Given that there's only 1,000 CVV2 values (10,000 for Amex) isn't putting so much into CVV2 value a bit ridiculous? Someone who really wanted to could get a CVV2 value in only 500 auth attempts on average.
That's going to trip a fraud check at the bank and get the card frozen long before 500 attempts.
If you store CVV2 in your database against your merchant agreement, and someone steals it, I'm sure the credit card comp will come after you for the losses.
As far as being non-PCI compliant, you as a merchant are only compliant right at the time of the audit. And maybe not even then, given Heartland's experience. The whole PCI thing is to give Visa and MasterCard a way to do some CYA.
That company passed PCI-DSS because these were in-flight transactions, if that had been a historical database they would not have passed.
Sometimes banks make it mandatory, sometimes not. It's not * required* to make a transaction, it merely offers an (optional) extra level of security.
Also, the banks will offer differing levels of chargeback cover based on these factors.