Given all the new PCI compliance verification going on I beleive it would be good to have a tool built into the AV that could also provide for scanning and / or varification of a site for PCI compliance.
Rather than use a third party entity, that in reality is unknown to the security world, Symantec could provide the same level of service as other compliance providers but bundle it with current server products.