What's your strategy for payment security and PCI compliance when you're processing payments directly instead of via Apple?

We’re moving away from Apple’s payment system for our subscription flow but now I’m drowning in PCI compliance requirements.

Anyone else dealt with this transition? The security protocols seem overwhelming compared to just letting Apple handle everything.