as far as I know, for the business i' have audited includes hotels and retailing. This includes also in the region you're in, for example this is compulsory in the States, whereas in Asia, the awareness is somewhat, still lacking.
These are the two which PCI is a must due to the regulation from VISA/MC/Amex etc. Not all business will need to go into PCI unless you're in that the following tiers:
# Tier 1: The highest volume merchants, which submit 6 million or more transactions per year.
# Tier 2: Merchants that submit 1-6 million transactions per year.
# Tier 3: Merchants that submit 20,000 to 1 million e-commerce transactions per year.
# Level 4: Merchants submitting less than 20,000 e-commerce transactions per year, and all other merchants up to 1 million transactions per year
Read more:
http://pindebit.blogspot.com/2008/12/more-on-pci-and-tiers-1-2-and-3.html#ixzz0etxqkjU8