The needs for PCI standards include setting up a firewall, restrict physical use of servers, using and regularly upgrading anti-virus and adware and spyware software etc as layed out here

Should you host the application within the cloud , how will you make sure that you meet these PCI needs

The easiest method to make sure you are PCI complaint would be to search for cloud infrastructure companies that provision "private cloud" infrastructures. Check if the cloud resource pools are realistically divided, physically divided and what isolation levels exist.

You will find several good private cloud companies available, but have techniques used in supplying isolated instances. Quite frequently you will notice enterprise clouds as VMware vSphere 4 installations.

The simplest way is by using a third party payment company. They are able to handle all of the transactions for you personally inside a secure manner, without you needing to know any particulars.