We operate in furniture and home textiles; we make sales both in our physical store using POS devices and online via virtual POS on our own e-commerce site. Our total annual card transaction volume sits around 40,000 across both in-store and online.
Recently, the bank and payment processor we applied to for renewing our virtual POS infrastructure asked us for our PCI DSS compliance status and the related self-assessment documents. When I looked it up online, I saw talk of audits costing thousands of dollars licensed QSA auditors, and certification processes; honestly, we got pretty intimidated.
What does this "certificate" actually mean for an SME-sized business like ours? Do we really need to go through an independent audit and get an official certificate, or do we just fill out a form? If we process payments via iFrame or redirect without ever touching card data on our own server what exactly is expected of us?