Will PCI become a standard for everyone..... hmmm good question, but I honestly think no, but its a step in the right direction.
As already stated PCI:DSS is only focused on payment card information, so its a narrow scope, and does not have interest in any area where this form of information is not resident or flowing. The PCI standard is still relatively new, and will of course continue to be developed and improved, but adoption is still relatively low and often misunderstood. Yes everyone who processes card data should be doing the PCI dance, but if their acquirer isnt making the push companies are not doing it, and when they do its a slow going process, and most often a minimal tick box approach.
All of these standards are best practice and common sense, some are mandated, and some are optional. Organisations still dont fully understand security benefits, its an overhead, and rarely done properly. If people who need to be PCI compliant expanded the requirements to fill their organisation this would be a good start to improved security, but I think we are some way away from this.