New requirements in PCI DSS 3.0 include:
Methodology-based penetration testing to verify that the methods used to segment the merchant cardholder data environment (CDE) from other IT infrastructure
Inventory of all hardware and software components within the cardholder data environment
Documentation detailing which requirements are managed by third-party vendors vs.