If the email you are getting is from Security Metrics, know that they are bullies and don't deserve anyone's business. The way I have had it explained is that QB is the one taking payment, therefore I do not need to be in compliance. QB does.
However, if you take cards for payment at your company, you need to be compliant. But it would benefit you and your company to use a company of your choosing. Not the one that Intuit/ QB has.
You will save money and sanity if you go with another company.