According to this quote from "applicability" section of PCI DSS it's not:
The primary account number is the defining factor in the applicability of PCI DSS requirements. PCI DSS requirements are applicable if a primary account number (PAN) is stored, processed, or transmitted. If PAN is not stored, processed or transmitted, PCI DSS requirements do not apply.
But does it mean that it is not applicable at all? Or just that I'm not obliged for fulfill these requirements? If I want my solution (application) to be secure (= to be recognized as secure by large enterprises), should I implement the requirements anyway, or should I invest my time to some other set of recommendations? In other words - would the PCI compliance give me some credit when selling an application that is not dealing with payment cards, or is there some other, more generic standard?