I like the idea, but I'd be skeptical that it's practical for very small companies.
That doesn't let them off the hook, but all that process overhead can be a killer.
I worked for a company that was PCI DSS, and it often made it impossible to get any work done (to be fair, it had more to do with how they implemented it, than the standard, itself).
But I agree that security needs to be Job One for everyone, regardless of size.