It's a matter of what data they should and shouldn't be storing after a transaction. Once a transaction happens there are certain pieces of data that the merchant no longer needs and shouldn't store going forward. That's embedded in the standards.
There are also requirements to have their website scanned by independent third parties to ensure there's no breaching or ability to breach their websites. It's also the physical security of their premises to ensure they are not storing card data they really don't need to store that has been provided to the acquirers, the merchants.
Most recently MasterCard has worked with the CFIB on a document to make it simpler for small businesses to understand the needs and requirements of PCI. Certainly major retailers have very large IT departments that can handle this stuff. We have to make it simpler and easier to understand for small business. We've been working with CFIB on that.