A small business owner I know just got an email from trustwave.com about urgently needing to log in to their "PCI Manager" and update their "Scan Attestation". I assumed it was a phishing email at first, but I did some research and a) PCI compliance has to do with accepting credit card payments, which they do (though they're just a local shop; they don't have any custom tech around doing that), and b) trustwave
seems like it may be a real company: it has a website and a Wikipedia page, and the latter has been around for ~4 years though it's also marked as "reading like an advertisement".
How do I know if this is legit? I equally don't want them to get phished and don't want them to have a problem with their PCI status.