February 1, 2024

PCI DSS Requirement 6: What Is It & How to Comply?

PCI DSS Requirement 6 suggests that businesses should ensure that all systems and applications developed or used by the company are secured.

By
Full name
Share this post
https://www.hicomply.com/en-us/hub/pci-dss-requirement-6
A woman smiles while using a tablet, surrounded by digital notifications and a data chart.

What is PCI DSS Requirement 6?

PCI DSS Requirement 6 suggests that businesses should ensure that all systems and applications developed or used by the company are secured. This requirement also deals with patch management and addressing vulnerabilities.

By implementing watertight coding standards that are regularly reviewed, especially when it comes to your application environment, you can protect your business from experiencing an attack or a breach.

{{snapshot}}

What Requirement 6 covers

  • Ensure all systems and applications developed or used by the company are secured.
  • It deals with patch management and addressing vulnerabilities as they emerge.
  • Watertight, regularly reviewed coding standards help protect against attacks and breaches.

{{/snapshot}}

PCI DSS 6.1: Rank vulnerabilities based on severity.

This requirement calls for companies to establish processes for identifying and addressing vulnerabilities that may impact the security of their internal systems and applications.

Verified outside sources, such as the Common Vulnerabilities and Exposures (CVE) list, would need to inform how these vulnerabilities are addressed. This also requests that companies assign risk rankings in order of severity (low, medium, high) to all vulnerabilities that have been identified.

An external assessor will also interview the relevant personnel to confirm that the controls are being performed correctly.

PCI DSS 6.2: Patches need to be applied for all known security vulnerabilities.

Businesses must ensure they are protected against all known vulnerabilities by installing security patches as soon as they’re made available by vendors. These critical patches cannot be installed any later than a month after their production, and necessity will depend on the affected network’s risk ranking.

As with PCI DSS Requirement 6.1., a qualified assessor will also need to scan a sample of the business’ system components. These results will be cross-referenced with your vendors’ lists of relevant and available patches so that they can be installed in the right time frame.

PCI DSS 6.3: Develop all apps securely.

This requirement calls for the secure development of internal, external and web apps through the following sub-sub requirements:

  • PCI DSS 6.3.1 – Remove all accounts and settings created for either development or testing purposes before making apps or software usable by clients or publicly available.
  • PCI DSS 6.3.2 – Review all custom code for vulnerabilities, whether manually or through an automation process, before making apps or software usable by clients or publicly available.

{{snapshot}}

Ranking, patching, and secure development

  • Rank vulnerabilities by severity — low, medium, high — informed by verified sources like the CVE list.
  • Install critical security patches within a month of a vendor release, based on the network’s risk ranking.
  • Before release, remove development and test accounts and review all custom code for vulnerabilities.

{{/snapshot}}

PCI DSS 6.4: Install processes and procedures for change control.

Companies must ensure all relevant personnel follow change control procedures, including:

  • PCI DSS 6.4.1 – Separate all development or test environments from production environments.
  • PCI DSS 6.4.2 – Separate the duties between development and production environments.
  • PCI DSS 6.4.3 – Ensure all production data is not used for development or testing.
  • PCI DSS 6.4.4 – Remove any test-related data from all components before activation.
  • PCI DSS 6.4.5 – Implement the change control procedures, which include:
  • Documentation of change impact and approval.
  • Testing of functionality and back-out procedures.
  • PCI DSS 6.4.6 – Implement all PCI DSS Requirements once changes have been made.

PCI DSS 6.5: Address all frequent development vulnerabilities.

This sub-requirement covers the controls for mitigating the most frequent vulnerabilities in coding.

ControlProtects against
6.5.1Injection flaws
6.5.2Buffer overflow or buffer overrun vulnerabilities
6.5.3Insecure cryptographic key storage
6.5.4Insecure communications and traffic
6.5.5Improper error-handling behaviours
6.5.6Threats rated as high risk
6.5.7Cross-site scripting (XSS) across web apps
6.5.8Improper access control across web apps
6.5.9Cross-site request forgery (CSRF) across web apps
6.5.10Authentication management flaws across web apps

{{snapshot}}

Change control and common flaws

  • Separate development, test, and production environments and never use production data for testing.
  • Follow change control: document impact and approval, test functionality, and keep back-out procedures.
  • Review public web apps at least annually and guard against injection, XSS, and CSRF.

{{/snapshot}}

PCI DSS 6.6: Adjust for New and Known Threats in Web Apps

PCI DSS Requirement 6.6 requires that businesses review all publicly available web applications to ensure that external users do not become victims of threats. These reviews should be either automated or manual but will need to be performed annually.

Your business may also be able to install an automated detection or prevention solution for your web apps to monitor traffic.

PCI DSS 6.7: Document all system and application controls.

As with all other PCI DSS requirements, you will also need to formally document this process. This will need to be in use throughout the company and with stakeholders who will also need to comply with the sub-requirements.

{{snapshot}}

In Hicomply's experience

Requirement 6 spans your whole software lifecycle — vulnerability ranking, patch SLAs, secure coding, and change control — so the evidence sits with engineering, not just compliance. We find it stays manageable when secure-development controls are mapped once and reused across frameworks like ISO 27001, with patch and change records collected continuously. A platform tour shows how, and our free compliance tools help you scope it.

{{/snapshot}}

Achieve PCI DSS compliance with Hicomply

If you’re looking to meet all the PCI DSS requirements, including PCI DSS Requirement 6, we can help. At Hicomply, we know that the process can seem long-winded and confusing, which is why we offer a full ISMS solution that allows you to keep everything you need to achieve certification in one place. Contact us today for a demo.

Risk Management
Compliance Reporting
Policy Management
Incident Management
Audits and Assessments

Ready to Take Control of Your Privacy Compliance?

See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.

Risk Management

Identify, assess, and mitigate security risks with an integrated risk register.Hicomply’s automated risk management software maps controls across ISO 27001, SOC 2, and NIST frameworks — helping teams track risk treatment plans, assign ownership, and monitor real-time compliance status. Build a resilient ISMS that reduces audit findings and demonstrates continuous improvement.

Compliance Reporting

Generate instant, audit-ready compliance reports across multiple frameworks — from ISO 27001 and SOC 2 to GDPR, DORA, and NHS DSPT.Automated evidence collection and built-in dashboards provide a single source of truth for your compliance posture, saving weeks of manual work during audits.

Policy Management

Centralise, version, and publish all your information security policies in one place.Hicomply automates approvals, reminders, and distribution, ensuring your ISMS documentation stays current and aligned with frameworks like ISO 42001 and NIST CSF.Say goodbye to outdated PDFs — manage policies dynamically and maintain full traceability.

Incident Management

Capture, investigate, and resolve security incidents with structured workflows and automated evidence trails.Hicomply integrates with ticketing tools like Jira, Zendesk, and Azure DevOps to streamline incident response and link findings to risk and control updates — a key step for SOC 2 Type II readiness.

Audits and Assessments

Simplify internal and external audit preparation with built-in audit templates and automated task assignments.
Hicomply’s audit management platform aligns with ISO 27001, ISO 9001, and ISO 14001, giving teams a clear overview of control effectiveness, audit evidence, and corrective actions — all from one dashboard.

Getting Started
Computer Software
IT and Services
Legal Services
Growth