Common Barriers to PCI Compliance and DSS 2.0
This article from Symantec covers a list of issues that the companies QSAs see frequently that stop companies from becoming complant with the PCI DSS. As you may expect, the issues that top the list are a lack of formalized policies and procedures that are required by the PCI council as well as segmentation issues related to the cardholder data environment.