We are a design and furniture store with two branches in Istanbul. We accept payments using bank POS terminals at our physical locations and also sell online via a virtual POS on our open-source e-commerce platform. Our total card volume is around 3,500 transactions per month. Recently, we received an official email from a private bank whose virtual POS we use; it stated that under the transition to PCI DSS 4.0, we need to update our security compliance and fill out a self-assessment questionnaire.
I'm vaguely familiar with PCI DSS, but I never looked into what changed with 4.0 or how it directly affects small businesses like ours. We never store card details on our own servers anyway; payments are processed entirely through the bank's hosted checkout page. Are they going to demand a full server audit now, or do we just sign off on a form? Do we need to hire security consultants from scratch for PCI DSS 4.0, and where should we even start?