Organisations approaching PCI-DSS for the first time tend to treat it as a control-implementation exercise: read the requirements, apply them across the estate, present the result for assessment. This is the expensive path, and it is expensive in a way that compounds annually.
The decision that determines the cost of every subsequent assessment is architectural, and it is taken before any control is implemented: how much of your system touches cardholder data at all. A tokenisation boundary placed at the network edge keeps application services, reporting databases, log aggregation and most of the engineering organisation outside the assessment scope entirely. The same estate without that boundary pulls all of it in.
The practical consequence is that PCI scope should be settled during architecture, alongside the tenancy model and the network topology, and not deferred to a compliance workstream that begins after the system exists. Reducing scope retrospectively means re-architecting data flows that already have consumers, which is the most expensive form of the same work.