PCI_DSS_v4Requirement 6voice-validated

PCI_DSS_v4 R6: Requirement 6

PCI_DSS_v4

AL
Adam Lundqvist
Founder at SQUR · last verified 2026-10-06

Regulation text

Bespoke and custom software used in the cardholder data environment must be developed securely. Software-development processes shall incorporate security considerations from the start of the SDLC, including secure coding training, code review, security testing, and remediation of vulnerabilities discovered. Public-facing web applications are addressed by either pen-testing or a deployed automated solution.

ATT&CK techniques this article tests · 0

TechniqueWhy it mapsConfidence

Defending mitigations · 0

MitigationWhat it doesConfidence

Underlying weaknesses · 7

CWEWhy it persistsConfidence
CWE-791. Improper Neutralization of Input (Cross-site Scripting) is a common web application vulnerability. 2. Secure coding training and code review directly address this by enforcing proper input validation and output encoding.
90%
CWE-891. Improper Neutralization of Special Elements (SQL Injection) is a critical vulnerability. 2. Secure coding practices, including parameterized queries and input sanitization, are fundamental to preventing this weakness.
90%
CWE-201. Improper Input Validation is a root cause for numerous vulnerabilities. 2. Secure development processes, starting early in the SDLC, prioritize robust input validation to prevent many attack types.
90%
CWE-3521. Cross-Site Request Forgery (CSRF) is a common web application vulnerability. 2. Secure coding guidelines and security testing, including pen-testing, help identify and mitigate CSRF risks.
80%
CWE-5021. Deserialization of Untrusted Data can lead to remote code execution. 2. Secure development practices must include careful handling of deserialization, often identified through code review and security testing.
80%
CWE-2871. Improper Authentication allows unauthorized access to systems. 2. Secure development ensures robust authentication mechanisms are designed, implemented, and tested correctly throughout the software lifecycle.
80%
CWE-6111. Improper Restriction of XML External Entity Reference (XXE) can lead to information disclosure or SSRF. 2. Secure coding practices and security testing identify and prevent XXE vulnerabilities in XML parsers.
70%

What SQUR Covers

Web application + API pentesting for OWASP Top 10, business logic flaws, authentication bypass, injection attacks, and other application-layer vulnerabilities. €1,995 per scan, 24-hour turnaround, EU-only data.

What SQUR Does Not Cover

Internal network pentesting, endpoint security testing, physical security assessments, social engineering, or ICT third-party concentration risk reviews. Engage a complementary provider for those scope items.

Provenance

Mapped Q2.2026 using gemini-2.5-flash · €0.0191 compute · voice-rubric self-validated