We have been analyzing the NCR Retail Online (NRO) business and our NCR Industry Solutions Board, an internal team that helps set strategy, has decided to set the NRO product to End of Life on March 31, 2018 . The CPOnline Product was also recently announced with an end of life date of September 30th, 2017 . The End of Life terms indicate that all current customers will need to be transitioned off their respective product and the servers turned off by 9/30/17 (CPO) & 3/31/18 (NRO) . Your NCR Counterpoint business partner has been notified of this decision in advance and has started taking steps to help you transition your eCommerce solution.
Next Steps
As of today, we are encouraging all customers to reach out to your current NCR Counterpoint Partner to begin the transition to a new eCommerce platform. Your partner will be your best resource in planning and transitioning to a new eCommerce solution.
NCR has worked with several partners to create options for your new eCommerce solution. Please refer to the below chart for information about these options. Your partner can provide you with further documentation about these solutions to assist you with the decision process. You can also view a list of FAQ’s about moving from NRO to one of the below options by clicking here .
We will be discussing this transition directly with the users that attend our Synergy User Conference at the end of June. We will be offering a presentation on eCommerce and we will have representatives at the exhibit booth to handle your questions. In the meantime, please reach out to your partner to help determine your next steps.
We appreciate your business and look forward to taking this next, innovative step together.
Recommended eCommerce Solutions
| Solution | Cost | Platform | Additional Notes | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Commerce5 |
|
Magento | Most tightly integrated with Counterpoint and offers the most advanced features | |||||||||||||||||||||
| CP Magento |
|
Magento | Integrated with Counterpoint and offers features similar to NRO | |||||||||||||||||||||
| CP Shop |
|
Woo Commerce | Catalog, Inventory, and Orders are integrated with Counterpoint | |||||||||||||||||||||
Regulatory Compliance During An Ecommerce Platform TransitionMoving away from NCR Retail Online involves more than transferring product records and changing the storefront. An ecommerce platform also carries customer data, payment workflows, tax settings, marketing permissions, accessibility features, and records that may be subject to legal retention rules. When the product is discontinued, retailers must protect those obligations while selecting and configuring a replacement. Magento and WooCommerce can support different business models through extensions, integrations, and custom development. However, compliance does not transfer automatically with the data. The retailer remains responsible for determining which regulations apply, documenting controls, and verifying that the new platform performs as expected. A controlled migration should therefore combine technical planning with privacy, security, consumer protection, and accessibility reviews. Treat the transition as a regulated business change rather than a simple website rebuild. Establish The Compliance BaselineBegin by identifying where the store sells, where customers live, and where information is processed. Requirements may include the General Data Protection Regulation for European residents, state privacy laws such as the California Consumer Privacy Act, Canadian privacy rules, sector-specific obligations, and consumer protection laws governing pricing, refunds, subscriptions, and advertising. Create an inventory of data categories before selecting a migration method. Customer names, addresses, order histories, account credentials, payment tokens, support messages, loyalty records, and marketing preferences each carry different risks. Classify every field by sensitivity, purpose, retention period, and lawful basis for processing. Review the existing privacy notice and cookie disclosures as well. A new analytics tool, payment service, email provider, or fraud-prevention platform can change the store’s data-sharing practices. The privacy documentation, consent mechanisms, and vendor contracts should reflect the replacement architecture before the new site goes live. Protect Data During Extraction And TransferExporting information from a discontinued platform creates a temporary concentration of risk. Use encrypted transfers, restricted administrator accounts, logged access, and separate staging environments. Avoid sending full customer exports through ordinary email or storing them indefinitely on personal computers. Passwords require special care. A retailer should never attempt to copy passwords in readable form. If the legacy system cannot transfer secure password hashes into the new platform, require customers to reset credentials through a controlled process. Communicate that change clearly and protect reset links against interception and replay. Data minimization is equally important. Do not migrate obsolete accounts, expired payment details, duplicate profiles, or content that has no continuing business purpose. A smaller, cleaner dataset reduces exposure and makes it easier to honor deletion, correction, access, and portability requests. Inventory accuracy has compliance implications when incorrect stock information causes cancellations, delayed fulfillment, or misleading availability claims. Retailers planning the operational side of the move can use this inventory synchronization guide to connect stock controls with the wider migration process. Align Payments Tax And Consumer RightsPayment Card Industry Data Security Standard obligations must be reassessed when checkout technology changes. Determine whether the new architecture uses hosted payment fields, redirects, tokenization, or direct card handling. Confirm the applicable PCI scope with the payment provider and document responsibilities in the provider’s compliance materials and contract. Never migrate stored card numbers unless the payment service explicitly supports a secure, compliant token transfer. Payment tokens may be provider-specific and unusable on a replacement gateway. Plan for token conversion, customer reauthorization, or a carefully worded request for updated payment information. Tax calculations deserve a separate workstream. Validate tax registrations, product tax categories, exemption handling, marketplace rules, shipping taxes, and destination-based rates. Test rounding and invoice behavior across jurisdictions, then reconcile test orders against accounting records. Consumer law also affects the storefront experience. Prices, shipping charges, renewal terms, delivery estimates, return rights, warranty language, and cancellation controls must remain clear and accurate. A redesigned checkout should not introduce preselected consent, hidden fees, or confusing subscription enrollment.
