We run an e-commerce site selling boutique coffee machines and spare parts in the US. We process around 18,000 transactions a year with an annual turnover of roughly 1,200,000 dollars. We don't take payments directly on our own servers; we use the secure iFrame and external redirect flow provided by our payment gateway, so we thought card numbers never even touched our site.
Yesterday we received an urgent email from our payment processor. It says we must complete our annual PCI DSS compliance validation, or else we'll be hit with per-transaction fines and risk having our payment gateway suspended. They sent over complicated forms and links to hundreds of pages of technical standards.
As a small merchant, what is the actual PCI DSS compliance checklist that applies to us? If card data never touches our servers, exactly which Self-Assessment Questionnaire do we need to fill out, and what will this realistically cost us?