We have been analyzing the NCR Retail Online (NRO) business and our NCR Industry Solutions Board, an internal team that helps set strategy, has decided to set the NRO product to End of Life on March 31, 2018 . The CPOnline Product was also recently announced with an end of life date of September 30th, 2017 . The End of Life terms indicate that all current customers will need to be transitioned off their respective product and the servers turned off by 9/30/17 (CPO) & 3/31/18 (NRO) . Your NCR Counterpoint business partner has been notified of this decision in advance and has started taking steps to help you transition your eCommerce solution.
Next Steps
As of today, we are encouraging all customers to reach out to your current NCR Counterpoint Partner to begin the transition to a new eCommerce platform. Your partner will be your best resource in planning and transitioning to a new eCommerce solution.
NCR has worked with several partners to create options for your new eCommerce solution. Please refer to the below chart for information about these options. Your partner can provide you with further documentation about these solutions to assist you with the decision process. You can also view a list of FAQ’s about moving from NRO to one of the below options by clicking here .
We will be discussing this transition directly with the users that attend our Synergy User Conference at the end of June. We will be offering a presentation on eCommerce and we will have representatives at the exhibit booth to handle your questions. In the meantime, please reach out to your partner to help determine your next steps.
We appreciate your business and look forward to taking this next, innovative step together.
Recommended eCommerce Solutions
| Solution | Cost | Platform | Additional Notes | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Commerce5 |
|
Magento | Most tightly integrated with Counterpoint and offers the most advanced features | |||||||||||||||||||||
| CP Magento |
|
Magento | Integrated with Counterpoint and offers features similar to NRO | |||||||||||||||||||||
| CP Shop |
|
Woo Commerce | Catalog, Inventory, and Orders are integrated with Counterpoint | |||||||||||||||||||||
Understanding PCI Compliance After Switching To A New Ecommerce PlatformMoving from NCR Retail Online to another ecommerce system changes more than the storefront’s appearance. A platform migration can affect payment pages, checkout scripts, customer accounts, order processing, inventory connections, hosting arrangements, and the vendors that handle cardholder data. Each change can alter the scope of your PCI DSS responsibilities. PCI compliance is the process of meeting the Payment Card Industry Data Security Standard, which protects payment card information from theft, misuse, and exposure. A new platform may provide stronger security controls, but it does not automatically make a retailer compliant. Responsibility is shared between the merchant, ecommerce provider, payment gateway, hosting company, and other service providers. The safest approach is to treat migration as a security project rather than a simple website replacement. Document how payments move through the new store, identify every system that touches sensitive information, and preserve evidence showing that required safeguards are working. Why A Platform Migration Changes PCI ScopePCI scope includes the systems, people, applications, and processes connected to payment card data. During a migration, the payment flow may change from a hosted checkout to an embedded form, a redirect to a gateway, or a setup where the ecommerce platform sends payment details directly to a processor. These arrangements create different compliance obligations. For example, a fully hosted payment page can reduce the number of systems exposed to card data, while a custom checkout may bring additional scripts, servers, integrations, and development practices into scope. Even if the new platform uses tokenization, the merchant still needs to confirm how tokens are created, stored, transmitted, and linked to customer orders. Retailers should also examine connected tools. Point-of-sale software, fulfillment applications, analytics tags, customer service systems, email platforms, and inventory synchronization services can introduce risk if they receive payment-related information or influence the checkout page. A migration from NCR Retail Online to Magento, WooCommerce, or another solution should include a complete data-flow review. Identify The New Payment EnvironmentBegin by mapping the customer journey from product selection to payment confirmation. Record where a shopper enters card details, which system encrypts the information, where authorization occurs, and what data returns to the store. Include failed payments, refunds, recurring transactions, mobile checkout, and customer service-initiated orders. The payment provider’s role should be clearly defined in writing. Ask whether it hosts the payment form, provides a validated point-to-point encryption solution, stores cardholder data, or simply authorizes transactions. These distinctions help determine which PCI Self-Assessment Questionnaire, or SAQ, may apply. Content and merchandising systems deserve attention as well. A retailer selling drinkware, for example, might review its barware collection while testing product links, checkout behavior, and third-party scripts. Product pages themselves do not usually handle card data, but injected code, compromised plugins, or unsafe tag management can affect the payment experience. Match Controls To The New PlatformPCI DSS requirements cover network security, secure configuration, access control, vulnerability management, monitoring, authentication, software development, and documented policies. The new ecommerce platform may provide some controls as part of its service, but the merchant must verify what is covered and what remains its responsibility. Request current compliance documentation from the platform and payment partners. Useful evidence can include an Attestation of Compliance, a responsibility matrix, penetration-test summaries, vulnerability-management details, and information about encryption. A provider’s compliance status supports the retailer’s program; it does not replace merchant-level validation. The checkout should be checked for unauthorized scripts, weak administrative accounts, exposed test environments, and outdated extensions. This is particularly important for open-source or highly customizable platforms, where plugins and themes may be managed by different vendors. Apply security updates promptly and establish a process for reviewing new extensions before installation.
