We have been analyzing the NCR Retail Online (NRO) business and our NCR Industry Solutions Board, an internal team that helps set strategy, has decided to set the NRO product to End of Life on March 31, 2018 . The CPOnline Product was also recently announced with an end of life date of September 30th, 2017 . The End of Life terms indicate that all current customers will need to be transitioned off their respective product and the servers turned off by 9/30/17 (CPO) & 3/31/18 (NRO) . Your NCR Counterpoint business partner has been notified of this decision in advance and has started taking steps to help you transition your eCommerce solution.

Next Steps

As of today, we are encouraging all customers to reach out to your current NCR Counterpoint Partner to begin the transition to a new eCommerce platform. Your partner will be your best resource in planning and transitioning to a new eCommerce solution.

NCR has worked with several partners to create options for your new eCommerce solution. Please refer to the below chart for information about these options. Your partner can provide you with further documentation about these solutions to assist you with the decision process. You can also view a list of FAQ’s about moving from NRO to one of the below options by clicking here .

We will be discussing this transition directly with the users that attend our Synergy User Conference at the end of June. We will be offering a presentation on eCommerce and we will have representatives at the exhibit booth to handle your questions. In the meantime, please reach out to your partner to help determine your next steps.

We appreciate your business and look forward to taking this next, innovative step together.

Recommended eCommerce Solutions

Solution Cost Platform Additional Notes
Commerce5
  • Upfront: Starts at $2500**
  • Monthly: Starts at $495.00 plus hosting
Magento Most tightly integrated with Counterpoint and offers the most advanced features
CP Magento
  • Upfront: Starts at $2,500**
  • Monthly: Starts at $200.00 including hosting
Magento Integrated with Counterpoint and offers features similar to NRO
CP Shop
  • Upfront: Starts at $999**
  • Monthly: Starts at $125.00 plus hosting
Woo Commerce Catalog, Inventory, and Orders are integrated with Counterpoint

Understanding Security After NCR Retail Online Is Discontinued

The discontinuation of NCR Retail Online changes how merchants should interpret the platform’s former security assurances. A certification, compliance report, or technical control belongs to a defined product, service, legal entity, and period. When an ecommerce platform is retired, those credentials do not automatically transfer to the replacement system.

This does not mean every security protection disappears on the shutdown date. Stores may continue operating under transition arrangements, while payment providers, hosting companies, and NCR Counterpoint partners retain separate obligations. The important question is whether a specific certification still covers the environment handling a merchant’s data and transactions.

Merchants moving to Magento, WooCommerce, or another supported platform should therefore treat the change as a compliance review. The migration must establish which controls remain active, which have ended, and which must be validated again by the new provider.

A certification applies to a defined scope

Security certifications are never universal promises covering every product associated with a technology company. They normally identify a specific service, infrastructure boundary, operating location, or business process. A certificate may cover a hosted ecommerce environment while excluding customer-managed plugins, payment processors, retail point-of-sale systems, and third-party integrations.

This scope matters after NCR Retail Online is discontinued. A historical certification may prove that controls were assessed during a previous period, but it does not establish that a successor platform has the same architecture or protections. The certificate’s expiration date, covered services, issuing body, and terms of use all need to be reviewed.

The same principle applies to security attestations such as SOC 2 reports. A report can describe control design and operating effectiveness for a particular audit period. It should not be presented as current evidence for an unrelated platform unless the report expressly includes that platform.

What happens when the platform is retired

A discontinued product may stop receiving security updates, feature changes, and routine compliance maintenance. If its certification was tied directly to the product, the credential may remain an archived record of past operations until its validity period ends, but it generally cannot be used to support claims about a new system.

Some credentials are tied to the organization rather than a single product. Even then, the scope may change when a service is withdrawn. An enterprise could retain an organization-wide certification while removing the retired ecommerce environment from its covered boundaries. Merchants should request current documentation instead of relying on an older badge, certificate, or marketing statement.

Encryption also requires careful interpretation. An HTTPS certificate protects connections to a particular domain or endpoint. It does not certify the security of the entire ecommerce application, its database, installed extensions, or the merchant’s internal systems. Once traffic moves to a new host or domain, the replacement environment needs its own valid TLS configuration.

Compliance evidence during migration

A transition creates a useful point for collecting evidence. Merchants should retain copies of historical certificates, audit reports, data-processing terms, incident notices, and security policies connected with NCR Retail Online. These documents may help demonstrate what controls existed during an earlier period, especially if a customer, auditor, or card brand asks about past transactions.

