CMMC and Epicor

Extending on this behemoth of a thread: Epicor Kinetic Innovation Moves to the Cloud: On-Premises Development Ends in 2028 - Kinetic ERP - Epicor User Help Forum

The poster asks some excellent questions. Can we get Epicor to answer them? I’m sending this to my CAM as well. To me, it sounds like we shouldn’t store any CUI in Epicor, which makes it more or less useless to us.

Is a BOM material list CUI?

In a User Group meeting a Epicor rep said they’re working on getting the certifications for CMMC. They may have it by now even.

I can’t answer that with any authority. However it is my understanding that any documentation that is provided by or owned by the government, and is not covered by other controls, is considered CUI. We read that as any part, material, or hardware level information, specifications, operations, work instructions, and other comments necessary to create the part. :safe_harbor:

Ok, thanks. That was my interpretation too. Just didn’t know if we were being overly cautious. :slight_smile:

Update from my Epicor CAM to help ease some concerns:

  1. Can Epicor contractually guarantee that only U.S. persons (including during support, maintenance, emergency response, and incident investigation) can access ITAR or EAR controlled data in Epicor Cloud?

Yes, and this is a control that is audited in our annual SOC assessment - reviewing privileged access and restricting to US persons.

  1. Can Epicor commit to U.S. only data residency, backups, and disaster recovery for regulated customers?

Yes. This is part of the US Government Cloud offering.

  1. How can customers obtain audit-ready evidence (logs, access records, patch history, administrative activity) without relying solely on SOC summaries?

This is not something we offer. Customers can turn on additional logging within their application for application functions and produce reports from there, but we don’t expose underlying operating system or environment logs for shared environments.

  1. In the event of a CUI or CDI incident, who has authority over containment, investigation, and reporting timelines?

Epicor has a dedicated security team that would handle any security incident, and involve other areas as needed. Customers would be contacted in 48 hours or less and be involved in the process.

  1. Is Epicor able to restrict or disclose subprocessor and offshore support access, including during escalation scenarios?

Our sub processor list is available on our website. That being said, we do not use non US sub processors in our US Government cloud environment.

We are ITAR and how Epicor controls this for support is…cases most often are initially assigned to a non-US person and then after you spend time attempting to get them to understand the issue and they can’t figure it out - they ask for a Teams/WebEx call to look at your environment and tell you they are not a US citizen. You then end up requesting the ticket be transferred to the US team and start the process all over.
We put ITAR in the subject of all our cases but they don’t seem to pay any attention to it.