This is rubbish no where can I find a requirement that we need to go above and beyond what we normally do to remain compliant with PCI-DSS if we do not store our customers credit card data (which we don't).
I am marking this one as link bait and moving on, annoyed at the waste of a couple of hours.