Rebuild Privacy And Security ControlsThe replacement platform should support the rights and choices promised in the store’s privacy policy. Test customer access requests, correction workflows, deletion requests, marketing opt-outs, cookie preferences, and suppression across connected systems. Deleting a profile in the storefront may not remove copies held by email, analytics, help desk, or fulfillment vendors. Update vendor due diligence before launch. Review data processing agreements, subprocessors, hosting regions, breach notification terms, retention provisions, and security commitments for the ecommerce platform, extensions, payment services, search tools, shipping applications, and analytics providers. A popular plugin may still create unacceptable exposure if it collects unnecessary data or receives infrequent security updates. Administrative security should receive the same attention as customer privacy. Enforce multifactor authentication, role-based permissions, secure API keys, audit logging, vulnerability management, backup testing, and an incident response procedure. Remove credentials belonging to former staff and limit production access during the cutover window. Content can also carry compliance obligations through forms, tracking scripts, embedded media, and archived claims. A structured approach to content migration planning helps preserve approved disclosures while identifying pages that need legal, privacy, or accessibility review before publication. Make Accessibility And Testing Part Of Release ControlAn accessible store is essential for equitable service and may be required by disability discrimination laws or contractual standards. Review keyboard operation, visible focus, heading hierarchy, form labels, error recovery, alt text, color contrast, zoom behavior, and compatibility with assistive technology. Automated scanners are useful for finding patterns, but they cannot replace manual testing. Accessibility should cover the entire purchase journey, including account creation, product filtering, cart updates, checkout, order tracking, returns, and customer support. Check transactional emails and downloadable invoices as well. Fixing the storefront while leaving inaccessible confirmation messages can still create a serious customer barrier. User acceptance testing should include compliance scenarios rather than focusing only on design and functionality. Test a privacy request, an opt-out, a failed payment, a tax-exempt order, a refund, an accessibility path, and an account recovery flow. Teams can strengthen this process with user acceptance testing practices that assign evidence and approval responsibilities. Record expected results, actual outcomes, defects, owners, and retest dates. A signed release decision should identify unresolved risks, compensating controls, and the person authorized to accept them. This creates an audit trail and prevents business pressure from quietly overriding known compliance failures. Prepare Records And Operational OwnershipCompliance depends on evidence after launch, not simply on good intentions during implementation. Retain migration logs, data maps, access reviews, security test results, accessibility findings, consent records, tax validation, vendor assessments, and approval notes according to the organization’s retention policy. Set clear ownership for recurring activities. Privacy teams may manage data rights and notices, finance may own tax configuration, information security may oversee access and incidents, ecommerce staff may review content, and operations may validate inventory and fulfillment. Assigning duties prevents assumptions that the platform provider is responsible for every obligation. Train customer service and store administrators on the new procedures. They should know how to handle deletion requests, suspicious account activity, payment questions, refund disputes, accessibility complaints, and data incidents. Include escalation paths and response deadlines in practical runbooks. After launch, monitor failed checkouts, unusual login activity, consent records, stock discrepancies, tax anomalies, and customer complaints. Schedule a post-migration review within the first weeks, then repeat risk assessments when adding extensions, entering new markets, or changing payment and analytics providers. Create A Controlled Launch PlanA staged release can reduce the impact of configuration errors. Freeze unnecessary changes, take verified backups, confirm rollback options, and define the cutover window. Keep the legacy environment protected and available only as long as necessary for lawful support, reconciliation, and record access. Before opening the new store, verify redirects, canonical URLs, robots settings, transactional emails, cookie behavior, consent records, order exports, refund processing, stock updates, and administrator permissions. Test real operational scenarios with small controlled transactions where appropriate, then reconcile every result with the relevant business system. Use these priorities to keep the work focused:
A transition from NCR Retail Online is an opportunity to replace inherited settings with deliberate controls. Start with a documented regulatory assessment, involve legal and security specialists early, and require evidence before approving the production cutover. Build the compliance checklist into the migration schedule now, then use it to govern testing, launch, and ongoing platform management. |
||||||||||||||||||||||||
After you have completed your move to a new eCommerce platform, don’t forget to submit the Store Closure Request form to close your NRO site and cancel your billing subscription.