations implement security throughout the software development lifecycle and apply patches and updates promptly to protect against known vulnerabilities. It applies to both internally developed and third-party software, including commercial applications and open-source components. 

This requirement emphasises secure coding practices, vulnerability management, and change control processes to reduce the likelihood of systems being compromised through software flaws. It also applies to both production and non-production environments, such as development and testing systems, if they store, process, or transmit account data or provide access to the cardholder data environment. 

By embedding security into software development and maintenance, organisations reduce the risk of exploitation due to coding errors, unpatched systems, or poor change control. 

Why is Requirement 6 important? 

Attackers are constantly scanning for weaknesses in software that they can exploit. These vulnerabilities may be: 

  • Publicly disclosed issues with available patches 
  • Flaws caused by insecure coding practices 
  • Back doors or security gaps introduced by third-party components 

Requirement 6 helps organisations reduce these risks by following secure software development and maintenance practices. 

Key changes in PCI DSS v4.0.1 for Requirement 6 

Changes from v3.2.1 to v4.0.1 include: 

  • Increased focus on patch management and maintaining software inventories 
  • More detailed requirements around secure development training and code reviews 
  • Broader application protection that includes both internal and external applications 
  • Option for a customised approach for organisations with mature development practices 

PCI DSS v4.0.1 places more emphasis on: 

  • Continuous identification and remediation of vulnerabilities 
  • Secure software development lifecycle (SDLC) practices 
  • Protection of all bespoke and custom applications, not just web apps 
  • Use of automated tools and threat intelligence 

A breakdown of Requirement 6 

6.1 – Processes and mechanisms for developing and maintaining secure systems and software are defined and understood.

Organisations must formally define and document the processes and mechanisms used to develop and maintain secure systems and software. These processes must be communicated and understood by all relevant personnel. This includes assigning roles and responsibilities, setting out secure development policies, and maintaining awareness of current threats and industry best practices. The aim is to ensure a consistent and secure approach across all environments. 

6.2 – Bespoke and custom software are developed securely.

Secure coding practices must be followed when developing bespoke or custom software. This includes training developers on secure development, integrating security into each phase of the development lifecycle, and using techniques such as code reviews, static/dynamic analysis, and threat modelling. The goal is to eliminate security vulnerabilities before software is deployed into production environments. 

6.3 – Security vulnerabilities are identified and addressed.

Organisations must identify vulnerabilities in systems and software through a combination of threat intelligence, vendor-provided updates, and automated tools. Once identified, vulnerabilities must be risk-assessed and addressed based on their severity. This includes timely installation of patches and updates, and verification that fixes have been applied successfully. Delays in patching known issues can leave systems open to attack. 

6.4 – Public-facing web applications are protected against attacks.

Public-facing web applications must be protected against known threats such as injection attacks and cross-site scripting. This can be achieved either through secure coding practices and thorough testing, or by deploying web application firewalls (WAFs) or similar technical controls. These protections must be kept up to date and effectively maintained. 

6.5 – Changes to all system components are managed securely.

All changes to system components must follow a formal change control process that includes documentation, testing, and approval before implementation. This helps prevent unintended security flaws from being introduced during updates, configuration changes, or system modifications. Change control must also include back-out procedures and an audit trail of changes for accountability and troubleshooting. 

Common challenges with Requirement 6 

Organisations often face challenges such as: 

  • Incomplete inventories of custom-developed software 
  • Delays in patching, especially with legacy systems 
  • Gaps in developer training or lack of secure coding standards 
  • Over-reliance on firewalls rather than addressing vulnerabilities directly 
  • No formal process for code reviews or validating security in the SDLC 

How Securious Can Help 

Securious has been a PCI QSAC since 2016, with a team of qualified, highly experienced PCI DSS QSA and 3DS assessors ready to assist you in achieving and maintaining compliance with the latest PCI DSS standards. 

Based in Exeter, Devon, we undertake PCI QSA work both nationally and internationally. We are the only PCI DSS QSA company in our region, so organisations in Devon, Cornwall, or Somerset can benefit from cost efficiencies with on-site assessments. 

Our mission is to build cyber security confidence. When it comes to PCI DSS compliance, we collaborate with you to make the process as efficient as possible, helping you understand what needs to be done and why. 

We offer three options to assist our clients with PCI DSS compliance: 

  1. PCI DSS QSA Gap Analysis & Assessment (one-off fee)
    Read more about our PCI DSS QSA Gap Analysis & Assessment by clicking here.
  1. Managed PCI DSS Compliance Service (fixed monthly fee)
    Read more about our Managed PCI DSS Compliance Service by clicking here.
  1. Assisted PCI DSS SAQ Compliance Service (one-off fee)
    Read more about our Assisted PCI DSS SAQ Compliance Service by clicking here. 

Get in Touch to Get Started 

To learn more, visit our PCI services page, call us on 01392 247 110, email info@securious.co.uk, or send us a message using the form below. 

Find out whether you’re ready for PCI DSS v4.0.1 in minutes.