Utter pain
The PCI DSS procedure, audit process and general bullying is a complete pain for a small business. You get threatening letters from them, phone harrassment and endless emails, all ending up in spending a day a year filling in a ridiculous questionnaire about which, I am sure, most people lie through their teeth just to get rid of the problem.
It was such a pain that I got rid of the in-house credit card acceptance system and used an on-line provider instead - voila, the problem has gone away and I took enormous pleasure in writing the eff-you letters to my previous merchant account provider. This is presumably the background of the whole ponderous apparatus - it couldn't have been designed for any other purpose than semi-malicious intent.