Don't get me wrong, a PCI audit is a time consuming, costly, political, frustrating process but at the end of the day don't seem to truly increase security. At the size of business I work with, there doesn't seem to be any risk of getting shut down. Some of the smoke and mirrors (and outright lies) I've seen would probably make most people cut up all their credit cards. Its pretty sickening. Even by VISAs own numbers only about 20% of tier 1 merchants are compliant (> 6 million transactions per month). And thats with the violations they've actually caught.