There are many open source shopping carts that don't have any PCI compliance certification.
Is it legal to sell/distribute ecommerce related software that isn't compliant?
It makes no sense, since if the source code is modified in any way, you probably have to re-certify the software again correct?