Preserve Evidence During The CutoverA migration creates a period when old and new systems may operate together. That overlap can produce forgotten administrator accounts, duplicated integrations, temporary databases, unprotected staging sites, or payment settings that differ between environments. Treat every environment as a potential compliance concern until it has been reviewed and retired or secured. Before launch, create a cutover checklist that covers access permissions, encryption certificates, firewall rules, administrative MFA, logging, backups, and payment-provider settings. Confirm that test transactions do not use live card information unless the environment and process are explicitly approved for it. After launch, compare actual payment behavior with the planned data flow. Review logs for unusual requests, scan the public-facing environment where required, and verify that old credentials and API keys have been disabled. Keep dated records of approvals, test results, vendor communications, and corrective actions. Manage Customer Data And Store FunctionsPCI DSS focuses on payment card data, but a migration also affects personal information such as names, addresses, telephone numbers, passwords, and purchase history. Minimize what the new platform stores, define retention periods, and restrict staff access according to job responsibilities. Card verification values must not be retained after authorization, and sensitive authentication data requires especially careful handling. Inventory synchronization can create indirect security exposure. A store may connect online orders with a point-of-sale system, warehouse software, shipping service, and accounting package. Review the permissions granted to each connection and use unique credentials, encryption, and least-privilege access. A service that only needs product quantities should not receive customer payment information. Customer-facing features should be tested for privacy and reliability after migration. For instance, everyday tableware product pages may share recommendation, review, or marketing scripts that need separate review before they appear beside checkout functions. Verify that cookies, consent controls, and analytics tools do not capture payment fields or transmit unnecessary customer data. Choose The Right Validation PathMost small and midsize merchants validate PCI DSS through an appropriate SAQ and, where applicable, external vulnerability scans. The correct questionnaire depends on the payment architecture, not the brand name of the ecommerce platform. A retailer should select it with guidance from its acquiring bank, payment processor, qualified security assessor, or compliance provider. If a merchant stores, processes, or transmits cardholder data directly, the assessment may be more demanding. A hosted payment page can reduce exposure, but it still requires controls around website security, access management, monitoring, policies, and third-party oversight. A payment provider’s certificate alone is not a complete merchant compliance package. Document exceptions instead of ignoring them. If a control cannot be implemented immediately, record the risk, compensating measures, responsible owner, deadline, and management approval. Revisit the assessment whenever the checkout changes, a plugin is added, a payment provider is replaced, or a security incident occurs. Build A Repeatable Compliance RoutineCompliance should continue after the new store goes live. Schedule vulnerability scans, access reviews, software updates, log checks, backup tests, and policy reviews. Train employees to recognize phishing, protect administrator credentials, report suspicious activity, and avoid placing card details in email, chat, spreadsheets, or support tickets. Use the following practices to keep the post-migration program organized:
A written responsibility matrix is especially valuable when NCR Counterpoint partners, Magento developers, WooCommerce specialists, hosting providers, and payment companies share the work. It should state who owns each control, who performs it, how often it is checked, and what evidence proves completion. A successful platform change should leave the retailer with a clearer, safer payment environment than before. Review the new checkout, confirm responsibilities with every provider, complete the appropriate PCI validation, and preserve evidence from the first test transaction onward. Taking these steps turns a disruptive ecommerce migration into a controlled transition that protects customers and supports dependable online sales. |
||||||||||||||||||||||||
After you have completed your move to a new eCommerce platform, don’t forget to submit the Store Closure Request form to close your NRO site and cancel your billing subscription.