To minimize the Scope, you first have to understand where is your Card data (stored, transferred and processed) and document it as requested by PCI DSS. Then you have to analize what kind of data is where, as there are different requirements for different types of data. Accoding to results, try to use network segmentation and firewalls in order to limit access to network segment where data is stored or processed. Appendix F of PCI DSS, “Requirements and Security Assesment procedures” shows the process of identificaton of the scope that should be used by QSA Auditor. You can use the same to understand what is acceptable.