i run an organic food store, and after a conference call with my
credit card service (card connect), do i really have to hire a PCI
certified professional once a year in order to be pci compliant?
You probably do not need to hire a PCI certified professional, because unless you're a particularly large organic food store, you are likely small enough that the Self-Assessment Questionnaire will suffice. (The caveat being that your processor may compel you to have an audit instead of an SAQ, but that would usually only be the case for a small merchant who had a history of compliance problems).
If you've never gone through the process, then hiring an auditor at least once is a good idea. They can help you understand the issues so that handling the SAQ will be easier for you in future years. They can point out security issues that the SAQ might not make apparent to you.
If this is the case, how much does it cost?
That varies widely by the size and location of your business, and by the individual auditor you might engage, so it's impossible for us to say. The standard advice of "get multiple quotes" applies.
Or am I just misreading things, i don't think any "cyber criminal" is going to target my business.
If you handle cards, you are a target of opportunity. They may not know or care who you are, but they'll hit you nonetheless. It's not about your level of profit, it's about the fact that customers hand you cards, and each card represents thousands of potential dollars, and a useful smaller amount of real dollars to the attacker who sells it down the line. PCI DSS is not about employees, it's about infrastructure and practices to protect the cards that have to flit across your business on their way to the processor.
Sure, NCR does a lot to protect the cards - but a necessary step, imposed by the card brands, is to make sure that Merchants do their part also.