Common mistake: just because you don't store credit cards it doesn't mean that this changes anything about your PCI DSS requirements. As long as CCs hit your IPs you are responsible for them. Not storing CCs simplifies certain things but you still have to get certified.