At the same time, historical evidence should be clearly labeled. It should state the relevant dates, product scope, and limitations rather than implying that the retired service remains certified. This distinction is especially important for PCI DSS, where responsibilities are divided among the merchant, payment gateway, hosting provider, and software vendors.

For stores selling specialist products, operational details can affect the review. A retailer adding services such as gift wrapping options should verify that customer notes, delivery addresses, and order customizations are protected in the replacement application. New fields and extensions can create additional privacy and access-control requirements.

Security item What may remain valid What must be checked after migration
Historical certificate Evidence that a defined service met requirements during a stated period Expiry date, product scope, and whether it can be cited for past activity only
SOC report or audit Controls tested during the report’s audit window Whether the new platform and current operating period are included
PCI DSS evidence Shared responsibility records for the former payment environment New gateway, checkout flow, tokenization, and merchant obligations
TLS certificate Protection for the domain or endpoint named on the certificate New domains, redirects, certificates, protocols, and renewal ownership
Privacy documentation Past processing purposes and contractual roles Current data locations, subprocessors, retention, and deletion procedures
Access controls Historical account and administrator policies Roles, multifactor authentication, partner access, and offboarding

The replacement platform needs its own assurance

Magento and WooCommerce are software ecosystems rather than single security outcomes. The final risk profile depends on hosting, configuration, extensions, themes, patches, payment integrations, administrator practices, and monitoring. A platform may provide strong security capabilities while a poorly maintained installation remains vulnerable.

NCR Counterpoint partners or other implementation providers should identify the infrastructure supporting the new store. Ask which company hosts the application, who applies operating-system and platform patches, how backups are encrypted, and how vulnerabilities are reported. The answer should distinguish vendor responsibilities from merchant responsibilities.

Payment architecture deserves separate attention. A migration may replace a native checkout with a gateway, hosted payment page, or embedded payment form. Merchants can review practical considerations around third-party payment gateways, including token handling, redirect security, webhook validation, and the division of PCI responsibilities.

Data protection does not end at shutdown

Discontinuation should trigger a data-lifecycle review. The merchant needs to know whether customer accounts, order histories, payment tokens, addresses, loyalty records, and support notes are being exported, retained, deleted, or transferred to a partner. Any transfer should use an approved method and a documented chain of custody.

Payment card data requires particular caution. Merchants should avoid exporting full card numbers or sensitive authentication data unless a documented, compliant process explicitly permits it. In many cases, payment tokens are usable only within the original processor’s environment. A new gateway may require customers to enter payment details again.

Privacy notices and processor agreements may also need updating. A new host, analytics service, shipping tool, or marketing extension can introduce additional subprocessors and international data transfers. Retailers handling food, wine, or age-restricted products should review those workflows carefully; catalog content such as food and wine products can involve delivery records, age-verification information, and customer preferences.

How merchants should document the change

A concise migration security file can make the transition easier to defend during an audit or incident investigation. It should contain the retirement notice, final platform documentation, data-export records, deletion confirmations, new provider agreements, current certificates, and a list of unresolved risks.

The file should also map controls between the old and new environments. For example, record how administrator authentication, payment processing, vulnerability management, backups, logging, and incident response worked on NCR Retail Online and how each function operates now. A control that was previously provided by the platform may become the merchant’s responsibility after migration.

Testing should occur before and after launch. Review checkout encryption, account recovery, authorization boundaries, plugin permissions, payment callbacks, refund controls, backup restoration, and administrator alerts. A vulnerability scan or penetration test may be appropriate for a higher-risk store, particularly where custom integrations or sensitive customer data are involved.

Practical steps for a defensible transition

  • Obtain the last available certificates, attestations, audit reports, and scope statements for the retired service.
  • Mark historical evidence with its validity dates and avoid using it to represent the replacement platform.
  • Request current security and compliance documentation from the new host, payment provider, and implementation partner.
  • Confirm data retention, deletion, token migration, backup handling, and access revocation in writing.
  • Update privacy notices, incident procedures, vendor registers, and PCI DSS responsibility records.

Security certifications after NCR Retail Online are discontinued should be viewed as evidence with boundaries, not as permanent properties that follow a store to its next platform. Historical credentials can support records about the former service, while current assurance must come from the providers and configurations operating today.

Before the new storefront goes live, gather the relevant evidence, test the payment and customer-data flows, and obtain written clarification from each responsible vendor. That process turns a product retirement into a documented security transition rather than an assumption that old compliance claims still apply.

After you have completed your move to a new eCommerce platform, don’t forget to submit the Store Closure Request form to close your NRO site and cancel your billing subscription.