I'm hoping folks familiar with the up to date PCI environment can chime in here. There have been some earlier threads, but they are now quite old.
We're looking to implement tier 3 and 4 affiliate websites, where credit card details are taken on our server and passed over to the merchant's site. The merchant is currently permitting self assessment. But who knows if later on down the track it will require auditing.
The reason for us doing this is to have as much control over the booking process, to assist in adding value to the user, without actually taking the money.
What would you expect to pay for self managed compliance, is it manageable doing it yourself, and what benefits and disadvantages do you see, or experience?