The PCI DSS security requirements apply to all system components included in or connected to the cardholder data environment. The cardholder data environment (CDE) is comprised of people, processes and technologies that store, process, or transmit cardholder data or sensitive authentication data. “System components” include network devices, servers, computing devices, and applications.
—PCI DSS v3.2.1,2 p. 10
Although de-scoping your CDE from your non-CDE is highly recommended, it is not currently a mandated requirement. However, if you should decide to reduce your PCI DSS burden ...