I manage very few credit card transactions and they are all handled exclusively through QB Payments with no website e-commerce. QB is trying to tell me that I'm not PCI compliant and they want me pay SecurityMetrics to verify my compliance, but the PCI website says I can self-assess using SAQ-A and an AOC. I don't know how to submit this to QB without using the 3rd party. The QB TOS do not mention anything about verification or certification. They just list the actual 12 requirements that constitute PCI compliance, all of which I meet or are N/A. Frankly, this all feels quite scammy?