DIane
The first thing I would do is contact those you are considering and get written confirmation that the providers are offering you services that are PCI-DSS compliant. (PCI=Payment Card Industry - Data Security Standard). Preferably , they should either be DSS 1.2 or guarantee they are about to reach 1.2 compliance.
If those directing you to other sources do not understand the infomation above, download the document and have them read it. Hand it to your tech folks and expect to hear. OMG, OMG, OMG this is nearly impossible and extremely expensive to be compliant.
I also feel it is worth checking the following link to see if the provider is listed by ViSA as a PCI-DSS Validated Service Provider. http://usa.visa.com/download/merchants/cisp-list-of-pcidss-compliant-service-providers.pdf