Shared premises is not a relevant factor for PCI compliance. You don’t face fines for customer information you don’t handle.
PCI compliance should be a minimal standard. Does your shared customer recognize your organizations as distinct, or do you act as one support organization? Act to meet your customer’s expectations. If you wish to present yourselves as a single organization, then recognize that your customer can seek damages from both of you if either of you fail the standard of reasonable care. This is not a PCI issue.
Discuss This Question: