- Install and maintain a firewall
- Lock down system users, groups, passwords and default settings of your services
- Use encryption
- Use and update anti-virus software
- Restrict access to your systems and have auditable logs of all access to your systems, physical and digital
- Have unique identifiers for all people with access to your systems, so that those audits are meaningful
- Log and monitor all network access to your systems
- Have, distribute, and regularly test your physical, network and information security policies
- Fill out a self-assessment questionnaire attesting you meet all these requirements
- Have your server scanned by a 3rd party compliance company every 3 months
To pass the compliance scans, you will have to maintain all services on your servers at the latest versions or provide evidence that you have applied patches covering all known security flaws, among other things. The scans are not cheap and have to be made by a provider approved by PCI. SecurityMetrics charges $699 per year to do them quarterly.
By signing up with Stripe you are agreeing that you're taking care of this already.
> You agree that at all times you shall be compliant with the Payment Card Industry Data Security Standards (PCI-DSS) and the Payment Application Data Security Standards (PA-DSS), as applicable. You agree to promptly provide us with documentation evidencing your compliance with PCI DSS and/or PA DSS if requested by us. You also agree that you will use only PCI compliant service providers in connection with the storage, or transmission of Card Data defined as a cardholder’s account number, expiration date, and CVV2. You must not store CVV2 data at any time. Information on the PCI DSS can be found on the PCI Council’s website. It is your responsibility to comply with these standards.
It's also important to realize that you can't meet all the requirements on shared or cloud hosting -- except Amazon EC2, which is AFAIK the only PCIDSS approved cloud. You really need your own server to be in compliance.