Having worked on PCI-DSS initiatives for implementing enterprise clients, it is both expensive and extensive.
I have never heard it mentioned from AC, so I am going to guess that PCI-DSS was not a requirement set that they have implemented.
We do have a client that has a credit-card machine, merchant account, and uses Quickbooks - Quickbooks contacted them to make a mandatory upgrade that was supposedly to go to a version that was PCI-DSS compliant. You might want to investigate that as a method to comply.
PCI-DSS implementations are considered a combinations of systems and procedures that work together to protect subject data. The greater stress and rigor came about as result of the TJ Maxx debacle - 45 million credit card accounts lifted from a WEP 'protected' wireless network. The bad actors sat in the parking lot and stole data.