What actually shrinks the audit
Four moves, in the order that pays best.
Get the card fields out of your page. A hosted payment page or a provider-controlled iframe is the single largest reduction available, and nothing else comes close. We built two payment gateway plugins for a licensed European payment institution around exactly this pattern, hosted checkout with deliberately low PCI scope, because the alternative drags the merchant's entire platform into assessment. Everything below this is a smaller lever.
Take the marketing tags off checkout. Not off the site. Off the payment step.
Analytics on a product page is a completely different risk from analytics on a page with a card field in it, and only the second one matters here. Most stores can get to a clean checkout in a couple of weeks, and in our experience the conversion cost is roughly zero. The objection is always that marketing will lose the funnel. They lose very little in practice, because the purchase event still fires on the confirmation page, which is where it was always counted.
Write the script inventory down. Who added each script, why, and what breaks if it disappears. That list is the artifact 6.4.3 is asking for, and on most stores it is an afternoon of work rather than a project.
Ask your acquirer which questionnaire they expect, before you build anything new. The Council's guidance points merchants at the entity the questionnaire will be submitted to, typically the acquirer or the payment brands, to establish which one applies. A ten-minute email in January prevents a three-month scramble in October.
The pattern we see across the Magento stores we run under ongoing support and maintenance is consistent, and slightly unfair: the businesses with the least painful audits are not the ones with the most security tooling. They are the ones whose checkout is boring.