How have Department of Defense companies in the past successfully displayed and securely stored data within ERP systems such as Epicor Kinetic–most notably in the form of KPIs–while also remaining CMMC Level 2 compliant? We are looking into GROW Bi at the moment but need to ensure our data is not susceptible to security breaches.
Welcome to the party @AzariaB!
I implemented a Gov Cloud customer (DoD Aerospace) earlier this year, and although Epicor Gov Cloud IS CMMC Level 2 compliant, Grow BI (at least at that time) was not. Please check CLOSELY with both your CAM and with the Grow BI folks directly to see if that has changed.
My understanding from a Compliance session at Insights, Epicor is not CMMC Level 2. The presenter indicated that Epicor will never be CMMC Level 2 certified as it is the customer who has to be since it is the customer’s data.
We are on Epicor Gov Cloud and currently working to be CMMC Level 2 certified, however Epicor for us is out of scope as we do not allow attachments in Epicor so we have no CUI data in Epicor.
You have far more knowledge of it than I… and it may have been an ITAR issue with Grow and not a CMMC one (there is no mention in my notes so I’m working off of memory). In any case, they were not able to use Grow BI.
It is dependent on what data you are flowing thru the Epicor system or any additional items such as Grow. If you are not including CUI data then you can still be acceptable. This is based on what we had been instructed from auditors
@Erine I wouldn’t say I have more knowledge…when the Epicor presenter made that statement in the Insights session…I quickly jotted it down since we are in the throws of becoming certified
We don’t use Grow BI so have no knowledge of that.